Lead Cloud Networking Engineer
999 REMOTE, United States
Applications have closed
CACI International Inc
The Opportunity:
The DHS CDM Program mission is to safeguard and secure cyberspace in an environment where the threat of cyber-attack is continuously growing and evolving. The CDM Program defends the United States (U.S.) Federal Information Technology (IT) networks from cybersecurity threats by providing continuous monitoring sensors (tools), diagnosis, mitigation tools, and associated services to strengthen the security posture of Government networks.
As an AWS Security Engineer, you are responsible for managing an enterprise that consists of multiple flavors of Linux & Windows within the AWS infrastructure. All with Cybersecurity at the core.
Although this is a high-pace environment, be assured you’d be joining a high-tech people-oriented team and overall community that’s just as flexible as we’re hoping you to be.
Responsibilities:
- Lead the design, deployment, and troubleshooting of Azure VPN Gateways and ExpressRoute with BGP to support secure inter-account and external connectivity, including mission-critical links to DISA.
- Oversee PPSM edits and IAP whitelisting requests, ensuring alignment with DoD cybersecurity requirements and verifying post-change connectivity.
- Serve as a technical lead in the re-architecture and deployment of the Coast Guard’s Azure Enterprise Cloud, including documentation and knowledge sharing.
- Proactively troubleshoot complex hybrid-cloud infrastructure issues across Azure and AWS, including routing conflicts, firewall/NACL/NSG/SG blocks, and CAP/IAP restrictions.
- Lead the redeployment of Cisco FMC/FTDv boundary protection appliances, aligning with Cisco and AWS best practices, including policy design, SSO integration, and testing.
- Develop and maintain Terraform modules to automate deployment of Versa VOS SD-WAN appliances, promoting infrastructure as code and repeatability.
- Build serverless automation using AWS Lambda to enhance operational resilience through remote Cisco firewall backups.
- Architect and implement Ansible automation, including server buildout and playbooks to manage Cisco FMC configurations via configuration as code.
- Configure IAM roles, users, and policies to enable secure integration with third-party tools such as the Versa CMS connector in AWS.
- Lead the provisioning of new AWS and Azure environments, applying security controls, routing, and firewall rules as part of the onboarding process for new accounts and workloads.
- Administer Azure Entra ID, managing admin access and permissions to align with least privilege principles.
- Develop and maintain detailed network documentation, diagrams, and operational runbooks for new deployments and architectural changes.
- Drive Agile delivery by managing JIRA tasks, leading SCRUM contributions, and mentoring junior team members on technical tasks and ticket ownership
Qualifications:
- Cleared for Secret work
- DoD Approved 8570 Baseline Certification: IAT Level II
- US Citizenship required.
- University Degree (BS), or equivalent years of related experience, and additionally 10+ years of related IT engineering experience required.
- 10+ years’ cumulative experience with customer interactions, including presenting, answering questions, proactively resolving issues.
- 10+ years’ cumulative experience with in-depth systems administration in Linux environments (RHCE equivalence) and Windows Server environments.
- 10+ years’ cumulative experience integrating and troubleshooting systems in a Cloud environment (AWS Cloud preferred).
- 7+ years’ hands-on cumulative experience creating, analyzing and automating Linux scripts (Command, Bash, C, Ansible) – basically you need to know how to connect things for automation needs.
- 5+ years’ cumulative experience implementing and securing services relating to remote connections.
- 3+ years’ cumulative experience integrating/understanding Multi-factor authentication (MFA, 2MFA).
- 7+ years’ cumulative experience with enhance data protection and compliance (such as OpenSSL, KeyStore, Cyphers).
- 3+ years’ cumulative experience with securing systems by following STIGs, best practices, and government/compliance requirements (such as NIST 800-53, NIST 800-171, FISMA, FEDRAMP), and negotiating/working-with IA personnel to arrive at sensible and effective solutions.
- 1+ years’ cumulative experience with network devices, integrations and concepts such as VPN, firewall, routing.
- 1+ years’ cumulative experience with Agile/Kanban, Git/GitHub
- Responsible for Configuration, maintenance, and troubleshooting when necessary - IaaS (Linux and windows), SaaS, and PaaS implementations. "as well as other cloud resources"
- One (1) of the following certifications: AWS DevOps Engineering Expert, AWS Solutions Architect Expert, AWS Security Engineer Associate (Certification must be recent)
Desired:
- Technical degree in Computer Science, Computer Engineering, or a related subject area
- Relevant Technical and/or Security Certifications (e.g. CISSP, Sec+ etc.)
- Two or more of the following certifications: AWS DevOps Engineering Expert, AWS Solutions Architect Expert, AWS Security Engineer Associate
- Proven communication skills both written and verbal to management
- Familiarity with common cybersecurity tools is greatly desired. Our mission to support DHS in their cybersecurity needs, inclusive of identifying and preventing culprits from accessing systems/data that they shouldn’t is a high priority focus for our team.
- 2+ years’ recent (within the past 3 years) cumulative experience with AWS Cloud Computing
- 3+ years’ cumulative experience with VMWare (implementing, managing, configuring)
- Some experience (1+ years’) with any or all these products or technologies: MS SQL, Ansible, Puppet, Chef, Qualys, SCCM, BigFix, MDM solutions, GIT (again, nice to have, not required)
- Some experience (1+ years’) setup and integration with IIS, SQL Server
- Experienced and understanding of ADFS, SAML and PKI.
- Experience with AWS Rest API calls
________________________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.
Your potential is limitless. So is ours.
________________________________________________________________________________________
Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here.
Since this position can be worked in more than one location, the range shown is the national average for the position.
The proposed salary range for this position is:
$95,500-$210,100CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
Tags: Agile Ansible APIs Automation AWS Azure Bash C CISSP Clearance Clearance Required Cloud Compliance Computer Science DevOps DISA DoD DoDD 8570 FedRAMP Firewalls FISMA GitHub IaaS IAM Jira Kanban Lambda Linux Monitoring MSSQL NIST NIST 800-53 PaaS PKI Puppet Qualys REST API SaaS SAML Scrum SQL SQL Server SSO STIGs Terraform VMware VPN Windows
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Startup environment Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.