Senior Network Engineer
Concept Solutions is seeking a Senior Network Engineer to join a dedicated team of Information Technology (IT) professionals supporting the Federal Aviation Administration's (FAA) Command, Control, and Communications (C3) office. The C3 office carries a critical strategic mandate: ensuring FAA managers maintain daily situational awareness and uninterrupted continuity of communications during severe national emergencies, natural disasters, or critical equipment malfunctions. Should disruptions occur, the C3 office is chartered with executing rapid disaster recovery and restoring essential communication services expeditiously. This high-stakes, mission-critical position is based on-site in Washington, DC, with some telework eligibility available once the candidate is fully trained and integrated.
In this role, the selected engineer serves as the primary technical advisor and bridge between traditional enterprise network environments and modern, scalable AWS cloud systems. The role is responsible for the design interpretation, modernization, security, and continuous operation of the hybrid infrastructure that underpins the FAA's emergency communications posture, aligning complex physical architectures with cutting-edge public sector cloud solutions.
Core Duties & Hybrid Architecture Responsibilities
The Senior Network and Hybrid Cloud Engineer will lead complex, time-sensitive projects and serve as a senior technical authority. The core responsibilities span across traditional hardware environments and AWS public sector cloud infrastructure:
Traditional Enterprise Network Engineering
• Serve as the senior technical authority for the end-to-end design, development, and implementation of robust enterprise network architectures, including Local Area Networks (LAN), Wide Area Networks (WAN), and Metropolitan Area Networks (MAN).
• Lead multi-vendor physical engineering efforts for the expansion, performance optimization, and modernization of enterprise network infrastructures, with specific focus on high-scale routers, switches, and firewalls.
• Evaluate emerging physical networking technologies and develop strategic investment recommendations to continuously improve the scalability, resiliency, and path diversity of the C3 office's mission-critical networks.
• Perform system administrator duties on an as-needed basis to verify server-network integration, maintaining high availability for local and remote operations.
Hybrid Connectivity & AWS Cloud Architecture
• Design, build, and maintain highly secure hybrid connectivity architectures bridging traditional civilian FAA data centers with AWS cloud environments, utilizing AWS Direct Connect, Site-to-Site VPN, Transit Gateway, and Route 53.
• Formulate and execute structured cloud migration strategies to transition legacy, on-premises civilian systems, applications, and network appliances into secure, scalable AWS environments.
• Develop and operate robust multi-account AWS landing zones using AWS Control Tower, establishing logical subnets, route tables, security groups, custom VPC configurations, and strict network segmentation boundaries.
• Establish highly available cloud architectures and robust disaster recovery configurations designed to meet stringent Recovery Time Objective (RTO) and Recovery Point Objective (RPO) requirements.
• Optimize cloud resource costs and efficiency (FinOps) through proactive resource right-sizing, AWS Savings Plans, Reserved Instances, and tier-appropriate storage optimization strategies.
Cybersecurity, Compliance & Zero Trust Hardening
To ensure the high integrity of critical communications, the candidate will be responsible for integrating a holistic security posture across physical and virtual environments, conforming to strict federal guidelines:
• Verify the posture of the LAN, WAN, and AWS environments to ensure complete compliance with civilian configuration management and federal security requirements, in strict accordance with OMB Circular A-130, FISMA, and the NIST SP 800 series (specifically NIST SP 800-53 and FedRAMP security controls).
• Implement and enforce advanced network security controls and Zero Trust Network Architecture (ZTNA) principles, utilizing Cisco secure firewalls, segmentation rules, and secure remote access tunnels (IPsec, 802.1x, and client-to-site VPNs).
• Deploy and monitor unified cloud-based security tools including IAM, AWS Organizations, AWS Security Hub, Amazon GuardDuty, AWS Config, Key Management Service (KMS), and AWS WAF.
• Lead the buildout and strict enforcement of civilian and federal Security Technical Implementation Guides (STIGs) across all routing, switching, and cloud-native network components.
• Support civilian Security Assessments, vulnerability remediation cycles, continuous monitoring, and Authorization to Operate (ATO) activities to preserve the network's authorized operations status.
Diagnostics, Automation & Operational Support
Operational readiness demands rapid troubleshooting, automated infrastructure management, and rigorous environment isolation:
• Provide tier-3 diagnostic expertise to resolve complex enterprise network failures affecting critical systems, utilizing deep-packet analysis (such as Wireshark) and performance tracking to isolate packet loss, latency, or routing loops.
• Proactively monitor physical and virtual infrastructure performance using enterprise-grade monitoring suites including Riverbed, NetFlow, SolarWinds, AWS Network Manager, and Cisco Catalyst Center.
• Automate the deployment and configuration of physical network components and AWS resources utilizing modern Infrastructure-as-Code (IaC) and configuration management tools including Terraform, AWS CloudFormation, Ansible, Python scripting, and structured CI/CD pipelines.
• Build, maintain, and support a segregated, realistic test lab environment to validate software patches, firewall rules, and cloud infrastructure modifications prior to production release.
• Coordinate closely with external telecommunications vendors and ISP engineering teams to troubleshoot high-capacity circuits and resolve external carrier network disruptions.
• Deliver professional technical mentorship, direction, and coaching to junior network engineering and operations staff.
• Serve in an on-call capacity after standard business hours, with the critical operational requirement to respond rapidly to emergency network outages or degradation.