About this role
Applied Research Associates (ARA), Inc. is seeking an experienced Network Engineer to design, operate, secure, and sustain classified and mission-supporting network infrastructure within the Integrated Mission Systems Sector in Raleigh, NC. The engineer will support Cisco switching and routing, Cisco and Palo Alto firewalls, integration with Splunk and Forescout, vulnerability remediation, configuration management and documentation of the above. This position requires an active DoD Secret clearance with eligibility for Top Secret and close coordination with system administrators, cybersecurity personnel, program teams, and Government stakeholders.
Staff Network Engineer Primary Responsibilities:
- Build out documentation of current Infrastructure via Server, Cable and PPSM and Port maps under Raleigh Secure IT ownership. Use to provide guidance to information owners on future expansion and recommendations for improvement.
- Design, configure, maintain, and troubleshoot LAN infrastructure supporting classified and mission environments, including SIPRNet where assigned while applying DISA STIG and NIST 800-53 controls.
- Fully administer platforms such as Cisco Catalyst's Switches, ARS/ISR Router's, Dell Fabric Switches, Palo Alto 450's and Cisco ASA 1000's and integrate with ForeScout/ISE, Splunk and AAA services.
- Fully Administer operating systems such as IOS, IOS-XE, FTD/ASDM, PaloAlto, SmartFabric OS10.
- Implement and support Layer 2 technologies including STP , 802.1Q VLANs, QoS, 802.1X / MAB, DAI and additional port-security.
- Implement and support Layer 3 technologies including static and dynamic routing, BGP, ACLs, VRFs, traffic shaping, and rate limiting as applicable.
- Maintain secure network segmentation, boundary protection, firewall policy, routing controls, DNS and approved external or DoDIN connectivity.
- Integrate network infrastructure with Splunk, Forescout or other SIEM platforms to monitor network availability, performance, capacity, configurations, and security events.
- Apply applicable DISA STIGs, secure configuration baselines, software updates, vulnerability remediation, and hardening requirements to network devices.
- Develop and maintain network diagrams, IP address plans, device inventories, rack elevations, ports/protocols/services records, configuration baselines, standard operating procedures, and recovery documentation.
- Prepare implementation, validation, and rollback plans and execute approved changes through the Configuration Control Board process.
- Support cybersecurity incidents, outages, Government-directed actions, assessment activities, and after-hours maintenance when mission requirements demand it.
- Provide technical evidence and engineering support for RMF, ATO maintenance, continuous monitoring, DCSA reviews, and customer assessments.
Staff Network Engineer Qualifications:
- US Citizen with an active DoD Top Secret clearance; SCI eligibility preferred
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field along with 2-4 of relevant work experience.
- 8+ years of relevant network engineering, administration, or operations experience; additional directly relevant experience may substitute for a degree.
- Strong troubleshooting ability across OSI Layers 1 through 4, including packet and log analysis.
- Experience with network monitoring, configuration management, backup/recovery, patching, vulnerability remediation, and technical documentation.
- Ability to meet DoD 8570 / 8140 cybersecurity workforce qualification requirements applicable to the assigned work role. (IAT Level – II).
- Demonstrated ability to communicate technical risk, authorization status, deficiencies, and resource needs to technical staff, program leadership, and Government stakeholders.
Staff Network Engineer Preferences:
- CCNA, CCNP, or another relevant networking or security certification.
- Experience supporting SIPRNet, DoDIN connectivity, classified contractor environments, or DCSA-authorized systems.
- Experience with Cisco Firepower, network automation, Forescout, Splunk, TACACS+/RADIUS, network-access control, virtualization, or high-availability architectures.
Who is ARA?
Do you want to work for a purpose? Applied Research Associates, Inc. (aka ARA) is an employee-owned international research and engineering company. We have been providing technically superior solutions to complex and challenging problems in the physical sciences since 1979. ARA has over 2,279 employee owners and continues to grow rapidly. Together, our offices throughout the U.S. and Canada provide a broad range of technical expertise in defense, civil, and health technologies, computer software and simulation, systems analysis, environmental technologies, and testing and measurement.
ARA also prides itself, on having a challenging culture where innovation & experimentation are the norm. The motto, Engineering and Science for Fun and Profit sums up the ARA experience. Employee ownership ensures you have a voice with what happens in the company.
To find out more about what the Integrated Mission Systems Sector has to offer, visit our website at https://www.ara.com/raleigh/
To learn more about our generous benefits program including health, life & disability, retirement, flexible spending, rewards & recognition, work/life balance, professional development and relocation visit https://www.ara.com/benefits/
