Location Washington, DC — hybrid; on-site as required by task assignment Employment Type Full-time — contingent upon contract award Salary Range $92,000 – $110,000 Clearance / Suitability Public Trust (Tier 2); U.S. citizenship or permanent residence required Position Summary The Network Engineer provides secure engineering and operational support for a U.S. legislative branch agency's Cisco-based enterprise network. The role designs, implements, and sustains secure network architectures that enforce Zero Trust principles — segmentation, micro-segmentation, and least-privilege access — while hardening and continuously monitoring switches, routers, and perimeter systems in accordance with federal cybersecurity standards (NIST SP 800-53 and NIST SP 800-207) and Cisco best practices. Key Responsibilities Operate, optimize, and troubleshoot the Cisco core, distribution, access, and edge network infrastructure to ensure reliability, performance, and availability. Configure and manage routing, switching, VLANs, DNS, DHCP, and VPN services with secure, standards-aligned configurations. Implement and maintain network security controls aligned with NIST SP 800-53 (AC, CM, SC, AU control families). Enforce Zero Trust architecture per NIST SP 800-207, including network segmentation, micro-segmentation, and continuous verification of users and devices. Deploy and manage 802.1X port-based network access control (NAC) and least-privilege, identity-aware access across all network layers. Harden network devices to secure configuration baselines (e.g., Cisco Secure Configuration Guides); secure perimeter and public-facing assets through ingress/egress filtering, firewall rule optimization, and MFA for administrative access. Configure centralized logging and forward logs to the enterprise SIEM; support continuous, real-time (24/7) monitoring and alerting. Conduct continuous monitoring and vulnerability assessments aligned with the NIST Risk Management Framework (RMF); coordinate patching, firmware updates, and remediation. Support incident response with network-level analysis, containment actions, and forensic data collection. Perform root cause analysis (RCA) for network incidents; develop and maintain network diagrams, configuration baselines, and Standard Operating Procedures (SOPs). Serve as technical adviser on complex service-desk tickets, collaborating with cloud, Microsoft engineering, and cybersecurity teams. Required Qualifications Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field (equivalent experience considered). Minimum 8 years of hands-on enterprise network engineering experience in Cisco environments. Demonstrated expertise in routing and switching, VLANs, DNS/DHCP, VPNs, and 802.1X network access control. Working knowledge of NIST SP 800-53 controls and NIST SP 800-207 Zero Trust Architecture. Active Cisco certification (CCNP or CCNA) or equivalent demonstrable expertise. S. citizenship or permanent residence status; ability to obtain a Public Trust (Tier 2) determination. Preferred Qualifications CCNP Enterprise or CCNP Security; CompTIA Security+ (DoD 8140/8570 IAT Level II). Experience with Cisco ISE, TrustSec/MACsec, and Catalyst 9300 StackWise environments. Experience with next-generation firewalls (Check Point or Palo Alto) and secure web gateways (e.g., iBoss). Familiarity with SIEM (Microsoft Sentinel or Splunk) and network monitoring tools (SolarWinds, ThousandEyes). Prior experience supporting federal or Congressional / legislative branch environments. Clearance, Suitability & Security U.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier 2) suitability determination and will undergo an FBI criminal background check and U.S. Capitol Police fingerprinting prior to starting work, in accordance with the contract's security requirements. Remote work is authorized; however, on-site presence at the customer's facilities in Washington, DC (and, as needed, data-center/computing facilities in Ashburn, VA and Manassas, VA) may be required based on task assignment. Local travel to these sites is non-reimbursable. Core hours are 9:00 AM–6:00 PM ET, Monday–Friday; occasional after-hours or weekend maintenance activity may be required. Compensation Salary Range: $92,000 – $110,000, commensurate with experience, education, and certifications. INNOVIM offers a comprehensive benefits package including health, dental, and vision coverage, retirement savings, paid time off, and professional development support. ime off, and professional development support.
Senior Network Engineer - CBO
INNOVIM
Cybersecurity Engineer - CBO
INNOVIM
Software Development Engineer
Workday
Senior Machine Learning Engineer - AI Platform
Workday
Application Development Engineer - I/O + T&M
Beckhoff Automation
Cloud Security Engineer
Lucyrx