Principal Network Architect / Subject Matter Expert (SME)
Valiant SolutionsPosition Description
Valiant Solutions is seeking a Principal Network Architect / Subject Matter Expert (SME) to serve as the senior technical authority for a nationwide enterprise network operations consolidation supporting our government customer. Today the customer's network is managed in silos by separate vendors and internal teams across cloud, WAN, LAN, and security, which slows incident resolution and stalls modernization. This role owns the end-to-end design that replaces that model: a single operating picture spanning campus LAN, a carrier MPLS WAN reaching roughly 50 sites, two enterprise data centers, and two public cloud platforms.
The architect sets technical direction for the agency's Zero Trust and IPv6 programs, grounded in NIST SP 800-207, TIC 3.0 reference architectures, and the federal IPv6 mandate in OMB M-21-07. This is a hands-on senior engineering role rather than a management position, and it serves as the final escalation point for Tier 3 architectural root cause analysis.
Named one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!
This position is based in Silver Spring, MD, and allows for partial remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.
Responsibilities
Transition, Consolidation, and Assessment
- Lead the technical content of the 60-day phase-in, including validation of the device inventory across Cisco Catalyst and Nexus switches, Cisco Firepower Threat Defense firewalls, Cisco ISE appliances, and Ubiquiti UniFi and Meraki switches.
- Direct the initial enterprise network assessment covering design, security, redundancy, and performance posture, and identify the gaps that block the target Zero Trust architecture.
- Drive knowledge transfer from incumbent staff and government engineers, capturing undocumented operational procedures and reconciling them against existing network standard operating procedures.
- Define the ITIL v4 aligned service management model that replaces tool-by-tool operation, and set the architecture for a consolidated monitoring dashboard aggregating MPLS WAN, data center fabric, and cloud telemetry.
- Assess the existing ServiceNow ITSM workflow used for network service requests and deliver written recommendations through the customer's review process.
Network Design, Redundancy, and Tier 3 Engineering
- Conduct the network design review within the first 90 days of performance and annually thereafter, identifying single points of failure in internet, DMZ, and cloud egress paths.
- Verify that the hot-hot aggregation design across the Seattle and Ashburn data centers survives the loss of any single circuit or backbone device without dropping internet or cloud connectivity.
- Plan and evaluate failover testing with the security team to confirm that backup paths activate automatically.
- Serve as the Tier 3 escalation authority for architectural root cause analysis, complex code upgrades, and disaster recovery execution.
- Review and approve Methods of Procedure before Change Control Board submission, including rollback plans and risk assessments, to protect the change success rate standard.
Multi-Cloud and Carrier Architecture
- Own BGP traffic engineering across the carrier MPLS backbone, transport circuits, and cloud interconnects to prevent suboptimal routing between on-premise and cloud workloads.
- Confirm that all cloud connectivity conforms to TIC 3.0 reference architectures so that cloud traffic is inspected and logged as required.
- Set Quality of Service policy on customer edge routers so that mission data and VoIP traffic receive priority across the wide area network.
- Act as the senior technical escalation point in carrier disputes, directing intrusive testing windows and vendor management escalation during circuit outages.
Modernization and IPv6 Transition
- Own the enterprise IPv6 transition plan and drive the enterprise from a roughly 5 percent dual-stacked endpoint baseline toward the 80 percent target, including cloud environments that are currently IPv4-only.
- Manage the interim dual-stack environment, keeping OSPFv3 and MP-BGP routing tables synchronized and stable.
- Maintain the enterprise IPv6 addressing plan and prefix allocation across sites, data centers, and cloud tenancies.
- Design NAT64 and DNS64 translation services if legacy IPv4-only applications are identified during migration.
- Identify End-of-Life and End-of-Support hardware and propose replacement paths that support TrustSec and native IPv6.
- Lead quarterly architecture reviews that adapt the design to changing traffic patterns such as increased cloud egress.
Qualifications
Experience and Education
- 8 years of progressive network architecture experience, including enterprise LAN, WAN, and data center design.
- Bachelor's degree in Computer Science, Information Systems, Mathematics, Engineering, or a related field. Four additional years of relevant experience may substitute for the degree.
- Demonstrated experience acting as the senior technical authority for a nationwide or multi-site enterprise network.
- Experience consolidating fragmented, multi-vendor network operations into a single operating model.
Technical Skills
- Deep routing and switching expertise across OSPF, OSPFv3, BGP, MP-BGP, and EIGRP redistribution in carrier-managed environments.
- Carrier-grade WAN design, including MPLS service management, Quality of Service policy, and circuit performance analysis using latency, jitter, packet loss, and availability metrics.
- Data center fabric design with Cisco Catalyst and Nexus platforms, including Data Center Interconnect tuning for storage replication.
- Multi-cloud network architecture across Oracle Cloud Infrastructure and Google Cloud Platform, including dedicated interconnect and hybrid routing design.
- Zero Trust network design incorporating Cisco Identity Services Engine, TrustSec Security Group Tags, and identity-based firewall policy.
- IPv6 transition planning at enterprise scale, including dual-stack operations, addressing plans, and translation gateways.
- Familiarity with Infrastructure as Code practice using Terraform, sufficient to set standards for the engineering team.
Communication and Stakeholder Engagement
- Written and verbal communication skills sufficient to explain network and security concepts to both engineers and non-technical government stakeholders.
- Ability to brief senior government leadership, including the Contracting Officer's Representative and Technical Lead, on incident root cause, risk, and remediation.
- Clear technical writing for Methods of Procedure, topology diagrams, standard operating procedures, and monthly status report inputs.
- Ability to work as a contractor employee in a non-personal services environment, identifying as contractor staff in all meetings, correspondence, and system records.
Federal Knowledge
- Working knowledge of federal network security direction, including Zero Trust Architecture (NIST SP 800-207), Trusted Internet Connection (TIC) 3.0 reference architectures, and the IPv6 mandate under OMB M-21-07.
- Familiarity with NIST SP 800-53 Rev. 5 security and privacy controls as they apply to network and boundary protection.
- Understanding of HSPD-12 identity credentialing and its enforcement in network access decisions.
- Awareness of Section 508 accessibility requirements (WCAG 2.0 AA) as they apply to contract deliverables.
- Experience operating inside a federal change control process, with government-approved documentation and deliverable acceptance criteria.
The following are preferred:
- CCIE Enterprise Infrastructure or CCNP Enterprise.
- CCNP Security or Cisco Certified Specialist – Security Identity Management Implementation (300-715 SISE).
- A cloud networking certification relevant to the environment, such as Google Professional Cloud Network Engineer or Oracle Cloud Infrastructure Architect.
- ITIL v4 Foundation certification is preferred, given the requirement to unify operations under an ITSM framework.
About Valiant Solutions
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology’s Fast 50, and Washington Business Journal’s Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you’ll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect – and we trust them to deliver results leveraging their expertise. If you would enjoy working in a dynamic environment as part of a stellar team of professionals, then we invite you to apply online today.
Benefits Snapshot (includes, but not limited to)Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time EmployeesValiant contributes 25% towards Health Coverage for Family and Dependents100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees100% Paid Certifications401K Matching up to 4%Paid Time OffPaid Federal HolidaysWellness & Fitness ProgramValiant University – Online Education and Training PortalFSA programs for: Medical Costs, Dependent Care, Transit, and ParkingReferral Bonuses
The salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the xxx- xxx range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.
Remote Work Policy
Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General’s effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.
Equal Employment Opportunity
Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.
Physical Demands
Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.
Authorization to Share Resume and Personal Information
By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.