In this role you will help architect, build, and sustain high-availability launch and test networks that span classified and unclassified enclaves. As a network-strong engineer with meaningful cyber depth, you will lead network design, implementation, and performance tuning while partnering with cyber teams to embed RMF-aligned protections and secure baselines into the infrastructure. You will design and plan network communications systems, produce specifications and detailed schematics, recommend hardware and software to meet present and future capacity requirements, test network designs, and evaluate emerging communications technologies. You will join a customer-supported engineering team in the San Antonio, TX area and maintain deep technical expertise across routers, switches, firewalls, multiplexers, bridges, and gateways. This position is 100% onsite and requires an active Top Secret clearance with SCI eligibility.
Schedule: full-time schedule.
Responsibilities
- Design, plan, configure, and sustain complex, multi-node enterprise-scale networks spanning classified and unclassified enclaves, maintaining detailed schematics and specifications for routers, switches, firewalls, multiplexers, bridges, and gateways.
- Partner with customer ISSMs/ISSOs and cyber engineering teams to develop and implement network changes in environments operating under, or seeking, an ATO/IATT, keeping designs aligned to RMF requirements.
- Lead end-to-end testing and validation of network designs, verifying configurations and monitoring hardware and link performance for reliability, availability, and compliance with security policy.
- Develop and execute implementation plans for enhancements, upgrades, and migrations, coordinating with stakeholders to minimize service disruption and documenting all changes and rollback plans.
- Engineer and operate core network services (DNS, DHCP, NTP, AAA) and segmented architectures that enforce well-defined trust boundaries and enable controlled information sharing across enclaves.
- Implement and tune network-level security controls — firewalls, VPNs, ACLs, IDS/IPS, and NAC — in close coordination with cyber and security teams so protections are built in rather than bolted on.
- Support network operations including fault and performance monitoring, incident response, and change management, using NMS and log/SIEM platforms within an integrated NOC/SOC construct.
- Perform physical-layer installation work (fiber, patch panels, encryption devices), maintain accurate as-built documentation and configuration baselines, and brief technical options, trade-offs, risks, and recommendations to internal and external stakeholders.
Basic Qualifications
- Bachelor's degree in a Science, Technology, Engineering, or Mathematics (STEM) discipline from an accredited institution and 8 years of related professional/military engineering experience; or a Master's degree in a STEM discipline and 6 years; or a Ph.D. in a STEM discipline and 4 years.
- U.S. citizenship with a current DoD Top Secret security clearance and SCI eligibility/access active within the last 24 months.
- DoD 8570 IAT Level II certification (e.g., Security+ CE) or equivalent prior to start.
- Hands-on experience planning, implementing, operating, and troubleshooting routed and switched IP networks (IPv4, OSPF, VLANs, VPNs, firewalls) in mission-critical or real-time environments, including administration of Microsoft and Linux networked systems and applying foundational cybersecurity practices (hardening, secure configuration, access control) alongside cyber/security teams.
Preferred Qualifications
- Proven experience as a network design authority or principal engineer for new deployments or major redesigns from concept through cutover, including high- and low-level designs, ICDs, addressing and routing plans, firewall/ACL matrices, and NOC runbooks.
- Extensive hands-on experience designing, implementing, and maintaining enterprise-scale physical and virtual networks (Cisco routing/switching, firewalls, VPNs, VMware vSphere/ESXi/NSX) with well-maintained schematics and configuration baselines.
- Deep routing and switching expertise in enterprise or mission networks — route filtering, convergence tuning, VLAN/VXLAN, spanning-tree variants, MLAG/port-channeling, QoS and traffic engineering — plus tuning of firewalls, IDS/IPS, NAC, and endpoint protection; Cisco CCNP or higher (e.g., CCIE) strongly preferred.
- Experience architecting and supporting multi-node test or launch networks for test ranges, weapon systems, or other real-time mission systems where latency, determinism, and availability are critical.
- Strong experience engineering and securing DNS, DHCP, NTP, and AAA (RADIUS/TACACS+) in mission-critical networks, including split-horizon DNS, DNSSEC, DHCP authorization, authenticated NTP, and integration with identity systems such as Active Directory.
- Extensive experience designing segmented architectures (user, server, management, security, out-of-band) with well-defined trust boundaries in multi-domain or cross-domain environments, including controlled information sharing between classified and unclassified networks using guards, data diodes, and MLS/CDS solutions.
- Demonstrated ability to align network architecture with RMF/ATO requirements and apply DISA STIGs and CIS benchmarks to routers, switches, firewalls, and VPN gateways, building standard baselines (AAA, logging, NTP, SNMP, management access, banners, crypto settings) and verifying compliance at scale.
- Proficiency in network automation, configuration management, and Infrastructure-as-Code (Ansible, Python, Bash, PowerShell), including device provisioning, configuration templating, drift detection, bulk policy updates, and automated compliance checks.
- Experience working within an integrated Network Operations Center — fault and performance monitoring, event correlation, escalation workflows, and SOC collaboration — with strong layer 1–7 troubleshooting and a track record of restoring service quickly.
- Experience leading end-to-end network testing and validation, including performance, resiliency, and failover testing in distributed environments, and executing upgrade and migration plans while minimizing mission impact; experience with VoIP, SIP trunking, and QoS in converged voice/data networks is highly desired.
- Strong interpersonal, written, and verbal communication skills, with demonstrated ability to work across cyber, systems, software, and test teams to capture requirements, document designs and decisions, and brief options, trade-offs, and risks to technical stakeholders and leadership.
Note: This position is intended to be contract-to-hire. While that is the intent, it is not a promise of conversion by our client. This contract role aligns with a full-time Senior Principal Network Systems Engineer position.
Benefits — tailored to your needs
When establishing benefits, our employees lead the charge. Benefits available may include:
- Flexible scheduling where available
- 401(k) with 4% company match
- Health, dental, and vision insurance
- Healthcare savings account (HSA)
- Paid time off, including holidays
- Performance-based bonuses
About Gentry Professional Services
Gentry Professional Services is an elite consulting firm connecting top-tier industry experts with challenging projects and alternative work arrangements. For more information, visit gentryservices.com or follow us on LinkedIn.