|
Apply
Description
Nemean Solutions, headquartered in Sierra Vista, AZ, is a certified SBA 8(a) Native Hawaiian Organization (NHO) and veteran-operated company providing advanced Military Intelligence, Enterprise and Cloud IT services, Cybersecurity, Special Operations Forces (SOF) Exercise and Training, and niche Program Support and Professional Services to Federal and State Agencies supporting the US Government Defense, Intelligence and Aerospace sectors. Job Overview: Nemean Solutions is seeking a Senior Network Engineer / FISMA Compliance Support professional to support the Privacy and Civil Liberties Oversight Board (PCLOB). The primary focus of this position is hands-on ownership of PCLOB's enterprise network environment and the network/security engineering responsibilities. The engineer will independently operate, maintain, secure, troubleshoot, and improve Cisco network and unified communications services. As a secondary responsibility, the position will support the FISMA readiness and continuous compliance activities, including NIST SP 800-53 control documentation, POA&M management, technical evidence, remediation, and Xacta 360 administration. The ideal candidate is first and foremost a senior network engineer who also understands federal FISMA/RMF compliance and can translate network configurations and remediation actions into auditable security-control evidence. Support Hours: Applicant shall be available during core work hours as established the Government customer. Essential Duties & Responsibilities: Enterprise Network Operations and Cisco Engineering - Primary Responsibility
- Serve as the primary technical owner for PCLOB enterprise network operations and maintenance, ensuring the continuous availability, performance, security, and reliability of production network services.
- Design, configure, administer, operate, maintain, and troubleshoot Cisco routing and switching infrastructure, including VLANs, subnetting, ACLs, TCP/IP, DNS, DHCP, routing protocols, IP addressing, and related network services.
- Independently resolve complex production incidents involving routing, switching, firewalls, VPNs, connectivity, name resolution, and IP services; perform root-cause analysis and implement sustainable corrective actions.
- Plan, implement, operate, and maintain network-security technologies and services, including firewalls, VPNs, IDS/IPS, network segmentation, secure remote access, vulnerability remediation, network monitoring, and security policy enforcement.
- Develop and execute network technology project plans, including Cisco Unified Communications Manager (CUCM)/Call Manager and enterprise VoIP capabilities, SIP, QoS, voice VLANs, voice gateways, and wireless/network modernization activities.
- Maintain highly available network services and support integrations with Windows Server, Hyper-V, Linux, server virtualization, Active Directory/identity and access services, Citrix, and related enterprise infrastructure. Maintain accurate physical/logical network diagrams, device inventories, configurations, change records, operating procedures, and troubleshooting documentation.
Security Architecture and Engineering - Primary/Shared Responsibility
- Assess network and security architecture, identify gaps in the security stack, and develop practical roadmaps and implementation plans that improve capability, tune existing tools, reduce unnecessary overlap, and maintain reliable operations.
- Review IT security policies with PCLOB OCIO and provide technical solutions for enforcement through network/security architecture, configuration, access controls, monitoring, and engineering changes.
- Collaborate with PCLOB OCIO, system, cloud, cybersecurity, and security-operations personnel on security-engineering deployments and integrated projects; define milestones, completion dates, resource needs, testing, dependencies, and coordination requirements.
- Provide weekly project updates when requested, identify concerns that could affect milestones or completion dates, and drive assigned network/security engineering actions to closure.
- Provide Security Engineering SME reviews, technical analyses, recommendations, and decision-ready write-ups on an ad hoc basis; support security administrator questions and technical remediation activities.
- FISMA, NIST, and Xacta 360 Compliance Support - Secondary Responsibility
- Support Task 3 FISMA readiness and continuous compliance activities by applying the NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5 requirements to network/security controls, technical configurations, evidence, findings, and remediation.
- Use and maintain Xacta 360 to support security-control tracking, control implementation documentation, assessments, evidence repositories, Plans of Action and Milestones (POA&Ms), remediation milestones, technical validation, and ongoing compliance status.
- Support recurring SSP updates, control inheritance, annual FISMA pre-assessment preparation, baseline compliance evidence, annual submission data/metrics, corrective-action planning, and audit/assessment readiness; ensure network-related artifacts accurately reflect the production environment.
- Review STIG, vulnerability, configuration, and compliance findings; validate technical impact, implement or coordinate corrective actions, document closure evidence, and support compliance briefings, assessor requests, ATO/accreditation activities, and leadership reporting.
Program Support and Customer Engagement
- Coordinate directly with PCLOB OCIO leadership, system administrators, cybersecurity personnel, and other stakeholders to clarify network and security requirements, communicate technical risk, and drive assigned actions to closure.
- Prepare concise network analyses, implementation plans, status updates, risk summaries, and decision-ready technical recommendations for Government and Nemean leadership.
- Participate in change-management reviews, technical exchanges, audit/assessment activities, incident-response exercises, and recurring status meetings as required.
- Maintain project milestones, risks, dependencies, action items, completion dates, and documentation for assigned network, security-engineering, and FISMA-support activities.
Competencies:
- Excellent verbal and written communication skills.
- Excellent interpersonal and customer service skills.
- Excellent organizational skills and attention to detail.
- Excellent time management skills with a proven ability to meet deadlines.
- Ability to prioritize tasks and to delegate them when appropriate.
- Ability to function well in a high-paced and at times stressful environment.
Requirements
Minimum Requirements/Education:
- Bachelor's degree in information technology or a related technical field, plus strong technical documentation, communication, organization, and customer-engagement skills.
- Seven or more years of hands-on enterprise network/security administration and engineering experience, including network design, installation, operations, maintenance, troubleshooting, security, and performance optimization.
- Three or more years of federal FISMA/RMF security-control validation and compliance experience, including NIST SP 800-53 controls, SSPs, POA&Ms, continuous monitoring, technical control evidence, vulnerability/configuration findings, remediation, annual assessment readiness, and hands-on Xacta/Xacta 360 experience.
- Current Cisco Certified Network Associate (CCNA) or Cisco Certified Network Professional (CCNP) certification. CCNP is strongly preferred.
- Must have experience administering Cisco CUCM/Call Manager and enterprise VoIP technologies, including SIP, QoS, voice VLANs, and voice gateways.
- Demonstrated ability to independently own enterprise network operations and complex Cisco routing, switching, VLAN, firewall, VPN, DNS/DHCP, IP addressing, network monitoring, and connectivity troubleshooting in a production environment.
- Hands-on experience configuring, administering, and maintaining firewalls, VPNs, IDS/IPS, network segmentation, ACLs, secure remote-access solutions, network security devices, and vulnerability remediation.
- Hands-on experience with Windows operating systems, Windows Server/Hyper-V, and Linux, with the ability to support network dependencies across virtualized and identity/access environments.
Security Requirement:
- An active TS / SCI security clearance.
Preferred Requirements:
- CompTIA Network+ and/or Security+ certification.
- Advanced hands-on experience with Xacta 360 supporting authorization packages, control inheritance, assessments, POA&Ms, evidence management, remediation, and ongoing FISMA compliance.
- Certification in IT audit, internal controls, cybersecurity compliance, or a related field.
- Hands-on experience with Cisco ISE/NAC/802.1X, Active Directory/identity services, Citrix, NetScaler, Nutanix, Azure/cloud networking, next-generation firewalls, or related enterprise network/security technologies.
- Experience supporting STIG compliance, ATO/accreditation activities, independent assessments, secure federal enterprise environments, and configuration/change-management processes.
The pay range listed represents a good-faith estimate, in accordance with pay transparency requirements, and may vary depending on the candidate's experience, education, and other job-related factors. What Nemean Solutions, LLC offers: Medical, Dental, and Vision insurance plans, Paid Time Off, sick leave, 401k Retirement Savings plan with company match, and more. Nemean Solutions is proud to be a Veteran friendly employer and provides Equal Employment Opportunity (EEO) to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability status, genetic information, marital status, ancestry, protected veteran status, or any other characteristic protected by applicable federal, state, and local laws. Equal Opportunity for VEVRAA Protected Veterans. Nemean Solutions, LLC will not discriminate against employees and job applicants who inquire about, discuss or disclose compensation information. We are a Virginia Values Veterans (V3) Certified Employer and strongly encourage applications from veterans, transitioning service members, and military spouses.
Salary Description
$150,000 and above
|