Jobs and Careers
KE

Senior Network Engineer

KeenLogic
Washington, United Statesfull_timeVerifiedPosted 4 Jun 2026

About the role

KeenLogic is seeking a Senior Network Engineer to support a federal program at the Congressional Budget Office (CBO). The Senior Network Engineer will provide advanced engineering, operational, and advisory support for CBO's enterprise Cisco network environment, ensuring the security, reliability, and resilience of critical network infrastructure while supporting ongoing cybersecurity modernization initiatives. 

The Senior Network Engineer will design, implement, and maintain secure network architectures across core, distribution, access, and edge environments, with a strong focus on Zero Trust principles, network segmentation, identity-based access controls, and continuous monitoring. This role will lead efforts to strengthen CBO's network security posture, support incident response and vulnerability remediation activities, and ensure compliance with federal cybersecurity standards, including NIST and Zero Trust Architecture requirements. The position combines deep technical expertise, strategic network engineering, and cross-functional collaboration to support mission-critical infrastructure and enhance the organization's overall cybersecurity readiness. 

Candidates must be able to support on-site work as-needed in Washington, DC. This position supports a long-term federal contract, offering up to five years of continued work. This is a full-time position with an anticipated start date of August 15, 2026. KeenLogic offers Fortune 500-level benefits, including health, dental, and vision insurance, PTO, 401(k), and life insurance. 

Required Qualifications 

  • U.S. Citizen and eligible for a Public Trust clearance 

  • Bachelor's degree in an IT-related field.  

  • 7+ years of experience designing, implementing, and supporting enterprise network infrastructure, including large-scale Cisco environments.  

  • 5+ years of experience leading network architecture, security engineering, or infrastructure modernization initiatives.  

  • Demonstrated experience implementing Zero Trust Architecture, network segmentation, micro-segmentation, identity-based access controls, and 802.1X authentication.  

  • Extensive experience with enterprise routing, switching, firewalls, VPNs, DNS, DHCP, network monitoring, and security operations.  

  • Experience supporting federal cybersecurity compliance requirements, including NIST SP 800-53, NIST SP 800-207, RMF, and related security frameworks.  

  • Experience serving as a technical lead, advisor, or subject matter expert supporting complex network engineering projects. 

Job Duties and Responsibilities  

  • Implement and maintain network security controls aligned with NIST SP 800-53, including access control (AC), configuration management (CM), system and communications protection (SC), and audit and accountability (AU) control families.  

  • Engineer and enforce Zero Trust network architecture principles in accordance with NIST SP 800-207, including network segmentation, micro-segmentation, and continuous verification of users and devices. 

  • Design and implement least-privilege network access controls, ensuring role-based and identity-aware access across all network layers. 

  • Deploy and manage 802.1X port-based network access control to prevent unauthorized device connectivity and enforce authentication at the network edge.  

  • Configure and maintain centralized logging and audit capabilities for all network devices, ensuring logs are forwarded to enterprise SIEM platforms and retained in accordance with compliance requirements. 

  • Conduct continuous monitoring and vulnerability assessments of network infrastructure, identifying risks and coordinating remediation in alignment with NIST Risk Management Framework (RMF) practices.  

  • Harden all network devices using secure configuration baselines (e.g., Cisco Secure Configuration Guides), including disabling unnecessary services, enforcing strong encryption protocols, and securing management interfaces.  

  • Secure public-facing and perimeter network assets by implementing strict ingress/egress filtering, firewall rule optimization, and multi-factor authentication for administrative access.  

  • Support incident response activities by providing network-level analysis, containment actions (e.g., segmentation, blocking malicious traffic), and forensic data collection.  

  • Establish and maintain secure network segmentation strategies to limit lateral movement and protect high-value assets and sensitive environments.  

  • Ensure all network changes follow formal change control processes with security impact analysis, supporting c

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

KeenLogic

View company profile →