- Salary
- $240k – $310k
- Location
- US-MD-Fort Meade1-8608 (MD063), United States of America
- Workplace
- Onsite
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Education
- Master
- Clearance
- Required
- Source
- Workday
Description
Purpose and Impact:
Are you ready to apply your leadership to shape the Cyber, Security, & Intel landscape? Amentum is seeking a Network Security Architect Lead, Principal to join our team of mission-driven professionals at Fort Meade, MD. In this role, you will lead challenging, high-visibility projects that directly impact the Nation’s defense and intelligence missions.
Supporting DISA, Amentum’s Intel and Cyber Division is expanding a proven team of highly skilled engineers and architects to design, deploy, and sustain an innovative IT enterprise solution. As the Principal Network Security Architect, you will serve as the technical visionary and authority for this team, defining secure network boundaries, driving the implementation of zero-trust architectures, and ensuring seamless security integration across complex enterprise environments.
Our team delivers secure, mission-critical capabilities where system integrity and rapid deployment are paramount. We are seeking a Network Security Architect Lead, Principal who combines meticulous security engineering discipline with strategic technical foresight. In this role, you will lead efforts to establish and maintain highly secure, resilient network architectures in a rapidly evolving operational threat environment. Success requires the ability to navigate complex, cross-functional technical dependencies independently while fostering collaborative engineering solutions across integrated teams. To excel, you must possess a proactive leadership mindset and the agility to rapidly master and govern the secure integration of next-generation systems and services.
Work Schedule: 8 Hours per day, Monday thru Friday
Essential Responsibilities:
- The duties and responsibilities of the Network Security Architect Lead, Principal include but are not limited to the following:
- Serve as the principal technical authority and visionary for the secure design, engineering, and evolution of the enterprise IT network infrastructure.
- Architect and engineer high-performance, resilient network transport solutions leveraging enterprise Cisco routing and switching platforms across multi-site environments.
- Design, deploy, and govern robust perimeter and boundary defense systems utilizing Palo Alto Next-Generation Firewalls (NGFW), including advanced threat prevention, SSL decryption, and security policy management.
- Lead the security engineering efforts necessary to navigate the Risk Management Framework (RMF) Assessment & Authorization (A&A) process, ensuring all designs comply with DISA Security Technical Implementation Guides (STIGs) and secure an active Authority to Operate (ATO).
- Define the architectural standards, blueprints, and TTPs for secure network integration, data flow segregation, and cross-domain solutions.
- Set the technical and daily priorities for the network security engineering team, providing advanced mentorship, design standards, and escalation support for complex network anomalies.
- Translate complex, high-level operational requirements and DISA security mandates into detailed technical specifications, low-level network designs (LLD), and security architecture diagrams.
- Organize and lead technical architecture reviews, change control assessments, and security posture briefings with senior program leadership and DISA technical authorities.
- Collaborate with Systems Engineers, Cloud Architects, and Project Managers to design secure interfaces and schedule authorized service interruptions (ASIs) for critical network upgrades.
- Conduct comprehensive vulnerability assessments and threat modeling on the network architecture, identifying potential exploit vectors and engineering robust mitigation solutions.
- Establish baseline configurations and configuration control templates for all network and security hardware, ensuring strict alignment with configuration management policies.
- Lead technical site surveys, evaluate infrastructure readiness, produce detailed Network Bills of Materials (BOMs), and assist in generating migration schedules for enterprise site deployments.
Work Environment, Physical Demands, and Mental Demands:
- Employee will work in a SCIF on a daily basis.
- Employee may also be required to work in a datacenter environment for specified periods of time.
Minimum Requirements (Knowledge, Skills, and Abilities):
- Fifteen (15) years of experience in network engineering, security architecture, or systems integration, with a primary focus on designing large-scale enterprise secure networks.
- Seven (7) years of dedicated experience as a senior network security engineer, with at least three (3) years serving as a principal architect or technical lead overseeing security engineering teams.
- Bachelor’s degree in Network Engineering, Computer Science, Information Technology (IT), Cybersecurity, or a related technical field (equivalent experience may be considered in lieu of a degree).
- Extensive background designing and maintaining high-performance networks using Cisco routing and switching platforms (e.g., Nexus, Catalyst, ISR/ASR series) across enterprise and data center enclaves.
- Hands-on technical depth engineering, configuring, and managing Palo Alto Next-Generation Firewalls (NGFWs), including Panorama, App-ID, User-ID, and advanced threat prevention profiles.
- Proven experience navigating the Risk Management Framework (RMF) and designing network architectures that meet NIST SP 800-53 controls and DISA STIGs to secure and maintain a government Authority to Operate (ATO).
- Active DoD 8140/8570.01-M Information Assurance Management (IAM) Level III or Information Assurance Technical (IAT) Level III certification (such as CISSP, CISM, or CompTIA CASP+) to meet secure environment compliance requirements.
- Strong technical depth to produce complex architectural artifacts, including High-Level Designs (HLD), Low-Level Designs (LLD), Network Diagrams (Visio), and detailed Network Bills of Materials (BOMs).
- Excellent communication, leadership, and technical presentation skills, with a track record of defending complex network security designs before DISA Technical Control Boards and senior leadership.
- Ability to support non-standard hours, including scheduled maintenance windows, deployment surges, and emergency incident response architectures.
- Ability to travel up to 10%.
Security Clearance Required:
- Must have active Top Secret clearance with SCI eligibility
Minimum Education:
- Bachelor’s degree in Computer Science, Information Technology (IT), Systems Engineering, or related technical field. Additional years of experience can substitute for degree.
Required Certifications and Qualifications:
(Minimum of 2 required, other within 180 days of hire):
- Cisco Certified Internetwork Expert (CCIE) – Security
- Palo Alto Networks Certified Network Security Engineer (PCNSE) or Palo Alto Networks Certified Network Security Consultant (PCNSC).
- F5 Certified Administrator BIG-IP
- HAIPE Configuration/Management Experience
- CISSP-ISSAP (Information Systems Security Architecture Professional) or CISSP-ISSEP (Information Systems Security Engineering Professional) concentration.
- Prior experience acting as a Lead Architect or Principal Engineer on high-consequence DISA or DoD programs at Fort Meade.
- Familiarity with Software-Defined Networking (SDN) technologies such as Cisco SD-Access or Cisco SD-WAN.
#javelin
As part of our commitment to maintaining a safe and compliant work environment, Amentum is a drug-free workplace and requires all personnel to comply with company drug and alcohol policies as a condition of employment. Employment is contingent upon successful completion of the drug screening process. Please note that this may include pre-hire screening for marijuana, as well as other federally controlled substances due to Amentum’s role as a federal contractor and trusted partner to the US Government.
Other Responsibilities:
Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.
Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.
Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.
Compensation Details:
$240,000 - $310,000
The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.
Benefits Overview:
Our health and welfare benefits are designed to support you and your priorities. Offerings include:
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (including 401(k) matching)
Educational reimbursement
Parental leave
Employee stock purchase plan
Tax-saving options
Disability and life insurance
Pet insurance
Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.
Original Posting:
10/09/2026 - Until FilledAmentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.
Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters.