- Salary
- $92k – $167k
- Location
- 3324 DISA Fort George G. Meade MD, United States of America
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Education
- Master
- Clearance
- Required
- Source
- Workday
Description
Leidos is seeking a Senior Infoblox DDI Engineer to engineer, implement, migrate, and sustain enterprise DNS, DHCP, and IP address management (DDI) services in support of large-scale network operations. The engineer will provide hands-on technical leadership for Infoblox grid infrastructure, DNS, DHCP, IPAM, and associated network services, including design, migration, troubleshooting, testing, security hardening, and production implementation. The position also requires strong routing and switching expertise because DDI services depend on the underlying network for reachability, DHCP relay, segmentation, routing, and high availability. The engineer must be able to troubleshoot issues across both the Infoblox platform and the network infrastructure supporting it.
Scope and Impact
Impact: Contributes to the completion of significant project milestones and recommends technical solutions and improvements that affect program results. Work is performed under general direction, with latitude for independent judgment on technical approach.
Complexity: Resolves complex technical problems requiring in-depth analysis, evaluation of multiple factors, and application of established engineering principles and best practices.
Communication: Communicates technical information, design recommendations, risks, and status to engineering leadership, peer teams, and stakeholders. Explains complex technical concepts clearly to both technical and non-technical audiences.
Knowledge: Strong working knowledge of DNS, DHCP, and IPAM principles and of routing and switching concepts, with demonstrated depth in enterprise DDI platform engineering.
Primary Responsibilities
Infoblox and DDI Engineering
- Engineer, deploy, configure, and sustain Infoblox grid infrastructure, including grid masters, grid master candidates, members, high-availability pairs, and distributed appliances across sites and enclaves.
- Design and maintain enterprise DNS architecture, including authoritative and recursive services, forward and reverse zones, delegation, conditional forwarding, split-horizon views, zone transfers, and DNSSEC.
- Engineer and maintain enterprise DHCP services, including scope and range design, failover and redundancy, reservations, option configuration, relay behavior, and lease management.
- Design and maintain IPAM structure, including network containers, address space allocation, utilization reporting, extensible attributes, and data hygiene across the enterprise.
- Perform Infoblox grid upgrades, patching, backup and restore, capacity planning, licensing, and lifecycle management.
- Integrate Infoblox with Active Directory, network access control, automation platforms, and provisioning workflows via APIs and supported integrations.
- Implement DNS security capabilities such as response policy zones, query filtering and logging, and threat-intelligence-driven blocking where approved.
Routing and Switching Engineering
- Engineer, configure, and implement enterprise routing and switching infrastructure supporting DDI services, including routing policy, VLAN architecture, DHCP relay paths, anycast service delivery, and high-availability designs.
- Support routing protocol configuration and troubleshooting across BGP, OSPF, and EIGRP, including redistribution, filtering, and convergence behavior affecting DDI reachability.
- Perform installation, modification, configuration, testing, and servicing of network equipment, including hardware refresh and software upgrades.
- Provide senior-level troubleshooting for complex connectivity, name resolution, and address assignment issues spanning client, network, and service layers.
Implementation and Documentation
- Develop implementation plans, test and validation steps, rollback procedures, and change documentation for DDI and network changes, and execute them during approved change windows.
- Support DNS and DHCP migrations, consolidations, and namespace cleanup efforts, including data validation and cutover sequencing.
- Apply configuration hardening, STIG requirements, and vulnerability remediation to DDI appliances and network devices.
- Maintain DDI architecture diagrams, namespace and address plans, zone and scope documentation, integration designs, backup and recovery procedures, troubleshooting guides, standard operating procedures, and as-built documentation.
Required Qualifications
- Bachelor’s degree with 8+ years of relevant experience, or a Master’s degree with 6+ years of relevant experience. Additional relevant experience, education, and training may be considered in lieu of a degree.
- Significant hands-on experience engineering, implementing, and troubleshooting enterprise network infrastructure supporting DNS, DHCP, and IP Address Management (DDI) services, including TCP/IP, VLANs, routing, DHCP relay, high availability, and service reachability.
- Working knowledge of enterprise routing protocols, including BGP and OSPF; experience with EIGRP is desirable.
- Strong working knowledge of DNS and DHCP, including DNS resolution, zone management, scope and range design, DHCP options, relay, failover, lease management, and troubleshooting.
- Strong understanding of IPAM principles and practices, including address-space planning, allocation standards, utilization management, and data integrity.
- Demonstrated experience performing enterprise-scale DNS and DHCP migrations, including discovery, data analysis, source validation, migration planning, cutover execution, rollback planning, and post-migration verification.
- Experience migrating DNS and DHCP services from legacy platforms, including Microsoft DNS/DHCP, to Infoblox or equivalent enterprise DDI platforms.
- Hands-on experience with Infoblox Grid architecture, including Grid Masters, Grid Master Candidates, Grid Members, high-availability pairs, delegated administration, and distributed DDI service delivery.
- Experience troubleshooting complex DNS resolution and DHCP address-assignment issues using packet captures, DNS query analysis, DHCP transaction analysis, logs, and network telemetry.
- Experience with DNS architecture and operations, including forward and reverse zones, AXFR/IXFR zone transfers, primary/secondary relationships, delegation, forwarding, recursion, conditional forwarding, and DNSSEC.
- Experience configuring and troubleshooting DHCP relay across routed, segmented, and multi-VRF network environments.
- Experience validating DNS and DHCP data before migration, including DNS records, scopes, reservations, exclusions, leases, options, stale records, and duplicate or conflicting data.
- Experience developing detailed migration runbooks, implementation plans, test procedures, validation criteria, and rollback procedures, and executing DNS/DHCP cutovers during approved production maintenance windows.
- Experience performing post-migration validation of DDI services, including forward and reverse DNS resolution, DHCP address allocation, relay operation, failover, client connectivity, and service availability.
- Experience supporting DDI services across multiple network enclaves, security zones, geographically distributed sites, or other complex enterprise network environments.
- Experience with DNS/DHCP monitoring, alerting, capacity management, availability management, and operational health reporting.
- Experience maintaining configuration baselines and as-built documentation for DNS, DHCP, IPAM, and Infoblox infrastructure.
- Demonstrated ability to identify and resolve dependencies among DNS, DHCP, IPAM, Active Directory, routing and switching infrastructure, applications, identity services, and security controls.
- Ability to analyze, reconcile, and remediate inaccurate or inconsistent DDI data and establish standards for maintaining DNS, DHCP, and IPAM data quality.
- Experience developing and executing technical test plans with documented success criteria, validation evidence, defect tracking, remediation, and operational acceptance.
- Experience supporting formal change-management processes, including change requests, implementation plans, maintenance windows, validation evidence, backout procedures, and post-change documentation.
- Demonstrated troubleshooting experience using packet capture and protocol-analysis tools across multi-vendor enterprise environments.
- Hands-on experience with Infoblox and one or more enterprise networking technologies or platforms, such as Cisco, Aruba, Palo Alto, Dell, or Brocade.
- Experience with IPv6 addressing, DNS, and DHCPv6 in enterprise dual-stack or IPv6 migration environments is desirable.
- Experience automating Infoblox provisioning and DDI data management using WAPI, REST APIs, Python, Ansible, or equivalent automation technologies.
- Experience integrating Infoblox with enterprise services such as Active Directory, PKI, NAC, identity services, configuration-management platforms, monitoring systems, and automation workflows.
- Experience applying cybersecurity hardening, vulnerability remediation, configuration baselines, and applicable DoD security requirements to DDI and supporting network infrastructure.
- Strong written and verbal communication skills, with demonstrated experience developing technical designs, implementation procedures, network diagrams, migration documentation, and operational procedures using Visio, PowerPoint, or similar tools.
- Current DoD IAT Level II certification or higher, such as Security+ CE.
- Active DoD Secret clearance.
Preferred Qualifications
- Infoblox certification (such as Infoblox Core DDI or equivalent) and Cisco Certified Network Professional (CCNP) Enterprise or equivalent.
- Experience with large-scale DNS/DHCP migrations, consolidations, or transitions from Microsoft DNS/DHCP to Infoblox.
- Experience with Infoblox API, WAPI automation, or scripting with Python or Ansible to automate DDI provisioning and data hygiene.
- Experience with anycast DNS delivery and distributed service architectures.
- Experience integrating DDI with network access control, identity-based networking, and segmentation efforts.
- Experience with IPv6 addressing, DNS, and DHCPv6 in enterprise environments.
- Experience integrating enterprise networking and DDI with cloud infrastructure and hybrid connectivity.
- Experience applying DISA STIGs, vulnerability remediation, and configuration hardening.
- Experience with Jira, Confluence, or similar project and knowledge-management tools.
Key Success Factors
- Successfully execute DNS and DHCP migrations with minimal operational impact.
- Maintain DNS, DHCP, and IPAM data integrity before, during, and after migration.
- Detect and resolve dependencies between DDI services and routing, switching, security, identity, and applications.
- Produce repeatable migration procedures that can be executed consistently across multiple SIPR sites and environments.
- Restore or roll back DDI services quickly when migration validation criteria are not met.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
October 9, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $92,300.00 - $166,850.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.