Senior Network Engineer
Description
Vamonos IT is seeking an experienced Senior Network Engineer to design, deploy, secure, and operate highly available network infrastructure for government and commercial customers. This hands-on senior individual contributor will own routing and switching architecture, network security, carrier/peering relationships, automation, monitoring, troubleshooting, and incident response.
The ideal candidate combines deep networking and protocol knowledge with strong automation skills and the ability to communicate effectively with both technical teams and customers.
Key Responsibilities
- Design, implement, and maintain enterprise and service-provider networks across on-premises, colocation, and cloud environments.
- Configure and operate BGP, OSPF, and other dynamic routing protocols, including route policy, redistribution, filtering, and traffic engineering.
- Manage upstream transit, peering, internet exchange, and routing relationships.
- Plan and manage IPv4/IPv6 addressing, subnetting, dual-stack deployments, ARIN/RIR resources, IRR, and RPKI.
- Implement network security through segmentation, firewalls, ACLs, VPNs, tunneling, access controls, and DDoS mitigation.
- Deploy and maintain monitoring, alerting, flow analysis, and network observability systems.
- Automate network configuration, validation, and deployment using Python, Bash, Go, Ansible, Terraform, or similar tools.
- Lead troubleshooting and incident response for complex network issues, including packet-level analysis and root-cause investigations.
- Perform capacity planning, lifecycle management, maintenance windows, and network cutovers with minimal customer impact.
- Maintain network diagrams, IP/asset records, runbooks, configurations, and change documentation.
- Support compliance and audits by providing configuration evidence, remediating findings, and enforcing security baselines.
- Serve as a technical escalation point and mentor junior engineers while working directly with customer technical contacts.
Required Qualifications
- 6+ years of professional network engineering experience in production environments; exceptional senior candidates may qualify through demonstrated technical ownership and portfolio work.
- Expert TCP/IP knowledge and hands-on production experience with BGP plus at least one IGP (OSPF, IS-IS, or EIGRP).
- Strong routing and switching fundamentals, including VLANs, trunking, spanning tree, link aggregation, QoS, MTU, and fragmentation.
- Experience with enterprise or carrier-grade platforms such as Cisco IOS/NX-OS, Juniper Junos, Arista EOS, MikroTik RouterOS, or equivalent.
- Practical experience with firewalls, IPsec/WireGuard/SSL VPNs, tunneling, and network access control.
- Working knowledge of DNS, DHCP, NTP, TLS/PKI, and load balancing.
- Strong IPv4/IPv6 addressing, subnetting, and dual-stack experience.
- Strong Linux administration and command-line skills.
- Proven troubleshooting skills using tcpdump, Wireshark, packet captures, and flow data.
- Scripting/automation experience with Python, Bash, Go, or similar languages.
- Experience with Git and configuration-as-code practices.
- Ability to work independently in a remote environment, manage priorities, and communicate clearly in writing.
- Legally authorized to work in the United States without sponsorship.
- Ability to pass a background investigation.
- Willingness to participate in an on-call rotation and scheduled after-hours maintenance.
Preferred Qualifications
- Federal government or federal contracting experience, particularly DHS, DoD, or civilian agencies.
- Active, prior, or eligible U.S. security clearance.
- Certifications such as CCNP/CCIE, JNCIP/JNCIE, Arista ACE, Network+, or Security+.
- Service-provider/ISP experience, including internet peering, transit, IXP operations, or RIR resource management.
- Experience with RPKI, IRR, BGP origin validation, and route-security practices.
- Cloud networking experience with AWS, Azure, or GCP, including VPC/VNet design, transit gateways, ExpressRoute/Direct Connect, and hybrid connectivity.
- Experience with Ansible, NAPALM, Nornir, Terraform, CI/CD, or other network automation frameworks.
- Experience with NetFlow, sFlow, IPFIX, Prometheus, Grafana, LibreNMS, ELK, or SIEM integration.
- Advanced security experience involving DDoS mitigation, IDS/IPS, threat modeling, deception, or traffic analysis.
- Experience with SD-WAN, MPLS, VXLAN, or overlay networks.
- Familiarity with NIST 800-53, FISMA, FedRAMP, CMMC, or similar compliance frameworks.
- Open-source contributions or a public networking/systems portfolio.
- Experience mentoring engineers or leading small technical teams.
Education
Bachelor's degree in Computer Science, Information Technology, Network Engineering, or a related field preferred. Equivalent professional experience, military experience, relevant certifications, or demonstrated technical work may substitute for a degree.
Work Environment & Travel
Remote position for candidates authorized to work in the United States. Occasional travel to customer facilities, data centers, or company meetings is required. Participation in an on-call rotation and periodic after-hours maintenance or incident response is expected.
Compensation & Benefits
Vamonos IT offers a competitive benefits package including:
- Medical, dental, and vision insurance
- 401(k) with company contribution
- Paid time off and federal holidays
- Professional development, certification, and training support
- Remote-first work environment
Equal Employment Opportunity
Vamonos IT is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.