Senior Network Engineer

Washington, D.C. Metro

At Ardent, we hire people who want more than a job — they want to serve a mission that matters. Our teams support the federal government’s most critical national security and defense priorities, helping protect the nation, strengthen resilience, and advance the technologies and capabilities that keep America secure. For veterans, cleared professionals, and purpose-driven innovators, Ardent is a place to continue serving alongside a team that understands the importance of the mission and the people behind it.

We also know top talent has choices, which is why we back our mission with benefits and flexibility that stand out: competitive pay, comprehensive health coverage, flexible PTO, federal holidays off, tuition reimbursement, professional development support, wellness stipends, and a culture that values and rewards hard work, dedication, and adaptability. If you want to build something meaningful, while enjoying the kind of flexibility and support that you need to do your best work — Ardent is where your next mission begins.


Ardent is seeking a Senior Network Engineer to join our team.  

This is a on site position in Washington DC.

Position Description:

• Enterprise Network Engineering: Design, implement, operate, and optimize the Congressional Budget Office’s Cisco-based network infrastructure, including core, distribution, access, and edge environments, to ensure high availability, scalability, performance, and resilience in support of mission requirements.
• Network Security Architecture & Compliance: Implement and maintain network security controls aligned with NIST SP 800-53, NIST SP 800-207 (Zero Trust Architecture), and Cisco security best practices, including continuous monitoring, risk mitigation, and network security posture management.
• Network Access Control & Identity Integration: Engineer and enforce secure network access controls, including 802.1X port-based authentication, role-based access, and integration with enterprise identity services to support Zero Trust principles and least-privilege access models.
• Routing, Switching & Infrastructure Services: Manage and support routing, switching, and network services (e.g., VLANs, DNS, DHCP, VPNs), ensuring secure configuration, optimal performance, and alignment with organizational standards and policies.
• Perimeter & Public-Facing Security: Secure and managing public-facing network infrastructure, including firewalls, remote access solutions, and edge devices, ensuring hardened configurations, restricted access, and continuous monitoring to prevent unauthorized access and external threats.
• Network Monitoring & Security Operations Enablement: Implement and manage network monitoring, logging, and alerting capabilities, integrating with enterprise SIEM and network detection and response (NDR) tools to enhance visibility, threat detection, and incident response readiness.
• Vulnerability Management & Device Lifecycle: Establish and maintain a structured program for network device patching, firmware updates, vulnerability remediation, and lifecycle management to ensure all infrastructure components remain secure, compliant, and supported.
• Change Management & Documentation: Support formal change management processes, maintain accurate network diagrams and configuration documentation, and contribute to standard operating procedures to ensure transparency, traceability, and operational continuity.
• Advisory & Technical Leadership: Serve as a senior technical advisor to CBO stakeholders, collaborating with cybersecurity, cloud, and operations teams to resolve complex network issues, improve architecture, and support audits, assessments, and compliance initiatives.
• Customer Service & Team Collaboration: Serve as the technical adviser for complicated service desk tickets and modifications to better support network operations, while collaborating with cloud, Microsoft engineering, and cybersecurity teams.

Responsibilities and Duties:

  • Implement and maintain network security controls aligned with NIST SP 800-53, including access control (AC), configuration management (CM), system and communications protection (SC), and audit and accountability (AU) control families.
  • Engineer and enforce Zero Trust network architecture principles in accordance with NIST SP 800-207, including network segmentation, micro-segmentation, and continuous verification of users and devices.
  • Design and implement least-privilege network access controls, ensuring role-based and identity-aware access across all network layers.
  • Deploy and manage 802.1X port-based network access control to prevent unauthorized device connectivity and enforce authentication at the network edge.
  • Configure and maintain centralized logging and audit capabilities for all network devices, ensuring logs are forwarded to enterprise SIEM platforms and retained in accordance with compliance requirements.
  • Conduct continuous monitoring and vulnerability assessments of network infrastructure, identifying risks and coordinating remediation in alignment with NIST Risk Management Framework (RMF) practices.
  • Harden all network devices using secure configuration baselines (e.g., Cisco Secure Configuration Guides), including disabling unnecessary services, enforcing strong encryption protocols, and securing management interfaces.
  • Secure public-facing and perimeter network assets by implementing strict ingress/egress filtering, firewall rule optimization, and multi-factor authentication for administrative access.
  • Support incident response activities by providing network-level analysis, containment actions (e.g., segmentation, blocking malicious traffic), and forensic data collection.
  • Establish and maintain secure network segmentation strategies to limit lateral movement and protect high-value assets and sensitive environments.
  • Ensure all network changes follow formal change control processes with security impact analysis, supporting compliance with NIST configuration management requirements.
  • Lead or participate in security assessments, audits, and compliance reviews, providing evidence, documentation, and remediation support as required.
  • Continuously evaluate and enhance network security posture through adoption of emerging best practices, threat intelligence, and Cisco security innovations.
  • Develop, implement, and maintain Network Standard Operating Procedures (SOPs); review and update all SOPs on at least an annual basis or as required to reflect changes in technology, policy, or security requirements.
  • Document and maintain detailed hardware and configuration baselines for all network devices, including Cisco switches, routers, firewalls, and related infrastructure; conduct annual reviews and updates.
  • Perform root cause analysis (RCA) for network incidents, including performance degradation, outages, and security events; document findings and implement corrective and preventive actions.
  • Establish, implement, and maintain automated network patch management and firmware update procedures in accordance with Cisco best practices and organizational security policies.
  • Develop, maintain, and update comprehensive network diagrams that accurately reflect the CBO enterprise network architecture, including cloud, production, and secure environments; review and update diagrams annually or as changes occur.
  • Administer and troubleshoot enterprise DNS services, including configuration changes, issue resolution, and performance optimization.
  • Support continuous, real-time monitoring of network infrastructure (24/7 operations), including integration with network management and security monitoring tools.
  • Maintain accurate and up-to-date documentation of network configurations, assets, and operational procedures to support audit readiness and operational continuity.

Requirements:

  • Bachelor's degree in Information Technology, Computer Science, Network Engineering, Cybersecurity, or a related field (or equivalent combination of education and experience).
  • Minimum of 8 years of experience designing, implementing, and supporting enterprise network infrastructures.
  • Minimum of 5 years of experience in a senior-level network engineering role supporting complex Cisco environments.
  • Extensive experience with Cisco networking technologies, including routers, switches, wireless infrastructure, and network management platforms.
  • Demonstrated experience implementing and maintaining Zero Trust Architecture principles, including network segmentation, micro-segmentation, and least-privilege access controls.
  • Strong knowledge of federal cybersecurity frameworks and standards, including NIST SP 800-53, NIST SP 800-207, and Risk Management Framework (RMF).
  • Experience implementing and supporting 802.1X network access control solutions and identity-aware networking technologies.
  • Advanced knowledge of routing and switching protocols, including BGP, OSPF, VLANs, STP, and related enterprise networking technologies.
  • Experience managing enterprise DNS, DHCP, VPN, and network authentication services.
  • Proven experience securing perimeter and public-facing network infrastructure, including firewalls, remote access solutions, and edge security technologies.
  • Experience integrating network infrastructure with Security Information and Event Management (SIEM) platforms and Network Detection and Response (NDR) tools.
  • Strong background in vulnerability management, network device hardening, patch management, and lifecycle management.
  • Experience conducting network troubleshooting, root cause analysis (RCA), incident response, and performance optimization.
  • Ability to develop and maintain network documentation, configuration baselines, network diagrams, and standard operating procedures (SOPs).
  • Experience supporting audits, security assessments, compliance reviews, and remediation activities.

Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.


Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.

 

 

Create a Job Alert

Interested in building your career at Ardent? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...

Select...
Select...
Select...
Do you have an ACTIVE government clearance(s).? Check all that apply. *
Select...
Select...
Where did you hear about this job opening? (check all that apply) *
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Ardent’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.