hirly

Amentum

Network Security Architect - Principal

US-MD-Fort Meade

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Amentum first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included
Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
US
Work mode
On-site / unstated
First seen by hirly
9 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Purpose and Impact:

Are you ready to apply your leadership to shape the Cyber, Security, & Intel landscape? Amentum is seeking a Network Security Architect Lead, Principal to join our team of mission-driven professionals at Fort Meade, MD. In this role, you will lead challenging, high-visibility projects that directly impact the Nation’s defense and intelligence missions.

Supporting DISA, Amentum’s Intel and Cyber Division is expanding a proven team of highly skilled engineers and architects to design, deploy, and sustain an innovative IT enterprise solution. As the Principal Network Security Architect, you will serve as the technical visionary and authority for this team, defining secure network boundaries, driving the implementation of zero-trust architectures, and ensuring seamless security integration across complex enterprise environments.

Our team delivers secure, mission-critical capabilities where system integrity and rapid deployment are paramount. We are seeking a Network Security Architect Lead, Principal who combines meticulous security engineering discipline with strategic technical foresight. In this role, you will lead efforts to establish and maintain highly secure, resilient network architectures in a rapidly evolving operational threat environment. Success requires the ability to navigate complex, cross-functional technical dependencies independently while fostering collaborative engineering solutions across integrated teams. To excel, you must possess a proactive leadership mindset and the agility to rapidly master and govern the secure integration of next-generation systems and services.

Work Schedule: 8 Hours per day, Monday thru Friday

Essential Responsibilities:

  • The duties and responsibilities of the Network Security Architect Lead, Principal include but are not limited to the following:
  • Serve as the principal technical authority and visionary for the secure design, engineering, and evolution of the enterprise IT network infrastructure.
  • Architect and engineer high-performance, resilient network transport solutions leveraging enterprise Cisco routing and switching platforms across multi-site environments.
  • Design, deploy, and govern robust perimeter and boundary defense systems utilizing Palo Alto Next-Generation Firewalls (NGFW), including advanced threat prevention, SSL decryption, and security policy management.
  • Lead the security engineering efforts necessary to navigate the Risk Management Framework (RMF) Assessment & Authorization (A&A) process, ensuring all designs comply with DISA Security Technical Implementation Guides (STIGs) and secure an active Authority to Operate (ATO).
  • Define the architectural standards, blueprints, and TTPs for secure network integration, data flow segregation, and cross-domain solutions.
  • Set the technical and daily priorities for the network security engineering team, providing advanced mentorship, design standards, and escalation support for complex network anomalies.
  • Translate complex, high-level operational requirements and DISA security mandates into detailed technical specifications, low-level network designs (LLD), and security architecture diagrams.
  • Organize and lead technical architecture reviews, change control assessments, and security posture briefings with senior program leadership and DISA technical authorities.
  • Collaborate with Systems Engineers, Cloud Architects, and Project Managers to design secure interfaces and schedule authorized service interruptions (ASIs) for critical network upgrades.
  • Conduct comprehensive vulnerability assessments and threat modeling on the network architecture, identifying potential exploit vectors and engineering robust mitigation solutions.
  • Establish baseline configurations and configuration control templates for all network and security hardware, ensuring strict alignment with configuration management policies.
  • Lead technical site surveys, evaluate infrastructure readiness, produce detailed Network Bills of Materials (BOMs), and assist in generating migration schedules for enterprise site deployments.

Work Environment, Physical Demands, and Mental Demands:

Employee will work in a SCIF on a daily basis.

Employee may also be required to work in a datacenter environment for specified periods of time.

Minimum Requirements (Knowledge, Skills, and Abilities):

Fifteen (15) years of experience in network engineering, security architecture, or systems integration, with a primary focus on designing large-scale enterprise secure networks.

Seven (7) years of dedicated experience as a senior network security engineer, with at least three (3) years serving as a principal architect or technical lead overseeing security engineering teams.

Bachelor’s degree in Network Engineering, Computer Science, Information Technology (IT), Cybersecurity, or a related technical field (equivalent experience may be considered in lieu of a degree).

Extensive background designing and maintaining high-performance networks using Cisco routing and switching platforms (e.g., Nexus, Catalyst, ISR/ASR series) across enterprise and data center enclaves.

Hands-on technical depth engineering, configuring, and managing Palo Alto Next-Generation Firewalls (NGFWs), including Panorama, App-ID, User-ID, and advanced threat prevention profiles.

Proven experience navigating the Risk Management Framework (RMF) and designing network architectures that meet NIST SP 800-53 controls and DISA STIGs to secure and maintain a government Authority to Operate (ATO).

Active DoD 8140/8570.01-M Information Assurance Management (IAM) Level III or Information Assurance Technical (IAT) Level III certification (such as CISSP, CISM, or CompTIA CASP+) to meet secure environment compliance requirements.

Strong technical depth to produce complex architectural artifacts, including High-Level Designs (HLD), Low-Level Designs (LLD), Network Diagrams (Visio), and detailed Network Bills of Materials (BOMs).

Excellent communication, leadership, and technical presentation skills, with a track record of defending complex network security designs before DISA Technical Control Boards and senior leadership.

Ability to support non-standard hours, including scheduled maintenance windows, deployment surges, and emergency incident response architectures.

Ability to travel up to 10%.

Security Clearance Required:

Must have active Top Secret clearance with SCI eligibility

Minimum Education:

Bachelor’s degree in Computer Science, Information Technology (IT), Systems Engineering, or related technical field. Additional years of experience can substitute for degree.

Required Certifications and Qualifications:

(Minimum of 2 required, other within 180 days of hire):

Cisco Certified Internetwork Expert (CCIE) – Security

Palo Alto Networks Certified Network Security Engineer (PCNSE) or Palo Alto Networks Certified Network Security Consultant (PCNSC).

F5 Certified Administrator BIG-IP

HAIPE Configuration/Management Experience

CISSP-ISSAP (Information Systems Security Architecture Professional) or CISSP-ISSEP (Information Systems Security Engineering Professional) concentration.

Prior experience acting as a Lead Architect or Principal Engineer on high-consequence DISA or DoD programs at Fort Meade.

Familiarity with Software-Defined Networking (SDN) technologies such as Cisco SD-Access or Cisco SD-WAN.

#javelin

As part of our commitment to maintaining a safe and compliant work environment, Amentum is a drug-free workplace and requires all personnel to comply with company drug and alcohol policies as a condition of employment. Employment is contingent upon successful completion of the drug screening process. Please note that this may include pre-hire screening for marijuana, as well as other federally controlled substances due to Amentum’s role as a federal contractor and trusted partner to the US Government.

Other Responsibilities:

Safety

Original posting on Amentum's site ↗

Listed on hirly, a job board. hirly is not the employer: Amentum is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job