Network Architect - Routing ADNS
Hybrid Remote • Delivery
Job Type
Full-time, Contract
Description

CyKor is a fast-growing Technology Solutions Provider to both federal and commercial clients. We attribute our continued growth to our core values, our professional team, and the valuable relationships with our clients. Our small and growing team fosters an environment in which each team member is respected, valued, and appreciated for their contributions.


Role & Responsibilities

The Routing Network Architect plays a key leadership role in designing, modernizing, automating, and implementing secure, scalable, resilient, and high-performance enterprise network solutions. This position requires a blend of deep technical expertise, solution design acumen, and hands-on experience in enterprise routing, WAN architecture, Enterprise SD-WAN, Cisco SD-WAN, network automation, security, and orchestration. 


The Architect will support the modernization and transformation of large-scale enterprise WAN environments, including the transition from traditional and legacy WAN architectures toward policy-driven SD-WAN solutions. 

You’ll work closely with government and technical stakeholders to understand mission requirements, assess existing infrastructure, develop current-state and target-state architectures, and design solutions that integrate traditional networking, SD-WAN, secure transport, automation, and hybrid cloud architectures. 


Enterprise Architecture & Design 

  • Engage with clients and government stakeholders to understand mission requirements, challenges, and objectives, translating them into tailored network architecture solutions. 
  • Assess existing infrastructure to identify optimization and modernization opportunities, focusing on scalability, resiliency, security, performance, and operational supportability. 
  • Lead the architecture and design of large-scale enterprise WAN modernization initiatives, including migration from legacy routed WAN environments to SD-WAN. 
  • Develop current-state, transitional, and target-state WAN architectures encompassing routing, SD-WAN, transport, segmentation, encryption, QoS, resiliency, and cloud connectivity. 
  • Design, document, and present end-to-end enterprise network architectures and provide technical leadership through implementation. 
  • Drive the adoption of network automation, infrastructure-as-code (IaC), and orchestration frameworks such as Ansible, Terraform, Python, and REST APIs. 
  • Standardize network architectures and create reusable templates and design patterns to streamline deployments and improve consistency across environments. 
  • Collaborate with engineering teams, vendors, technology partners, NOCs/SOCs, and government stakeholders to deliver integrated solutions aligned with mission and enterprise requirements. 
  • Serve as a trusted technical advisor during architecture reviews and technical discussions, ensuring solutions meet security, scalability, performance, and resiliency requirements. 

SD-WAN Architecture & Engineering 

  • Serve as a senior technical architect for enterprise-scale latest SD-WAN and Cisco SD-WAN design, implementation, and modernization. 
  • Design SD-WAN architectures across management, control, and data planes, including policy-based routing, application-aware routing, traffic steering, segmentation, QoS, and SLA-based path selection. 
  • Design multi-transport WAN architectures incorporating MPLS, dedicated circuits, Internet, broadband, LTE/5G, SATCOM, and other approved transport technologies. 
  • Establish scalable SD-WAN standards for site onboarding, configuration, policy management, resiliency, lifecycle management, and operational support. 

Routing & WAN Engineering 

  • Provide expert-level architecture and engineering leadership across BGP, OSPF, MPLS, VRF, IPv4/IPv6, multicast, QoS, BFD, route redistribution, and route filtering. 
  • Design resilient routing and WAN architectures supporting predictable convergence, failover, segmentation, and controlled integration between existing enterprise networks and the SD-WAN environment. 

Cybersecurity & Compliance 

  • Ensure designs align with: 
  • Risk Management Framework (RMF) 
  • Defense Information Systems Agency (DISA) STIGs 
  • Zero Trust Architecture (ZTA) principles 
  • Applicable DoD/DoW cybersecurity requirements 
  • Lead ATO package development and system accreditation support. 
  • Integrate security controls into network architecture, including encryption/IPsec, segmentation, identity enforcement, PKI, firewalls, and security policy controls. 
  • Ensure security architecture is consistently applied across the WAN underlay, SD-WAN overlay, cloud connectivity, and enterprise security boundaries. 

DoDIN Integration & Stakeholder Engagement 

  • Interface with: 
  • DoDIN operations, NOCs, and SOCs 
  • Network engineering teams 
  • Cybersecurity organizations 
  • Government technical authorities 
  • PMO and IPT organizations 
  • Technology vendors and service providers 
  • Translate mission needs into technical solutions aligned with DoD enterprise direction and DoW operational requirements. 
  • Provide technical leadership during architecture reviews, PMO syncs, IPT engagements, technical interchange meetings, and engineering reviews. 

WAN Modernization & Migration 

  • Develop and support brownfield migration strategies for transitioning existing DoD/DoW WAN environments to Cisco SD-WAN while maintaining mission continuity. 
  • Define migration sequencing, site onboarding, routing and security migration, application validation, cutover, rollback, and operational acceptance requirements. 
  • Provide technical leadership during major network cutovers, integration testing, production migration, and transition to operations. 

Technical Leadership & Delivery Excellence 

  • Mentor engineers and provide technical oversight for implementation teams. 
  • Lead architecture through the full lifecycle from requirements and design through laboratory validation, deployment, migration, and operational acceptance. 
  • Validate solutions in lab environments such as integration labs, staging environments, and C5I environments. 
  • Drive delivery discipline ensuring designs are executable, supportable, secure, resilient, and scalable. 

Documentation & Governance 

  • Produce and maintain: 
  • Current-state and target-state architecture 
  • Architecture diagrams 
  • Design packages (HLD/LLD) 
  • Migration and implementation plans 
  • Test and validation plans 
  • Operational documentation 
  • Support configuration control boards (CCB), engineering review boards, architecture reviews, and technical governance activities. 
  • Provide inputs to executive briefings, technical whitepapers, and senior stakeholder presentations. 
Requirements
  • Bachelor's degree in Computer Science, Information Technology, Engineering, or related field preferred. 
  • Active Secret clearance (or higher). 
  • Minimum 7 years of experience in network architecture, network engineering, or related disciplines. 
  • Proven experience designing and implementing enterprise-grade network infrastructures and large-scale WAN environments. 
  • Experience designing or implementing Enterprise SD-WAN or Cisco SD-WAN in enterprise or multi-site environments. 
  • Deep and thorough knowledge of network protocols and technologies including TCP/IP, OSPF, BGP, MPLS, IPv4/IPv6, Multicast, QoS, VRF, VPN/IPsec, and SD-WAN. 
  • Strong documentation, presentation, and communication skills, with the ability to convey complex technical concepts to both technical and non-technical audiences. 

Technical Requirements 

Deep Expertise In Enterprise Routing & Switching — BGP, OSPF, MPLS, VRF, IPv4/IPv6, Multicast, QoS; Enterprise WAN and SD-WAN architecture; network segmentation, resiliency, and security architecture 

Hands-On Experience With Enterprise SD-WAN and Cisco SD-WAN / SDA, Cisco ISE and identity-based networking, Firewalls including Cisco FTD and Palo Alto, IPsec, VPN, PKI, and secure network communications 

Experience With network automation — Ansible, Python, REST APIs, Terraform; virtualization and cloud networking — VMware, AWS GovCloud, Azure Government; multi-transport WAN architectures including MPLS, Internet, dedicated circuits, and wireless/LTE/5G 


Desired Qualifications 

  • Experience supporting SD-WAN at scale, including multi-site and geographically distributed enterprise deployments. 
  • Experience leading or supporting WAN modernization and migration from legacy MPLS/routed environments to Cisco SD-WAN. 
  • Familiarity with Zero Trust Architecture (ZTA); Identity services such as Cisco ISE; RMF, DISA STIGs, PKI, and DoD cybersecurity requirements 
  • Experience in lab-based validation environments such as integration labs, staging environments, C5I environments, or operational test environments. 
  • Prior experience supporting DoW/DoD enterprise networks. 
  • Cisco CCNP Enterprise, CCNP Security, or CCIE certification is highly desirable. 

Key Competencies 

  • Strategic thinker with strong systems-level perspective and the ability to architect complex enterprise WAN environments. 
  • Ability to translate mission requirements into executable network architecture and modernization roadmaps. 
  • Strong understanding of the relationship between WAN underlay, SD-WAN overlay, routing, security, application performance, and operations. 
  • Strong leadership and mentorship capability. 
  • Excellent communication with executive, government, engineering, cybersecurity, and operational stakeholders. 
  • Proven ability to deliver in high-tempo, mission-critical environments. 


Work Environment 

  • Mission-driven DoD/DoW environment supporting operational and enterprise networks. 
  • May require travel to customer, operational, or laboratory environments 
  • Participation in network cutovers and implementation activities 
  • Participation in after-hours maintenance, design cutovers, or incident response