Sr Principal Network Engineer-18754

Northrop Grumman Northrop Grumman · Aerospace · Roy, UT +1 · Networks

Senior Principal Network Engineer responsible for designing, implementing, securing, and optimizing complex network architectures for mission-critical operations within the defense sector. Requires expertise in routing, switching, network security, and automation, with a strong emphasis on cybersecurity compliance and supporting classified programs.

What you'd actually do

  1. Lead the design, architecture, deployment, and sustainment of large-scale enterprise, tactical, and datacenter networks (LAN/WAN/WLAN).
  2. Develop high-level and detailed network design documents, topology diagrams, and engineering implementation plans.
  3. Configure, manage, and optimize technologies including BGP, OSPF, EIGRP, MPLS, VXLAN, EVPN, SD-WAN, and QoS mechanisms.
  4. Oversee Layer 2/Layer 3 switching and routing infrastructure from vendors such as Cisco, Juniper, Palo Alto, Arista, etc.
  5. Implement and validate network security mechanisms including firewalls, IPS/IDS, segmentation, VPN technologies, and compliance with NIST/DoD cybersecurity controls.

Skills

Required

  • Network engineering experience
  • Enterprise networking technologies
  • Routing & switching (Cisco/Juniper/Arista)
  • BGP, OSPF, MPLS, VPN, STP, VLANs, trunking
  • Layer 2–3 troubleshooting and packet analysis
  • Firewalls and network security technologies (Palo Alto, Cisco ASA/FTD, Juniper SRX, etc.)
  • High-availability environments, redundant architectures, and failover systems
  • DoD/IC networking requirements, DISA STIGs, encryption devices, and secure transport protocols
  • Technical documentation and architectural artifacts
  • US Citizen with active U.S. security clearance
  • Ability to obtain Special Program Access (SAP)
  • Communication skills

Nice to have

  • Cisco CCNP, CCIE, Juniper JNCIP/JNCIE, or similar expert-level certifications
  • SD-WAN solutions
  • Network automation (Python, Ansible, Terraform, Postman, REST APIs)
  • Zero Trust, microsegmentation, or identity-driven access architectures
  • Classified networks, cross-domain solutions, and NIST 800-171/53 compliance
  • Virtualization platforms (VMware, KVM), hyperconverged systems, and cloud networking (AWS, Azure GovCloud)
  • Monitoring tools (SolarWinds, Splunk, Elastic, Cisco DNA Center, or equivalent)
  • Project management, engineering oversight, or technical authority roles
  • Architect scalable solutions for multi-site, distributed enterprise environments

What the JD emphasized

  • CLEARANCE REQUIRED FOR START: Yes
  • CLEARANCE TYPE: Secret
  • Must be a US Citizen and have an active U.S. security clearance (minimum of [Secret / TS / TS/SCI]), must also have the ability to obtain Special Program Access (SAP) within a reasonable time period.