The posting
Leidos is seeking an experienced Principal Network Security Engineer to design, engineer, and implement enterprise network security capabilities across a large, distributed network environment. The role is responsible for advancing network security architecture through the execution of strategic design and implementation efforts that improve the security posture, segmentation, access control, and resiliency of the enterprise network.
This position is responsible for overall network security engineering support across a broad range of efforts, including planning, designing, and evaluating the security components of the network. Duties include providing specifications for network security architecture, evaluating and recommending new technologies to enhance current capabilities, performing needs assessments, and directing the installation, configuration, testing, and tuning of network security infrastructure.
The successful candidate serves as a technical leader and subject matter expert — assessing the current security architecture, defining the controls and segmentation model the enterprise needs, building practical implementation plans with realistic risk and rollback provisions, and directing a team of engineers to deliver them under aggressive timelines.
Scope and Impact
Impact: Influences development of solutions that impact strategic project and program goals and business results. Recommends and develops new technical solutions, products, and security standards. Leads and manages the work of other technical staff that has significant impact on project results and outputs.
Complexity: Resolves highly complex problems through significant application of technical knowledge, conceptualization, reasoning, and interpretation. Develops solutions that are highly innovative and achieved through research and integration of best practices.
Communication: Communicates with government, program, cybersecurity, and technical leadership on matters of significant technical importance. Presents security architecture recommendations, implementation plans, risks, dependencies, and status to technical leadership, cybersecurity authorities, stakeholders, and approval boards, and works to build consensus around new concepts, practices, and approaches.
Knowledge: In-depth understanding of network security principles, theories, and concepts and their application across a range of programs. Serves as a subject matter expert within the network security domain.
Primary Responsibilities:
Network Security Engineering and Architecture
- Design, engineer, and implement enterprise network security architecture spanning next-generation firewalls, intrusion detection and prevention, web and TLS proxies, VPN and encryption services, network access control, DNS security, and east-west security controls.
- Evaluate the current network security architecture, identify gaps and improvement opportunities, estimate level of effort, assess implementation risk, and develop practical engineering plans to strengthen enterprise security capabilities.
- Lead network segmentation and secure connectivity efforts, including data-flow mapping, security-zone and enclave design, firewall rule set and ACL review and rationalization, routing and security policy coordination, cutover sequencing, validation, and stakeholder approval.
- Design and implement network access control and device-posture enforcement (Comply-to-Connect style), including identity and device authentication, posture assessment, policy enforcement points, remediation workflows, and phased enforcement rollout.
- Advance zero-trust-aligned networking, micro-segmentation, least-privilege access policy, and encrypted-transport strategies across the enterprise.
- Provide specifications for network security architecture, evaluate and recommend emerging security technologies, and perform needs assessments to inform design and investment decisions.
- Engineer secure connectivity between on-premises, cloud, and remote environments, including IPsec and TLS VPN, secure cloud interconnects, and perimeter and boundary protection designs.
- Tune and optimize security controls to reduce false positives, close coverage gaps, and improve detection and enforcement without degrading network performance or availability.
Project Execution
- Drive security engineering projects from concept through implementation, including architecture evaluation, requirements analysis, dependency identification, design coordination, planning, execution, validation, and transition to operations.
- Develop and manage implementation plans, schedules, cutover strategies, contingency plans, rollback procedures, validation steps, stakeholder communications, and change documentation for mission-critical security changes.
- Coordinate change windows, maintenance activities, test validation, and rollback procedures for high-impact security policy and infrastructure changes.
- Partner with network architecture, cybersecurity, operations, project management, and technical SME teams to resolve blockers, manage dependencies, and reduce delivery risk.
- Support accreditation and compliance activities, including security control implementation, STIG application, vulnerability remediation, POA&M support, and the technical artifacts required for authorization.
Technical Leadership
- Serve as the senior technical authority for network security design decisions, providing technical direction, mentoring, and day-to-day guidance to network and security engineers, administrators, and analysts.
- Organize technical priorities, track details across concurrent efforts, manage competing demands, and maintain accountability against aggressive schedules.
- Provide clear, well-reasoned technical information and recommendations to government stakeholders and approval authorities.
- Continuously improve engineering processes, documentation standards, implementation playbooks, migration runbooks, technical standards, and execution models to accelerate delivery, reduce rework, improve operational handoff, and lower sustainment burden.
Documentation
Develop and maintain engineering and operational documentation, including:
- Network security architecture and logical/physical design diagrams
- Data-flow diagrams, security-zone models, and segmentation designs
- Firewall policy standards, rule set baselines, and ACL documentation
- Port, protocol, and services (PPS) requirements
- Implementation and cutover plans with rollback and contingency procedures
- Test and validation plans
- Risk, dependency, and decision registers
- Security control implementation statements and accreditation artifacts
- Technical standards, playbooks, runbooks, and standard operating procedures
- As-built and operations transition documentation
Required Qualifications:
- Bachelor's degree or equivalent experience and 12+ years of prior relevant experience, or Master's degree with 10+ years of experience. Specific experience, education, and training may be considered in lieu of a degree.
- Significant experience designing and implementing network security architecture in complex, large-scale enterprise environments.
- Experience serving as a senior technical lead directing the work of network and security engineers, administrators, analysts, or implementation resources.
- Experience leading security engineering projects from planning through implementation, including requirements analysis, dependency management, risk reduction, contingency planning, execution oversight, validation, and operational transition.
- Hands-on engineering experience with next-generation firewalls, intrusion detection and prevention systems, proxies and TLS inspection, VPN and encryption services, and network access control platforms.
- Experience with network segmentation or similar secure connectivity efforts, including data-flow analysis, firewall and ACL policy review, routing changes, security-zone design, stakeholder coordination, and implementation planning.
- Strong working knowledge of core networking concepts, including TCP/IP, routing protocols, switching, VLANs, DNS/DHCP/IPAM, NAT, QoS, and software-defined and cloud-connected network environments.
- Hands-on experience with two or more of the following technologies: Palo Alto, Cisco, Aruba, Dell, Infoblox, and Brocade.
- Working knowledge of Federal Government application, server, and network security requirements such as NIST, FedRAMP, FISMA, RMF, DISA STIGs, and DoD cybersecurity requirements.
- Demonstrated ability to organize work, track details, manage competing priorities, meet aggressive schedules, and drive complex technical efforts to completion with a high degree of accountability.
- Experience documenting security and network designs, implementation plans, risks, dependencies, and technical recommendations using tools such as Visio, PowerPoint, Cameo, or similar.
- Excellent written and verbal communication skills, including experience briefing technical leadership, cybersecurity authorities, stakeholders, and approval boards.
- Current IAT Level II or higher certification, such as Security+ or CISSP.
- Active DoD Secret clearance.
Preferred Qualifications:
- CISSP, Palo Alto PCNSE, Cisco CCNP Security, or equivalent advanced security certification.
- Experience implementing Comply-to-Connect, 802.1X, or comparable network access control and device-posture enforcement at enterprise scale.
- Experience with zero-trust architecture, micro-segmentation, SASE, or secure cloud connectivity designs.
- Experience integrating network security platforms with SIEM, SOAR, ITSM, and analytics tooling.
- Experience with security automation and infrastructure-as-code using Python, Ansible, REST APIs, or similar, including automated firewall policy management.
- Experience with certificate and PKI management, encrypted-traffic inspection, and key management in enterprise environments.
- Experience supporting RMF, eMASS, continuous monitoring, and audit or inspection activities.
- Experience with Jira, Confluence, or other project and knowledge-management tools used to coordinate technical work across distributed engineering teams.
- Experience developing repeatable engineering execution frameworks, implementation playbooks, migration runbooks, technical standards, and risk-reduction processes.
Key Success Factors
This position requires more than a firewall administrator working a change queue. It requires a security engineer who can look at an enterprise network, determine where the real exposure is, design the segmentation and control model that closes it, and sequence the implementation so the enterprise stays up while it happens.
The successful engineer is equally comfortable in the technical detail — policy, routing, identity, certificates, inspection, and automation — and in front of cybersecurity authorities and approval boards defending a design, its residual risk, and its dependencies.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
October 8, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $116,350.00 - $210,325.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.



