Skip to content

Open nowPosted today

Network Security Architect - Principal

PAE1,685 open roles

Where
US-MD-Fort Meade
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowNetwork Security Architect - PrincipalPAE · US-MD-Fort Meade
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on PAE's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. PAE postings stay open a median of 5 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted today

PAE median: 5 days open

The posting

Purpose and Impact:

Are you ready to apply your leadership to shape the Cyber, Security, & Intel landscape? Amentum is seeking a Network Security Architect Lead, Principal to join our team of mission-driven professionals at Fort Meade, MD. In this role, you will lead challenging, high-visibility projects that directly impact the Nation’s defense and intelligence missions.

Supporting DISA, Amentum’s Intel and Cyber Division is expanding a proven team of highly skilled engineers and architects to design, deploy, and sustain an innovative IT enterprise solution. As the Principal Network Security Architect, you will serve as the technical visionary and authority for this team, defining secure network boundaries, driving the implementation of zero-trust architectures, and ensuring seamless security integration across complex enterprise environments.

Our team delivers secure, mission-critical capabilities where system integrity and rapid deployment are paramount. We are seeking a Network Security Architect Lead, Principal who combines meticulous security engineering discipline with strategic technical foresight. In this role, you will lead efforts to establish and maintain highly secure, resilient network architectures in a rapidly evolving operational threat environment. Success requires the ability to navigate complex, cross-functional technical dependencies independently while fostering collaborative engineering solutions across integrated teams. To excel, you must possess a proactive leadership mindset and the agility to rapidly master and govern the secure integration of next-generation systems and services.

Work Schedule: 8 Hours per day, Monday thru Friday

Essential Responsibilities:

  • The duties and responsibilities of the Network Security Architect Lead, Principal include but are not limited to the following:
  • Serve as the principal technical authority and visionary for the secure design, engineering, and evolution of the enterprise IT network infrastructure.
  • Architect and engineer high-performance, resilient network transport solutions leveraging enterprise Cisco routing and switching platforms across multi-site environments.
  • Design, deploy, and govern robust perimeter and boundary defense systems utilizing Palo Alto Next-Generation Firewalls (NGFW), including advanced threat prevention, SSL decryption, and security policy management.
  • Lead the security engineering efforts necessary to navigate the Risk Management Framework (RMF) Assessment & Authorization (A&A) process, ensuring all designs comply with DISA Security Technical Implementation Guides (STIGs) and secure an active Authority to Operate (ATO).
  • Define the architectural standards, blueprints, and TTPs for secure network integration, data flow segregation, and cross-domain solutions.
  • Set the technical and daily priorities for the network security engineering team, providing advanced mentorship, design standards, and escalation support for complex network anomalies.
  • Translate complex, high-level operational requirements and DISA security mandates into detailed technical specifications, low-level network designs (LLD), and security architecture diagrams.
  • Organize and lead technical architecture reviews, change control assessments, and security posture briefings with senior program leadership and DISA technical authorities.
  • Collaborate with Systems Engineers, Cloud Architects, and Project Managers to design secure interfaces and schedule authorized service interruptions (ASIs) for critical network upgrades.
  • Conduct comprehensive vulnerability assessments and threat modeling on the network architecture, identifying potential exploit vectors and engineering robust mitigation solutions.
  • Establish baseline configurations and configuration control templates for all network and security hardware, ensuring strict alignment with configuration management policies.
  • Lead technical site surveys, evaluate infrastructure readiness, produce detailed Network Bills of Materials (BOMs), and assist in generating migration schedules for enterprise site deployments.

Work Environment, Physical Demands, and Mental Demands:

  • Employee will work in a SCIF on a daily basis.
  • Employee may also be required to work in a datacenter environment for specified periods of time.

Minimum Requirements (Knowledge, Skills, and Abilities):

  • Fifteen (15) years of experience in network engineering, security architecture, or systems integration, with a primary focus on designing large-scale enterprise secure networks.
  • Seven (7) years of dedicated experience as a senior network security engineer, with at least three (3) years serving as a principal architect or technical lead overseeing security engineering teams.
  • Bachelor’s degree in Network Engineering, Computer Science, Information Technology (IT), Cybersecurity, or a related technical field (equivalent experience may be considered in lieu of a degree).
  • Extensive background designing and maintaining high-performance networks using Cisco routing and switching platforms (e.g., Nexus, Catalyst, ISR/ASR series) across enterprise and data center enclaves.
  • Hands-on technical depth engineering, configuring, and managing Palo Alto Next-Generation Firewalls (NGFWs), including Panorama, App-ID, User-ID, and advanced threat prevention profiles.
  • Proven experience navigating the Risk Management Framework (RMF) and designing network architectures that meet NIST SP 800-53 controls and DISA STIGs to secure and maintain a government Authority to Operate (ATO).
  • Active DoD 8140/8570.01-M Information Assurance Management (IAM) Level III or Information Assurance Technical (IAT) Level III certification (such as CISSP, CISM, or CompTIA CASP+) to meet secure environment compliance requirements.
  • Strong technical depth to produce complex architectural artifacts, including High-Level Designs (HLD), Low-Level Designs (LLD), Network Diagrams (Visio), and detailed Network Bills of Materials (BOMs).
  • Excellent communication, leadership, and technical presentation skills, with a track record of defending complex network security designs before DISA Technical Control Boards and senior leadership.
  • Ability to support non-standard hours, including scheduled maintenance windows, deployment surges, and emergency incident response architectures.
  • Ability to travel up to 10%.

Security Clearance Required:

  • Must have active Top Secret clearance with SCI eligibility

Minimum Education:

  • Bachelor’s degree in Computer Science, Information Technology (IT), Systems Engineering, or related technical field. Additional years of experience can substitute for degree.

Required Certifications and Qualifications:

(Minimum of 2 required, other within 180 days of hire):

  • Cisco Certified Internetwork Expert (CCIE) – Security
  • Palo Alto Networks Certified Network Security Engineer (PCNSE) or Palo Alto Networks Certified Network Security Consultant (PCNSC).
  • F5 Certified Administrator BIG-IP
  • HAIPE Configuration/Management Experience
  • CISSP-ISSAP (Information Systems Security Architecture Professional) or CISSP-ISSEP (Information Systems Security Engineering Professional) concentration.
  • Prior experience acting as a Lead Architect or Principal Engineer on high-consequence DISA or DoD programs at Fort Meade.
  • Familiarity with Software-Defined Networking (SDN) technologies such as Cisco SD-Access or Cisco SD-WAN.

#javelin

As part of our commitment to maintaining a safe and compliant work environment, Amentum is a drug-free workplace and requires all personnel to comply with company drug and alcohol policies as a condition of employment. Employment is contingent upon successful completion of the drug screening process. Please note that this may include pre-hire screening for marijuana, as well as other federally controlled substances due to Amentum’s role as a federal contractor and trusted partner to the US Government.

Other Responsibilities:

Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.

Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.

Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.

Compensation Details:

$240,000 - $310,000

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.

Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Original Posting:

10/09/2026 - Until Filled

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against PAE's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on PAE's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    PAE's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.