Network & Cybersecurity Engineer
Job Description
Redwood Strong LLC is seeking a Network & Cybersecurity Engineer to support enterprise IT operations, classified network security, and RMF/DoD authorization readiness for defense programs.
Responsibilities
- Act as the technical owner for the enterprise network infrastructure, focusing on security, availability, and scalability.
- Design, maintain, and optimize multi-site enterprise networks including routing, switching, VLANs, and VPNs.
- Configure, harden, and monitor enterprise firewalls and perimeter defense capabilities.
- Implement cybersecurity protections aligned with best practices and CMMC/NIST control families.
- Lead incident response, troubleshooting, and root-cause analysis to minimize downtime.
- Own and secure the company’s Microsoft GCC High environment, including:
- Azure AD administration
- Intune device management
- Microsoft Defender suite (endpoint, identity, and cloud security)
- Security audits, logging, and compliance tooling
- Maintain enterprise configuration baselines and change-control documentation.
- Support organizational cybersecurity governance aligned with CMMC objectives, including policies, internal controls, incident response, vulnerability assessments, and internal audits.
- Maintain compliance for account and identity-management workflows using RMF, NIST 800-53, and DoD 8510.01.
- Oversee enterprise cybersecurity operations across:
- Network defense
- Endpoint protection
- Secure configuration
- Microsoft 365 security (MFA, conditional access, DLP)
- Role-based access management
- Maintain cybersecurity components of business continuity and disaster recovery plans; support secure collaboration across Teams, SharePoint, and OneDrive.
- Support USG cybersecurity approval efforts by directing RMF work, developing SSPs and POA&Ms, conducting threat modeling, and preparing authorization packages for government review.
- Coordinate with ISSOs, System Owners, engineering teams, government stakeholders, and accreditation authorities to support compliant, secure mission-system development.
- Embed security requirements early by participating in design reviews and technical interchange meetings.
- Oversee integration, validation, testing, and continuous monitoring of security controls across development, deployment, and sustainment.
- Exercise judgment to meet operational needs without disrupting critical activities, including avoiding patch deployment or forced reboots during sensitive events such as flight testing.
- Serve as the ISSM for small classified environments, ensuring compliance with DoD and intelligence community security requirements.
- Develop and maintain classified system cybersecurity documentation including SSPs, POA&Ms, and SOPs.
- Perform system audits, continuous monitoring, and vulnerability management.
- Lead security control implementation aligned with DoD RMF requirements.
- Coordinate with government security assessors and accreditors to maintain active system accreditation.
- Manage required updates, assessments, and reporting to maintain compliance and operational readiness.
- Develop System Security Plans and DoD RMF engineering artifacts.
- Conduct system architecture analysis, define security boundaries, and implement required controls.
- Prepare full accreditation packages, including eMASS entries, diagrams, and evidence documentation.
- Work directly with government Authorizing Officials / Security Customer Approval Authorities.
- Obtain and maintain ATO or IATT for flight tests, demonstrations, and other mission activities.
- Ensure secure integration of systems crossing classification or security boundaries.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Engineering, or a related field (Master’s preferred).
- 7+ years of experience in cybersecurity governance, RMF compliance, system authorization, or defense/aerospace security operations.
- Experience leading or supporting system accreditation efforts across USG or defense-related programs.
- Proficiency in RMF documentation, including SSPs, POA&Ms, and security evaluation processes.
- Hands-on experience configuring enterprise networks and firewalls.
- Experience designing multi-site network environments and establishing network architectures and operational/security drawings.
- Experience with enterprise cybersecurity operations including audits, incident response, vulnerability assessment, and security hardening.
- Proficiency with secure architecture, firewalls, VPNs, endpoint protection, and cloud security services.
- Experience securing and managing Microsoft 365 environments including MFA, DLP, conditional access, and compliance monitoring.
- Ability to serve in an ISSM-level role for classified systems.
- Proficiency with Azure AD, Intune, Defender, and Microsoft GCC High.
- Ability to obtain and maintain a TS/SCI clearance.
- Strong communication, leadership, and collaboration skills.
- Travel: up to 25%.
- CISSP (Required).
- Top Secret (Required).
- Work location: Hybrid (3-4 days in office), Roanoke, TX 76262.
- Network architecture: 5 years (Required).
Technologies
- Azure AD
- Intune
- Microsoft Defender suite (endpoint, identity, and cloud security)
- Microsoft Defender
- Microsoft GCC High
- Microsoft 365
- MFA
- Conditional access
- DLP
- Teams
- SharePoint
- OneDrive
- eMASS
- VPNs
- Firewalls
- VLANs
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Health savings account
- Paid time off
Pay
$140,000.00 - $190,000.00 per year
Preferred
- Security+, CISSP, and completion of the latest Cisco networking coursework (such as modern CCNA or successor).
- Experience with cross-domain solutions and flight-test accreditation.
- Experience in small-business or multi-role engineering environments.
Security Clearance
- Top Secret (Required)
License / Certification
- CISSP (Required)