Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
EF
ECS Federal, LLC
Cloud/Network Infrastructure Engineer, Senior
Career Insights for Network Engineer / Architect
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Network Engineer or Architect designs and builds computer network systems, including software and hardware. Runs program and system tests, solves technical problems and maintains the network system. Designs and analyzes computer network models.
$132,604 / year median in Virginia
-14% projected decline
Job Description
Everforth ECS is seeking a Senior Infrastructure Engineer (AWS / Terraform / EKS) to join the Infrastructure & Cloud Team supporting the CDM Data Servicefederal programs under
The engineer will work inanenvironmentwhere all deployments are infrastructure-as-code, peer-reviewed, and fully auditable. The successful candidate will combine hands-on AWS engineering depth witha strong senseof operational discipline, automation, and compliance awareness.
This is not just EKS/Terraform buildwork;it is operational ownership across commercial and GovCloud AWSaccounts forconnectivity,routing, DNS, F5/load balancing, EKS, Terraform, security remediation, migrations, and stakeholder coordination.
We areseekingdynamic, energetic, and engagingteam memberswho lovechallenges!
The ideal candidate will be able to align to the following duties:
Troubleshoot and support enterprise load-balancingand ingress patterns, includingF5 or equivalent technologies, DNS, TLS/certificate paths, routing, and endpoint reachability.
Coordinate directly with application teams, Security, stakeholders, network owners, and program leadership to resolve connectivity, access,migraiton, and production readiness issues.
Design, build, andmaintainInfrastructure-as-Code using Terraform (modules, S3/DynamoDB remote state, OPA/tfsecpolicy integration).Provision, upgrade, and manage EKS clusters, including namespaces, Helm-based add-ons (cert-manager, ESO, Confluent Operator), and IAM roles for service accounts.
Design, configure, and troubleshoot AWS VPC networking, including routing, TGWs, DNS, DHCP, endpoints, NACLs, and security groups.
Implement and secure microservices on EKS with proper connectivity to AWS services (S3, ECR, Secrets Manager, IAM).Automate infrastructure deployments using GitHub Actions (or self-hosted runners), cross-account IAM role assumptions, and CI/CD policy gates.
Collaborate with security andapplicationsteams to enforce least-privilege IAM, automate compliance evidence collection, and support RMF/ATO documentation.
Diagnose and resolve complex issues spanning containers, Kubernetes networking, and AWS layers (VPC-Zscaler-C-TIPS-SaaS endpoints).Support observability, logging, and monitoring through integration with Elastic, ScienceLogic, or AppDynamics to meet SLA and audit requirements.
Mentor and guide junior engineers through knowledge sharing, paired engineering, and process standardization.
Evaluate and improve infrastructure design for policy compliance, resiliency, and performance tuning.
Develop andmaintainSOPs and playbooks that align with program governance.
Support legacy-to-CAWS migration activities, including RabbitMQ/app-server connectivity, environment cutover support, dependency discovery, and validation of network paths across lower and productionenvironments.
Quickly build working knowledge of inheritedenvironments, document tribal knowledge, creatediagrams/runbooks, and transfer operational context to primary and backup owners.
Operate within a formal change-control, evidence, and audit expectations, including CR support,implementationevidence, rollback planning, and post-change validation.
Bachelor's degree or 8 years of relevant experience.6+ years designing, implementing, securing, andmaintainingAWS Cloud infrastructure (CAWS, GovCloud, or equivalent).5 + years troubleshooting hybrid/cloud network connectivity, including VPC routing, TGW, DNS, DHCP, TLS/certificates, security groups, NACLs, endpoints, and load balancers.5+ years of experience with Terraform (advanced modules, state management, policy enforcement).5+years' Experiencewith Kubernetes networking, ingress,CoreDNS, service exposure, node/security groupbehavior, and connectivity between EKS workloads and AWS/external services.5+ years of infrastructure experience related to network securityStrong networking foundation: TCP/IP, DNS, DHCP, TLS, routing, subnetting, NACLs, and endpoint connectivity.
Proficient scripting/automation using Python or Bash, YAML/JSON templating, and Git-based workflows.
Experience in security compliance environments (Fed
Demonstrated ability to collaborate cross-functionally with Security,DevSecOps, and CI/CD teams tomaintaincompliant, auditable infrastructure.
Strong communicationskills with the ability tointerface effectively withstakeholders from engineers to senior management.
DHS CISA.
This role focuses on designing, building, andoperatingsecure, repeatable AWS environments within a FedRAMP and ATO-governed context.The engineer will work inanenvironmentwhere all deployments are infrastructure-as-code, peer-reviewed, and fully auditable. The successful candidate will combine hands-on AWS engineering depth witha strong senseof operational discipline, automation, and compliance awareness.
This is not just EKS/Terraform buildwork;it is operational ownership across commercial and GovCloud AWSaccounts forconnectivity,routing, DNS, F5/load balancing, EKS, Terraform, security remediation, migrations, and stakeholder coordination.
We areseekingdynamic, energetic, and engagingteam memberswho lovechallenges!
The ideal candidate will be able to align to the following duties:
Troubleshoot and support enterprise load-balancingand ingress patterns, includingF5 or equivalent technologies, DNS, TLS/certificate paths, routing, and endpoint reachability.
Coordinate directly with application teams, Security, stakeholders, network owners, and program leadership to resolve connectivity, access,migraiton, and production readiness issues.
Design, build, andmaintainInfrastructure-as-Code using Terraform (modules, S3/DynamoDB remote state, OPA/tfsecpolicy integration).Provision, upgrade, and manage EKS clusters, including namespaces, Helm-based add-ons (cert-manager, ESO, Confluent Operator), and IAM roles for service accounts.
Design, configure, and troubleshoot AWS VPC networking, including routing, TGWs, DNS, DHCP, endpoints, NACLs, and security groups.
Implement and secure microservices on EKS with proper connectivity to AWS services (S3, ECR, Secrets Manager, IAM).Automate infrastructure deployments using GitHub Actions (or self-hosted runners), cross-account IAM role assumptions, and CI/CD policy gates.
Collaborate with security andapplicationsteams to enforce least-privilege IAM, automate compliance evidence collection, and support RMF/ATO documentation.
Diagnose and resolve complex issues spanning containers, Kubernetes networking, and AWS layers (VPC-Zscaler-C-TIPS-SaaS endpoints).Support observability, logging, and monitoring through integration with Elastic, ScienceLogic, or AppDynamics to meet SLA and audit requirements.
Mentor and guide junior engineers through knowledge sharing, paired engineering, and process standardization.
Evaluate and improve infrastructure design for policy compliance, resiliency, and performance tuning.
Develop andmaintainSOPs and playbooks that align with program governance.
Support legacy-to-CAWS migration activities, including RabbitMQ/app-server connectivity, environment cutover support, dependency discovery, and validation of network paths across lower and productionenvironments.
Quickly build working knowledge of inheritedenvironments, document tribal knowledge, creatediagrams/runbooks, and transfer operational context to primary and backup owners.
Operate within a formal change-control, evidence, and audit expectations, including CR support,implementationevidence, rollback planning, and post-change validation.
Salary:
$123,000 - $184,000General Description of BenefitsMust be a US citizen withthe abilityto obtain Public Trust Suitability.Bachelor's degree or 8 years of relevant experience.6+ years designing, implementing, securing, andmaintainingAWS Cloud infrastructure (CAWS, GovCloud, or equivalent).5 + years troubleshooting hybrid/cloud network connectivity, including VPC routing, TGW, DNS, DHCP, TLS/certificates, security groups, NACLs, endpoints, and load balancers.5+ years of experience with Terraform (advanced modules, state management, policy enforcement).5+years' Experiencewith Kubernetes networking, ingress,CoreDNS, service exposure, node/security groupbehavior, and connectivity between EKS workloads and AWS/external services.5+ years of infrastructure experience related to network securityStrong networking foundation: TCP/IP, DNS, DHCP, TLS, routing, subnetting, NACLs, and endpoint connectivity.
Proficient scripting/automation using Python or Bash, YAML/JSON templating, and Git-based workflows.
Experience in security compliance environments (Fed
RAMP, FISMA, NIST 800-53
) and supporting ATO documentation.Demonstrated ability to collaborate cross-functionally with Security,DevSecOps, and CI/CD teams tomaintaincompliant, auditable infrastructure.
Strong communicationskills with the ability tointerface effectively withstakeholders from engineers to senior management.