Senior Network Engineer / FISMA Compliance Support - PCLOB
Summary
Senior Network Engineer owning PCLOB's enterprise Cisco network (routing/switching, CUCM/VoIP, firewalls, VPNs, segmentation) while supporting FISMA/RMF compliance via Xacta 360 and NIST 800-53 documentation.
Nemean Solutions, headquartered in Sierra Vista, AZ, is a certified SBA 8(a) Native Hawaiian Organization (NHO) and veteran-operated company providing advanced Military Intelligence, Enterprise and Cloud IT services, Cybersecurity, Special Operations Forces (SOF) Exercise and Training, and niche Program Support and Professional Services to Federal and State Agencies supporting the US Government Defense, Intelligence and Aerospace sectors.
Job Overview:
Nemean Solutions is seeking a Senior Network Engineer / FISMA Compliance Support professional to support the Privacy and Civil Liberties Oversight Board (PCLOB). The primary focus of this position is hands-on ownership of PCLOB's enterprise network environment and the network/security engineering responsibilities. The engineer will independently operate, maintain, secure, troubleshoot, and improve Cisco network and unified communications services. As a secondary responsibility, the position will support the FISMA readiness and continuous compliance activities, including NIST SP 800-53 control documentation, POA&M management, technical evidence, remediation, and Xacta 360 administration. The ideal candidate is first and foremost a senior network engineer who also understands federal FISMA/RMF compliance and can translate network configurations and remediation actions into auditable security-control evidence.
Support Hours: Applicant shall be available during core work hours as established the Government customer.
Essential Duties & Responsibilities:
Enterprise Network Operations and Cisco Engineering - Primary Responsibility
- Serve as the primary technical owner for PCLOB enterprise network operations and maintenance, ensuring the continuous availability, performance, security, and reliability of production network services.
- Design, configure, administer, operate, maintain, and troubleshoot Cisco routing and switching infrastructure, including VLANs, subnetting, ACLs, TCP/IP, DNS, DHCP, routing protocols, IP addressing, and related network services.
- Independently resolve complex production incidents involving routing, switching, firewalls, VPNs, connectivity, name resolution, and IP services; perform root-cause analysis and implement sustainable corrective actions.
- Plan, implement, operate, and maintain network-security technologies and services, including firewalls, VPNs, IDS/IPS, network segmentation, secure remote access, vulnerability remediation, network monitoring, and security policy enforcement.
- Develop and execute network technology project plans, including Cisco Unified Communications Manager (CUCM)/Call Manager and enterprise VoIP capabilities, SIP, QoS, voice VLANs, voice gateways, and wireless/network modernization activities.
- Maintain highly available network services and support integrations with Windows Server, Hyper-V, Linux, server virtualization, Active Directory/identity and access services, Citrix, and related enterprise infrastructure. Maintain accurate physical/logical network diagrams, device inventories, configurations, change records, operating procedures, and troubleshooting documentation.
Security Architecture and Engineering - Primary/Shared Responsibility
- Assess network and security architecture, identify gaps in the security stack, and develop practical roadmaps and implementation plans that improve capability, tune existing tools, reduce unnecessary overlap, and maintain reliable operations.
- Review IT security policies with PCLOB OCIO and provide technical solutions for enforcement through network/security architecture, configuration, access controls, monitoring, and engineering changes.
- Collaborate with PCLOB OCIO, system, cloud, cybersecurity, and security-operations personnel on security-engineering deployments and integrated projects; define milestones, completion dates, resource needs, testing, dependencies, and coordination requirements.
- Provide weekly project updates when requested, identify concerns that could affect milestones or completion dates, and drive assigned network/security engineering actions to closure.
- Provide Security Engineering SME reviews, technical analyses, recommendations, and decision-ready write-ups on an ad hoc basis; support security administrator questions and technical remediation activities.
- FISMA, NIST, and Xacta 360 Compliance Support - Secondary Responsibility
- Support Task 3 FISMA readiness and continuous compliance activities by applying the NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5 requirements to network/security controls, technical configurations, evidence, findings, and remediation.
- Use and maintain Xacta 360 to support security-control tracking, control implementation documentation, assessments, evidence repositories, Plans of Action and Milestones (POA&Ms), remediation milestones, technical validation, and ongoing compliance status.
- Support recurring SSP updates, control inheritance, annual FISMA pre-assessment preparation, baseline compliance evidence, annual submission data/metrics, corrective-action planning, and audit/assessment readiness; ensure network-related artifacts accurately reflect the production environment.
- Review STIG, vulnerability, configuration, and compliance findings; validate technical impact, implement or coordinate corrective actions, document closure evidence, and support compliance briefings, assessor requests, ATO/accreditation activities, and leadership reporting.
Program Support and Customer Engagement
- Coordinate directly with PCLOB OCIO leadership, system administrators, cybersecurity personnel, and other stakeholders to clarify network and security requirements, communicate technical risk, and drive assigned actions to closure.
- Prepare concise network analyses, implementation plans, status updates, risk summaries, and decision-ready technical recommendations for Government and Nemean leadership.
- Participate in change-management reviews, technical exchanges, audit/assessment activities, incident-response exercises, and recurring status meetings as required.
- Maintain project milestones, risks, dependencies, action items, completion dates, and documentation for assigned network, security-engineering, and FISMA-support activities.
Competencies:
- Excellent verbal and written communication skills.
- Excellent interpersonal and customer service skills.
- Excellent organizational skills and attention to detail.
- Excellent time management skills with a proven ability to meet deadlines.
- Ability to prioritize tasks and to delegate them when appropriate.
- Ability to function well in a high-paced and at times stressful environment.