1

Contract Aws Network Engineer Jobs (NOW HIRING)

$130 - $190/hr

AWS Certified Advanced Networking - Specialty (strongly preferred). * Palo Alto Networks Certified Network Security Engineer (PCNSE) . * Demonstrated experience with AWS Transit Gateway Appliance ...

Champion the design, implementation, and maintenance of our multi-region, multi-cloud (AWS/GCP/OCI ... Experience Level Expert Level Job Type & Location This is a Contract to Hire position based out of ...

Network Engineer

Englewood, NJ · On-site

$50 - $55/hr

Network Engineer Location: Englewood, NJ Note: Need local candidates who can attend In person ... Design and support AWS networking including VPC, Route Tables, Security Groups, Transit Gateway ...

Network Engineer Location: Englewood, NJ Note: Need local candidates who can attend In person ... Design and support AWS networking including VPC, Route Tables, Security Groups, Transit Gateway ...

Preferred Certifications • Azure Network Engineer Associate • Azure Solutions Architect Expert • AWS Certified Advanced Networking Specialty • AWS Solutions Architect Professional

Network Architect

Englewood, CO · On-site

$64.25 - $86/hr

Network Engineer Architect Location: Colorado, USA (Hybrid) Job Overview We are seeking an experienced Network Engineer Architect with strong expertise in AWS Elastic VMware Service (EVS), VMware ...

Role: Network Engineer Cloud Location: Louisville, KY Remote Fulltime Position JD: Must Have ... Good understanding on Azure, GCP,AWS network architecture Manikanth Sarian Solutions, Inc. Ph: 732 ...

Support the monitoring and troubleshooting of AWS network connectivity issues using CloudWatch, VPC ... Collaborate with cloud engineers to support hybrid network architecture and ensure consistent ...

Champion the design, implementation, and maintenance of our multi-region, multi-cloud (AWS/GCP/OCI ... Experience Level Expert Level Job Type & Location This is a Contract to Hire position based out of ...

Support the monitoring and troubleshooting of AWS network connectivity issues using CloudWatch, VPC ... Collaborate with cloud engineers to support hybrid network architecture and ensure consistent ...

Strong communication skills * 7+ years of overall Network Engineering experience, with 1+ years of ... AWS networking background * Deep understanding of Data center networking * Experience designing a ...

Support the monitoring and troubleshooting of AWS network connectivity issues using CloudWatch, VPC ... Collaborate with cloud engineers to support hybrid network architecture and ensure consistent ...

Showing results 21-40

Contract Aws Network Engineer information

See salary details

$31K

$109K

$158K

How much do contract aws network engineer jobs pay per year?

As of Sep 5, 2026, the average yearly pay for contract aws network engineer in the United States is $109,040.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $133,500.00 per year, depending on experience, location, and employer.

What is the difference between Contract Aws Network Engineer vs Cloud Network Engineer?

AspectContract Aws Network EngineerCloud Network Engineer
CertificationsAWS Certified Advanced Networking, CCNA, CCNPAWS Certified Advanced Networking, CCNA, CCNP
Work EnvironmentContract roles, project-based, on-site or remoteFull-time or contract, cloud-focused, on-site or remote
Industry UsageIT, cloud service providers, consulting firmsIT, cloud service providers, enterprise IT departments

The Contract Aws Network Engineer and Cloud Network Engineer roles share similar certifications and work environments, often overlapping in industry usage. The main difference lies in the contract nature of the AWS-specific role versus the broader cloud networking focus of the Cloud Network Engineer. Both positions require strong networking skills and AWS knowledge, but contract roles tend to be project-based with temporary assignments.

What cities are hiring for Contract Aws Network Engineer jobs?

Cities with the most Contract Aws Network Engineer job openings:

What are the most commonly searched types of Aws Network Engineer jobs?

The most popular types of Aws Network Engineer jobs are:

What states have the most Contract Aws Network Engineer jobs?

States with the most job openings for Contract Aws Network Engineer jobs include:

$130 - $190/hr

Other

Posted 13 days ago


Key responsibilities

  • Design, coordinate, and execute BCAP cutovers in collaboration with DISA and mission partners.

  • Manage the submission processes for SNAP and CPTC workflows to secure an Authority to Connect (ATC).

  • Design, configure, and manage AWS Transit Gateway instances, route tables, and VPC topologies across multiple isolated enclaves.


Job description

Defense Engineering, Inc. (DEi) is seeking an expert GovCloud Network Engineer to architect, deploy, and manage highly secure cloud networking environments. This role is dedicated to establishing and maintaining critical connections between the Department of Defense Information Network (DoDIN), NIPRNet/SIPRNet and AWS GovCloud (US) regions.

The ideal candidate possesses deep, hands-on experience working alongside the Defense Information Systems Agency (DISA) to execute Boundary Cloud Access Point (BCAP) cutovers, navigate the SCCA Network Approval Process (SNAP), and implement the Cloud Permission to Connect (CPTC) workflow. You will serve as our primary network authority, designing complex route table topologies across Inspection, Egress, and Perimeter VPCs, leveraging AWS Transit Gateway, and integrating Next-Generation Firewalls (NGFW) to facilitate compliant, secure cloud routing.

Key Responsibilities1. DISA & BCAP Connectivity Engineering
  • BCAP Planning & Execution: Design, coordinate, and execute end-to-end Boundary Cloud Access Point (BCAP) cutovers in collaboration with DISA and mission partners.
  • Connection Process Management: Lead the technical submission processes for SCCA Network Approval Process (SNAP) and Cloud Permission to Connect (CPTC) workflows to secure an Authority to Connect (ATC).
  • IP & Subnet Allocation: Manage NIPRNet IP block assignments (e.g., issued /24 ranges) and integrate them within a compliant cloud network architecture.
  • Hybrid Cloud Transport: Establish resilient, private connectivity into AWS GovCloud using AWS Direct Connect (DX), Direct Connect Gateways (DXGW), and backup IPsec VPNs.
2. AWS Secure Cloud Routing & Topology
  • Transit Gateway Architecture: Design, configure, and manage AWS Transit Gateway (TGW) instances, including complex TGW Route Tables, Route Table Associations, Route Table Propagations, and TGW Peerings.
  • Multi-VPC Topology Design: Structure and automate route tables across highly isolated, functional enclaves including:
  • Perimeter VPCs: Hosting boundary ingress/egress points.
  • Inspection VPCs: Centralizing traffic interception, deep packet inspection, and security analysis.
  • Egress VPCs: Controlling out-of-band communication and secure software repository syncing.
  • Mission Owner VPCs: Containing isolated application tiers.
  • VPC Peering & Transit Gateways: Properly evaluate design trade-offs between VPC Peering, Transit Gateway, and Transit Gateway Connect attachments.
3. Network Security & SCCA Compliance (VDSS)
  • Virtual Data Center Security Stack (VDSS): Deploy and operate the VDSS layer to protect the network perimeter according to the DISA SCCA framework.
  • Firewall Integration: Deploy, configure, and cluster third-party Network Virtual Appliances (NVAs)-such as Palo Alto VM-Series or Fortinet FortiGate-using AWS Transit Gateway Appliance Mode for stateful inspection.
  • AWS Native Security Control: Manage AWS Network Firewall rulesets, authorizing custom Suricata stateful rules for both east-west (inter-VPC) and north-south (external/on-premises) traffic.
  • DNS Resolution & Security: Implement DNS control using Amazon Route 53 Resolver, private hosted zones, and Route 53 DNS Firewall rules.
  • Private Ingress & Egress: Facilitate secure, private API access utilizing AWS PrivateLink (VPC Endpoints) to restrict public-IP exposure.
  • Compliance Enforcement: Harden all networking infrastructure and virtual appliances in accordance with the latest DISA Security Technical Implementation Guides (STIGs).
AWS Networking & Security Components Utilized

As a Senior Networking Expert, you must have advanced, practical mastery of the following AWS networking components:

  • Core Transport & Transit: AWS Transit Gateway (TGW), TGW VPC Attachments, TGW Route Tables, AWS Direct Connect (DX), Direct Connect Gateway (DXGW), Virtual Private Gateway (VGW), Transit Gateway Connect.
  • VPC Routing & Subnetting: Custom AWS Route Tables, local/static routes, VPC Peering, Private Subnets, Public Subnets, and NAT Gateways.
  • Network Ingress/Egress & Security: AWS Network Firewall, AWS Web Application Firewall (WAF), AWS Shield, Network Load Balancers (NLB), Application Load Balancers (ALB).
  • Private Service Connectivity: AWS PrivateLink (Interface and Gateway VPC Endpoints), Route 53 Resolver (Inbound/Outbound Endpoints), DNS Firewall.
  • Traffic Inspection & Monitoring: VPC Flow Logs, Traffic Mirroring (for forwarding copies of packets to IDS/IPS or third-party monitoring appliances).
  • Hybrid Connectivity Security: AWS Site-to-Site VPN, IPsec tunnels, Accelerated VPN.
Required Qualifications
  • Security Clearance: Active U.S. Government Secret clearance (Top Secret/SCI preferred) due to working on DISN/NIPRNet IL4 and IL5 networks.
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience.
  • Experience: 5+ years of dedicated cloud and hybrid networking experience with at least 3 years explicitly focused on AWS GovCloud (US)
  • DISA/SCCA Expertise: Direct experience managing connections to a DISA BCAP, configuring Boundary protection enclaves (VDSS), and implementing the SCCA Reference Design.
  • Protocol Depth: Strong foundation in BGP routing protocols, IPsec, GRE, NAT/PAT, TCP/IP stack behavior, and RFC 1918 private networking guidelines.
  • Automation: Proficient in automating network topologies using Terraform or CloudFormation, maintaining configuration versioning via Git.
  • DoD 8570/8140 Compliance: Meet IAT Level II baseline certification requirements (e.g., Security+ CE, CCNA Security, or CySA+), with an IAT Level III preferred (CISSP, CASP+).
Preferred Qualifications
  • AWS Certified Advanced Networking - Specialty (strongly preferred).
  • Palo Alto Networks Certified Network Security Engineer (PCNSE).
  • Demonstrated experience with AWS Transit Gateway Appliance Mode configuration for stateful third-party firewall traffic symmetry.
  • Previous experience operating within the DoD Joint Warfighting Cloud Capability (JWCC) or similar defense agency multi-cloud networks.
#J-18808-Ljbffr