$90K - 109K a year
Design, implement, and optimize secure AWS hybrid cloud network topologies including Direct Connect, VPN, and Transit Gateway, ensuring compliance and automation.
Bachelor's degree, 5+ years network engineering with 3+ years AWS networking experience, expertise in AWS Direct Connect, VPN, TGW, BGP, IPSec, and scripting.
About Heads in the Cloud (HITC) Heads in the Cloud (HITC) is a forward-thinking AWS Advanced Partner specializing in cloud architecture, migration, and managed services for both government and commercial clients. We help organizations modernize their infrastructure with secure, compliant, and scalable AWS solutions. Our expertise spans AI/ML, IoT, DR/BCP, FinOps, and multi-region networking, with a proven track record supporting agencies under VA IHT 2.0, DOE, and other federal transformation programs. We’re growing our bench of AWS-certified professionals under contingency for upcoming task orders and are seeking talented engineers ready to engage on federal and enterprise initiatives. Position Summary We are seeking a skilled AWS Cloud Network Engineer with hands-on experience in Direct Connect, Site-to-Site VPN, and Transit Gateway (TGW). The ideal candidate will design, implement, and optimize secure, scalable, and redundant network topologies that bridge on-premises and AWS environments. This is a contingency role — candidates will be shortlisted and activated upon contract award. Selected individuals will be part of the HITC Cloud Engineering Team, working collaboratively across AWS migration, DR, and security modernization projects. Key Responsibilities Network Architecture & Design • Design, deploy, and support AWS Direct Connect, VPN, and TGW architectures for hybrid cloud environments. • Architect multi-account VPC frameworks, including route tables, NACLs, security groups, and subnet segmentation. • Configure and manage BGP, IPSec, and DX Gateway for redundant, low-latency connectivity. • Support scalable, multi-region architectures through AWS PrivateLink, VPC Peering, and TGW Attachments. Implementation & Operations • Deploy and manage VPCs, Elastic IPs, NAT Gateways, and Load Balancers (ALB/NLB). • Troubleshoot and resolve complex routing and network issues using VPC Flow Logs, CloudWatch, and CloudTrail. • Work closely with DevOps and Security teams to maintain compliance across FedRAMP, CJIS, HIPAA, and DoD SRG environments. Security & Compliance • Apply Zero Trust principles, encryption (IPSec, TLS), and least-privilege access controls. • Maintain documentation and configuration baselines for audits and ATO readiness. • Support network segmentation and micro-segmentation strategies across hybrid workloads. Automation & Optimization • Leverage Terraform, AWS CDK, and CloudFormation for automated network deployments. • Optimize DX utilization and VPN throughput using AWS Network Manager and Transit Gateway Route Tables. • Provide continuous improvement recommendations to enhance resilience and reduce cost. Qualifications Required: • Bachelor’s in IT, Computer Science, or equivalent experience. • 5+ years of hands-on network engineering; 3+ years directly in AWS networking. • Proven experience with: • AWS Direct Connect provisioning, DX Gateway, and LAG configurations. • Site-to-Site VPN design, tunnels, and BGP failover. • Transit Gateway (TGW) routing, inter-region peering, and security segmentation. • Solid grasp of BGP, OSPF, IPSec, GRE, DNS, and NAT traversal. • Strong scripting skills (Python, Bash, or PowerShell) and proficiency in AWS CLI. Preferred: • AWS Certified Advanced Networking – Specialty • AWS Solutions Architect – Associate/Professional • CCNP / CCIE or equivalent certification. • Familiarity with AWS Organizations, Control Tower, and Service Catalog. Soft Skills • Strong analytical mindset and troubleshooting capabilities. • Excellent verbal and written communication. • Collaborative attitude, capable of working in agile, cross-functional environments. • Ability to operate with minimal supervision while driving measurable outcomes. Contract Details • Type: Contingency-Based Contract (activation upon task order award) • Duration: 12-month renewable (based on project performance) • Location: Remote (preferred US-based) • Clearance: Public Trust or ability to obtain • Compensation: Competitive market-based hourly rate; full-time conversion potential Why Join HITC • Engage in high-impact federal and enterprise AWS projects. • Collaborate with industry-recognized AWS architects and engineers. • Be part of an organization that emphasizes innovation, diversity, and career growth. • Access ongoing training, AWS certification support, and professional development. Job Types: Full-time, Contract Pay: $90,092.27 - $108,498.23 per year Benefits: • Health insurance Work Location: Remote
This job posting was last updated on 10/13/2025