
Solution Architect Senior
- Oakton, VA
- Permanent
- Full-time
Responsibilities
- Analyze network traffic using PCAP data to identify abnormal patterns, anomalies, or security threats
- Establish and maintain baseline network traffic profiles for normal behavior across different enclaves
- Work with cybersecurity and IT operations teams to investigate incidents using packet-level data
- Collaborate with tool owners to ensure optimal configuration and visibility in ExtraHop, SolarWinds, and Splunk
- Conduct protocol-level analysis of TCP/IP, DNS, HTTP/S, SMTP, and encrypted tunnels (e.g., TLS, VPN) to identify misuse, threats, or performance issues
- Develop traffic reports, summaries, and actionable insights for both technical and non-technical stakeholders
- Support tuning of alerts, dashboards, and data feeds that rely on network traffic sources
- Provide mentorship and guidance to junior engineers and analysts on the best practices of traffic analysis
- Assist in the development and documentation of network monitoring and troubleshooting procedures, including diagnosing MTU and packet fragmentation issues
- Bachelor’s degree in a related field OR
- Associate degree with 2+ additional years of relevant IT experience OR
- High school diploma or GED equivalent required with 4+ additional years of directly related IT experience in lieu of a degree
- 12+ years of experience in Enterprise Network Engineering, Traffic Analysis, or Cybersecurity
- Extensive experience in analyzing PCAP data using tools such as Wireshark, tcpdump, Zeek, Cisco products, or ExtraHop
- Must hold a current DoD 8140 (or 8570) baseline certification at the IAT Level II or higher (e.g., CompTIA Security+)
- U.S. Citizen with active TS/SCI clearance required
- Deep understanding of network protocols, packet structures, and flow analysis
- Proficiency in interpreting full packet captures for security, troubleshooting, and performance analysis
- Familiarity with network detection and performance tools such as ExtraHop, SolarWinds, and Splunk
- Experience with protocol dissection, filtering, and decoding in tools like Wireshark
- Ability to correlate network behavior with system or application issues
- Excellent documentation and communication skills to convey complex findings
- Strong problem-solving skills and situational awareness during live troubleshooting or incident response
- May require participation in meetings or briefings in person or via virtual platforms.
- Ability to travel occasionally, as required by the client or project.
- Ability to move about inside the office to access file cabinets, printers, or meeting rooms.