Overview In this role you will lead the architecture and lifecycle management of enterprise-scale DNS, DHCP, and IPAM services for NASA networks, ensuring secure, compliant name resolution. You will partner with Engineering, System Administration, and Operations to deliver resilient DDI capabilities aligned to NIST, CISA, and Zero Trust directives. You'll drive modern DNS practices, IPv6-first strategies, and DNS security programs across large, mission-critical environments. This position offers impact by shaping secure, scalable DNS operations and contributing to federal domain stewardship at the E-root level.
Responsibilities- Design and maintain authoritative and recursive DNS architectures with DNSSEC and DS management
- Operationalize NIST SP 800-81r3 guidance for secure DNS, including DoT/DoH/DoQ, logging, and QNAME minimization
- Ensure PDNS integration and enforce encrypted DNS policies aligned with CISA guidance and Zero Trust
- Align with BODs (18-01, 22-01, 23-01, 23-02) and pursue KEV remediation and asset visibility controls
- Drive IPv6-first strategy and dual-stack hygiene for DNS, DHCPv6, and IPAM
- Lead secure configurations, automation, availability, and performance in large DDI environments
- Integrate protective controls and SIEM/SOAR for forensics and incident response per NIST guidance
- Maintain vulnerability management aligned to KEV and coordinate remediation timelines
- Secure management interfaces and enforce Zero Trust for DNS/DHCP/IPAM admin
- Govern DNS email configurations (SPF/DKIM/DMARC) to meet BOD requirements
- Participate in E.root operations and ensure .gov domain compliance with DNSSEC and secure delegation
- Administer IPv4/IPv6 address allocations with ARIN policies and best practices
- Evaluate and integrate DDI modernization (encrypted DNS, DNSSEC automation, DHCPv6, IPAM APIs)
Key requirements- Bachelor's degree or equivalent plus 10+ years enterprise DDI experience (DNS/DHCP/IPAM)
- Hands-on DNSSEC, validating resolvers, signed zones, and DS management
- Experience with NIST SP r3 practices and protective DNS, DoT/DoH/DoQ
- Proven track record implementing BODs ( ) and KEV-driven patching
- IPv6 expertise in DNS, DHCPv6, and IPv6 transition strategies per OMB M
- Familiarity with .gov DNSSEC requirements and secure delegation
- Knowledge of ARIN policies, address planning, and RPKI; reverse DNS hygiene
- Clearance: U.S. Citizenship and ability to obtain Public Trust
- Root server operations familiarity (preferred) and RSSAC 002 awareness
- leadership in large, complex environments
- cross-functional collaboration
- ability to translate federal requirements into architecture
- DNSSEC automation
- DoT/DoH/DoQ
- PDNS or similar DNS platforms