69-090 – Network/System Administrator III
Sandy Mac Evolution LLC is seeking an experienced Network/System Administrator III to support Department of Defense Special Access Program environments at Joint Base Anacostia-Bolling in Washington, DC.
The selected candidate will organize, install, administer, and support secure government computer systems and data communications infrastructure, including local area networks, wide area networks, network segments, intranets, servers, virtualization platforms, security appliances, and enterprise monitoring systems.
This senior-level position will provide day-to-day support for Collateral, Sensitive Compartmented Information, and Special Access Program activities supporting organizations such as Headquarters Air Force, the Office of the Secretary of Defense, and other military compartmented programs. The Network/System Administrator III will also help lead daily IT operations, maintain compliance with Joint Special Access Program Implementation Guide and Risk Management Framework requirements, support security assessments, and contribute to infrastructure modernization decisions.
Independently perform assigned duties with little to no direct oversight.
Lead daily IT operations and support the management, administration, and maintenance of secure networks and information systems.
Implement technical capabilities approved by Cybersecurity, Information System Security Engineering, and higher headquarters.
Maintain JSIG and RMF Authority to Operate requirements and support continuous monitoring processes.
Administer local area networks, wide area networks, network segments, intranets, servers, workstations, and other data communication systems.
Help architect, design, evaluate, and analyze secure network models and infrastructure solutions.
Support recommendations and decisions regarding future hardware, software, networking, and infrastructure upgrades.
Manage commercial off-the-shelf and government off-the-shelf products used to collect, display, analyze, and remediate system security, operations, and performance data.
Operate enterprise security monitoring tools and Security Information and Event Management platforms.
Create and tailor complex event alarms, correlation rules, dashboards, and summary reports.
Monitor and analyze cybersecurity tools for reportable incidents, vulnerabilities, anomalous activity, and residual risk.
Execute cybersecurity procedures supporting daily network management, operations, maintenance, and incident response.
Participate as a member of the security incident response team when required.
Assist with security assessments of servers, network devices, security appliances, and supporting technologies.
Support the accuracy, completeness, and efficiency of technical security assessments.
Assist in evaluating the technical risks associated with emerging cybersecurity tools, technologies, and processes.
Develop daily, weekly, monthly, and annual operations and maintenance checklists.
Create and maintain technical procedures, Tactics, Techniques, and Procedures, and Standard Operating Procedures.
Collaborate with Information System Security Managers, Information System Security Officers, and Information System Security Engineers to improve the confidentiality, integrity, and availability of systems operating at multiple classification levels.
Provide technical support to users and troubleshoot hardware, software, account, system, network, and connectivity issues.
Support configuration management, patch management, vulnerability remediation, system hardening, backup operations, and access-control administration.
Maintain technical documentation, system configurations, network diagrams, operational records, and assessment evidence.
Ensure compliance with applicable Department of Defense policies, Special Access Program requirements, cybersecurity standards, and organizational procedures.
Five to seven years of related network administration, system administration, cybersecurity, or information technology experience.
At least two years of experience supporting Special Access Programs.
Demonstrated ability to operate independently and perform senior-level technical responsibilities with minimal oversight.
Thorough knowledge of Microsoft Windows desktop and server operating systems.
Experience administering Microsoft Active Directory, Group Policy, and enterprise user environments.
Experience with Microsoft Exchange Server and associated enterprise infrastructure.
Working knowledge of Red Hat Enterprise Linux administration and supporting hardware.
Experience supporting Local Area Network and Wide Area Network technologies.
Working knowledge of Cisco networking, routing, switching, and network-security technologies.
Experience with virtualization technologies as applied to servers, operating systems, user environments, and network appliances.
Working knowledge of data backup, restoration, and continuity technologies.
Experience with Windows Server Update Services and/or YUM patch deployment methodologies.
Working knowledge of communication security policies and integration.
Knowledge of the Risk Management Framework and its application to network and information-system environments.
Knowledge of Common Criteria, system security policies, assessments, authorization, and continuous monitoring.
Current or recent experience supporting Protection Level 2, Protection Level 3, and Protection Level 4 network environments or systems.
Familiarity with Department of Defense policies governing system and network administration.
Strong written and verbal communication skills.
Demonstrated ability to collaborate effectively in a high-performance technical and cybersecurity team environment.
Ability to regularly lift equipment weighing up to 50 pounds.
Candidates should demonstrate advanced technical competency in one or more of the following areas:
Microsoft Windows Server
Windows 10 or later operating systems
Active Directory
Group Policy design and configuration
Red Hat Enterprise Linux
Microsoft Hyper-V
VMware and ESXi
Xen hypervisors
Enterprise networking, firewalls, and intrusion detection or prevention systems
Vulnerability assessment and forensic-analysis technologies
PowerShell, Bash, or other scripting languages
Microsoft Exchange Server
Microsoft SQL Server
Oracle or Microsoft SQL database security
Internet Information Services
Apache and Tomcat web-server technologies
Web-server security and hardening
BMC FootPrints
Windows Server Update Services
Endpoint management and application-control technologies
BitLocker encryption
Video teleconferencing and Voice over Internet Protocol systems
Relevant experience may include:
Security Information and Event Management platforms
LogRhythm
Assured Compliance Assessment Solution
Nessus
Security Content Automation Protocol tools
Vulnerability scanning and remediation platforms
Enterprise logging and continuous-monitoring tools
Mandatory and role-based access-control concepts
Security-Enhanced Linux
AppArmor
PitBull
Sentris
Intrusion detection and prevention systems
Enterprise firewalls and network-security appliances
Bachelor’s degree in information technology, cybersecurity, computer science, information systems, engineering, or a related discipline.
Four additional years of relevant professional experience may be accepted in place of the bachelor’s degree.
The selected candidate must meet the position and certification requirements established by DoD Directive 8570.01-M for Information Assurance Technician Level III within six months of the date of hire.
Qualifying certifications may include applicable DoD-approved IAT Level III certifications.
Active Top Secret clearance with Sensitive Compartmented Information eligibility is required at the time of application.
Must be eligible for access to Special Access Program information.
Must be willing to submit to a Counterintelligence polygraph.
Must maintain all required security clearances, accesses, and certifications throughout employment.
Employment is contingent upon verification of clearance status and satisfaction of all customer security requirements.
This position is performed onsite within secure Department of Defense facilities at Joint Base Anacostia-Bolling. Remote or hybrid work is not available due to the classified nature of the program.
Sandy Mac Evolution LLC is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, or any other status protected by applicable federal, state, or local law.