Clearance: Active TS/SCI Clearance at time of consideration.
12+ years of progressive systems engineering experience within DoD/DoW, federal, or defense contractor enterprise environments.
Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of prior relevant experience or Masters with 10 – 13 years of prior relevant experience.
May possess a Doctorate in technical domain. Specific experience, education and training may be considered in lieu of degree.
Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).
Active Computing Environment certification, including one of: VMware VCP/VCAP, Nutanix NCP, Red Hat Certified Engineer (RHCE), Microsoft Certified: Windows Server Hybrid Administrator Associate
Direct experience drafting CSfC Key Management Plans (KMPs) and Continuous Monitoring Plans (CMPs) for NSA CSfC PMO approval.
Proficiency with PowerShell, Bash, and Ansible for automated STIG remediation, configuration drift detection, and certificate deployment
Advanced configuration of syslog daemons (Rsyslog, Syslog-ng) and forwarding architectures to enterprise SIEM platforms (e.g., Splunk, Elastic).
Build, manage, and optimize virtualized compute and storage fabrics utilizing VMware vSphere / ESXi or Nutanix AHV with vSAN/distributed storage. Design resilient, air-gapped backup and disaster recovery (DR) pipelines.
Deploy, configure, and administer hardened Microsoft Windows Server (Active Directory, DNS, Group Policy) and Red Hat Enterprise Linux (RHEL) systems.
Establish centralized, tamper-resistant Syslog and audit logging infrastructure across all network and system devices, hypervisors, and operating systems to support continuous monitoring and SIEM ingestion.
Understanding of cross-domain systems and forwarding log data through it to a centralized SIEM
Build and maintain automated OS deployment and gold image pipelines using Microsoft Configuration Manager (MCM/SCCM) for CSfC End User Devices (EUD).
Apply and validate patching and STIGs across all virtual and physical infrastructure. Execute vulnerability scans, track IAVMs, and remediate findings to maintain Authorization to Operate (ATO).