Start Your Search Here

push notification bell

Would you like to receive notifications about jobs in Aberdeen Proving Ground?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

Emerald Technical Solutions

Aberdeen Proving Ground / Global

Network/Systems Engineer

Job Description

Systems And Network EngineerEmerald Technical Solutions is seeking a Systems and Network Engineer to support the sustainment and operation of a mission-critical, controlled development enclave supporting a new project at Aberdeen Proving Ground. This position owns the build and the run - keeping the domain, endpoints, network, and infrastructure services operating, implementing changes, and maintaining the as-built record that the program's compliance work depends on. The Systems and Network Engineer will work on-site full time and may be called on to provide occasional direct support to the broader program as needed.Key ResponsibilitiesIdentity and Directory ServicesOperate the reactdev.com Active Directory domain, including domain controller health, replication, DNS, DHCP, and enclave time synchronizationAdminister Group Policy, including domain account policy, domain controller hardening, workstation baseline, legal notice banner, and update policy objectsMaintain organizational unit structure, security groups, service accounts, and group managed service account rotation per the Personnel Roster and Access ModelProvision, modify, and disable user and privileged accounts in accordance with the access model and tiered administration boundariesOperate the just-in-time elevation service granting developers time-boxed local administrator rightsOperate the two-tier internal public key infrastructure, including issuance, revocation, certificate revocation list publication, and offline root custodyEndpoint and ImagingMaintain Windows 11 and Linux golden images, unattended installation answer files, and post-deployment configuration scriptsOperate the PXE and imaging pipeline, including boot services, image distribution, driver packs, and hostname assignmentDeploy, re-image, refresh, and decommission suite workstations, including full disk encryption enrollment and key escrowPerform profile migration for users moving from local to domain accountsMaintain the approved application baseline on endpoints and remove prohibited softwareNetwork and InfrastructureConfigure and maintain the enclave firewall, access switching, and, once authorized, wireless infrastructureMaintain VLAN segmentation, firewall rule base, port security, and network access controlOperate the controlled update path used by network security devicesAdminister the virtualization platform, VM lifecycle, host hardening, and resource allocationComplete migration of the domain controller and virtual machines from interim hardware to the production server platformDesign and implement secure remote access once authorized, including MFA, validated cryptography, and session loggingSustainmentOperate backup and recovery, including scheduled restore testingOperate in-enclave patch and content distribution services for Windows and Linux, including offline repository synchronizationApply security patches and firmware updates on the agreed maintenance cadence; remediate assigned findingsMaintain equipment inventory, including serial numbers, hostnames, network addresses, and asset categorizationKeep build/discovery documentation, network diagrams, and configuration records currentProvide technical input to procurement specifications, bills of materials, and vendor quotesRequired QualificationsBachelor's degree in computer science, information technology, or a related field, or an equivalent combination of education and experienceFive years of hands-on systems and network engineering experience, including at least two years in a controlled or disconnected environmentWindows Server and Active Directory administration, including Group Policy authoring and PowerShell automationLinux administration (RHEL or Ubuntu), including Active Directory integration through SSSD and realmdCisco IOS XE switching and Cisco firewall administration, including VLAN segmentation and rule base managementVirtualization platform administration and VM lifecycle managementDoD 8570/8140 IAT Level II certification, or ability to obtain within 90 days of startActive Top Secret clearance, with ability to obtain and maintain facility access required for the programPreferred QualificationsCisco CCNP Security or equivalent; Red Hat Certified Engineer or equivalentExperience applying DISA Security Technical Implementation Guides (STIGs) and SCAP contentExperience with network installation imaging at scale (PXE, unattended installation, automated provisioning)Public key infrastructure and smart card/PIV credential experiencePrior work inside a CMMC or NIST SP 800-171 assessed boundaryBenefitsCompetitive salary and performance-based bonusesComprehensive health, dental, and vision insurance401(k) with company matchPaid time off and federal holidaysProfessional development and certification reimbursementLong-term career growth within a growing SDVOSB defense contractor
Apply Now

Similar Opportunities

View all jobs

Get Job Alerts

Don't miss the perfect fit. Get Daily curated job alerts.

Job Title or Keyword(s)
Location