System Administrator (Clearance Required
Listed on 2026-07-30
-
IT/Tech
Cybersecurity, Systems Administrator
System Administrator (Clearance Required)
Technology
Technology | Washington, DC, United States |
Location: Fort Meade, MD
Clearance Required: Top Secret/SCI with Active Full Scope Polygraph
We are seeking an experienced Linux-focused System Administrator (Level
2) to support a mission‑critical program within the Intelligence Community at Fort Meade, MD. This is an on‑site position in a Sensitive Compartmented Information Facility (SCIF) environment requiring a TS/SCI clearance with an active Full Scope Polygraph prior to consideration. The successful candidate will be responsible for the day‑to‑day administration, security compliance, and operational health of complex Linux‑based infrastructure spanning virtualized environments, container platforms, and classified networked systems.
The SA Level 2 operates with a high degree of independence and serves as a technical authority on Linux systems engineering, PKI/cryptographic policy enforcement, storage management, IP networking, and security compliance. This role carries significant responsibility for System Security Plan (SSP) maintenance, STIG implementation, and supporting Secure Telephone Equipment/Network (STE/STN) infrastructure within a heavily regulated RMF/NIST framework.
Key Responsibilities- Administer, configure, harden, and maintain Red Hat Enterprise Linux (RHEL), Rocky Linux, and/or CentOS Stream server environments.
- Apply and maintain DISA STIG configurations using OpenSCAP and other SCAP‑compliant tooling; remediate findings from automated scans.
- Manage system performance tuning, patch management (yum/dnf), software package management, and OS lifecycle operations.
- Configure and manage system services, daemons, scheduled tasks, logging (rsyslog/journald), and audit frameworks (auditd).
- Provide Tier 1 and Tier 2 application support and general troubleshooting across all Linux‑based systems.
- Support ongoing System Security Plan (SSP) development, maintenance, and compliance activities in accordance with NIST SP 800‑53 Rev 5 controls.
- Conduct and document Risk Management Framework (RMF) activities including control implementation statements, POA&M tracking, and continuous monitoring.
- Perform and respond to vulnerability assessments; coordinate CVE remediation and ensure timely patching.
- Maintain system authorization boundaries, support A&A activities, and coordinate with the ISSO/ISSM.
- Install, configure, and maintain Secure Telephone Equipment (STE) and Secure Telephone Network (STN) infrastructure.
- Coordinate STE/STN provisioning, moves, adds, and changes (MACs) with communications and security personnel.
- Troubleshoot STE/STN connectivity and interoperability issues.
- Maintain accurate inventory and documentation for all STE/STN endpoints.
- Manage DoD PKI operations including certificate issuance, renewal, revocation, and trust store management.
- Configure and maintain TLS/SSL for system services and applications.
- Administer hardware security modules (HSMs) and software‑based key management systems where deployed.
- Apply and enforce system crypto policies to ensure FIPS compliance across all managed systems.
- Deploy, operate, and maintain containerized workloads using Docker and/or Podman.
- Administer Kubernetes or Open Shift container orchestration clusters within classified/air‑gapped environments.
- Manage container image pipelines including base image hardening, vulnerability scanning, and approved image registries.
- Support lifecycle management of containerized applications.
- Administer VMware vSphere/vCenter environments including ESXi host management.
- Manage KVM/QEMU‑based virtual environments on Linux hosts.
- Coordinate capacity planning and resource optimization across virtualized infrastructure.
- Administer NAS and SAN systems; manage LUN provisioning, zoning, and multipath I/O.
- Operate and maintain Ceph distributed storage clusters.
- Configure and manage LVM, RAID arrays, and file system operations.
- Implement and verify data‑at‑rest encryption requirements.
- Configure and manage…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).