Remote Position:
Hybrid
Region:
Americas
Country:
Canada
State/Province:
Ontario
City:
Toronto
Summary
We are seeking an experienced, compliance-driven RDL Jump Host Administrator to take ownership of the system administration, security, and access control of our global local jump hosts. Reporting directly to the Lead Network Architect, and working in close alignment with the RDL Network Administrator, you will manage secure access pathways into completely isolated, air-gapped lab networks across multiple HPS Design Centers (including San Jose, Richardson, Thailand, Shanghai, Song Shan Lake, Penang, Chennai, and future sites).
The primary objective of this role is to ensure that remote connections terminating from corporate Zscaler ZTNA or customer Cyber Ark vPAM environments are securely processed, authenticated, and audited. Since our environments strictly prohibit Active Directory or domain joins, you will manage decentralized, local authentication configurations, shell environments, and session boundaries.
Crucially, you will implement and maintain the strict compliance frameworks required for Export Controlled VLANs—including interactive terms-of-use banners, mandatory user acceptance gates for shell access, and tamper-proof user-acceptance audit logging.
Core Responsibilities
1. Jump Host System Administration & Hardening
Deploy, configure, and maintain Linux-based (Rocky Linux, Ubuntu, CentOS) local jump host virtual machines operating on VMware vSphere or Microsoft Hyper-V clusters.
Apply strict CIS (Center for Internet Security) hardening benchmarks on all jump host operating systems. Ensure that no unauthorized software or corporate agents (e.g., Crowd Strike, Service Now, Clear Pass, Windows Domain utilities) are installed or active on endpoints installed on the VLAN behind the Jump Host.
Ensure the high availability, performance, patch status, and storage capacity of jump servers acting as gateways to the core RDL networks.
2. Export Control Compliance & Interactive Gates
Configure and manage interactive, mandatory user agreement screens (e.g., using custom shell login scripts, Pluggable Authentication Modules (PAM), or SSH Force Command) specifically for systems accessing Export Controlled VLANs.
Ensure that users cannot acquire an interactive shell, run commands, or bypass the landing screen without explicitly reading and accepting the export control and NDA terms.
Implement and maintain robust, structured logging systems (using Rsyslog, Journald, or custom secure local logging scripts) that capture:
The authenticated user's local/remote identifier. Source IP and connection timestamp. Explicit timestamped confirmation of the user's compliance acceptance.
Set up secure, write-only log forwarding or local hashing protocols to ensure audit logs of export-control acceptances cannot be modified or deleted by general users.
3. Identity, Access, & Session Management
Programmatically or manually provision local Unix user accounts, localized Role-Based Access Control (RBAC), and SSH keys on all jump hosts.
Partner with corporate IT to ensure seamless hand-offs from Zscaler ZTNA (via local Zscaler App Connectors) and Cyber Ark vPAM sessions terminating on the jump hosts.
Configure strict SSH timeouts, idle session terminations, and multi-factor authentication loops to prevent abandoned active connections.
4. Operations, Ticket Resolution & Collaboration
Collaboration:
Align daily with the RDL Network Administrator…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).