Position Title: Systems and Network Engineer
Position Type: Full-Time, On-Site
Location: Aberdeen Proving Ground, MD
Clearance Requirement: Top Secret (Active)
Salary Range: $120,000 - $140,000 |
Start Date: 10/01 tentative
Position OverviewEmerald Technical Solutions is seeking a Systems and Network Engineer to support the sustainment and operation of a mission-critical, controlled development enclave supporting a new project at Aberdeen Proving Ground. This position owns the build and the run - keeping the domain, endpoints, network, and infrastructure services operating, implementing changes, and maintaining the as-built record that the program's compliance work depends on. The Systems and Network Engineer will work on-site full time and may be called on to provide occasional direct support to the broader program as needed.
Key ResponsibilitiesIdentity and Directory Services
- Operate the reactdev.com Active Directory domain, including domain controller health, replication, DNS, DHCP, and enclave time synchronization
- Administer Group Policy, including domain account policy, domain controller hardening, workstation baseline, legal notice banner, and update policy objects
- Maintain organizational unit structure, security groups, service accounts, and group managed service account rotation per the Personnel Roster and Access Model
- Provision, modify, and disable user and privileged accounts in accordance with the access model and tiered administration boundaries
- Operate the just-in-time elevation service granting developers time-boxed local administrator rights
- Operate the two-tier internal public key infrastructure, including issuance, revocation, certificate revocation list publication, and offline root custody
Endpoint and Imaging
- Maintain Windows 11 and Linux golden images, unattended installation answer files, and post-deployment configuration scripts
- Operate the PXE and imaging pipeline, including boot services, image distribution, driver packs, and hostname assignment
- Deploy, re-image, refresh, and decommission suite workstations, including full disk encryption enrollment and key escrow
- Perform profile migration for users moving from local to domain accounts
- Maintain the approved application baseline on endpoints and remove prohibited software
Network and Infrastructure
- Configure and maintain the enclave firewall, access switching, and, once authorized, wireless infrastructure
- Maintain VLAN segmentation, firewall rule base, port security, and network access control
- Operate the controlled update path used by network security devices
- Administer the virtualization platform, VM lifecycle, host hardening, and resource allocation
- Complete migration of the domain controller and virtual machines from interim hardware to the production server platform
- Design and implement secure remote access once authorized, including MFA, validated cryptography, and session logging
Sustainment
- Operate backup and recovery, including scheduled restore testing
- Operate in-enclave patch and content distribution services for Windows and Linux, including offline repository synchronization
- Apply security patches and firmware updates on the agreed maintenance cadence; remediate assigned findings
- Maintain equipment inventory, including serial numbers, hostnames, network addresses, and asset categorization
- Keep build/discovery documentation, network diagrams, and configuration records current
- Provide technical input to procurement specifications, bills of materials, and vendor quotes
Required Qualifications- Bachelor's degree in computer science, information technology, or a related field, or an equivalent combination of education and experience
- Five years of hands-on systems and network engineering experience, including at least two years in a controlled or disconnected environment
- Windows Server and Active Directory administration, including Group Policy authoring and PowerShell automation
- Linux administration (RHEL or Ubuntu), including Active Directory integration through SSSD and realmd
- Cisco IOS XE switching and Cisco firewall administration, including VLAN segmentation and rule base management
- Virtualization platform administration and VM lifecycle management
- DoD 8570/8140 IAT Level II certification, or ability to obtain within 90 days of start
- Active Top Secret clearance, with ability to obtain and maintain facility access required for the program
Preferred Qualifications- Cisco CCNP Security or equivalent; Red Hat Certified Engineer or equivalent
- Experience applying DISA Security Technical Implementation Guides (STIGs) and SCAP content
- Experience with network installation imaging at scale (PXE, unattended installation, automated provisioning)
- Public key infrastructure and smart card/PIV credential experience
- Prior work inside a CMMC or NIST SP 800-171 assessed boundary
Benefits- Competitive salary and performance-based bonuses
- Comprehensive health, dental, and vision insurance
- 401(k) with company match
- Paid time off and federal holidays
- Professional development and certification reimbursement
- Long-term career growth within a growing SDVOSB defense contractor