System Administrator 3

First Tek, Inc.

$88K — $105K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field preferred
  • 8 years of relevant experience with an Associate's/Bachelor's; 10 years without a degree
  • 5 years experience in Active Directory administration and related services
  • 7 years of troubleshooting knowledge in Windows operating systems
  • 2 years of experience with Active Directory Federation Services and federated identity concepts

Responsibilities

  • Research and document technical procedures for server hardware and software
  • Perform system vulnerability assessments and recommend mitigation options
  • Schedule and conduct regular risk assessments on network equipment
  • Act as an escalation point for service performance incidents
  • Provide recommendations for process adjustments due to environmental changes
  • Support disaster recovery efforts ensuring domain service availability
  • Create and recommend functional documentation and conduct user training

Benefits

  • Situational telework eligibility
  • Full-time hours with the potential for routine telework
  • On-call duty approximately one week every 4-5 weeks
  • Opportunity to participate in training and workshops approved by management
  • Adherence to BPA’s Cyber Security and audit compliance requirements
Full Job Description


*** | SUPPLEMENTAL LABOR MANAGEMENT OFFICE

ADDITIONAL PROCUREMENT INFORMATION (API)

Title & Level

System Administrator 3

Work Group Location

Portland, OR

Specialty

Domain Administration

Offsite Work Eligibility*

Situational Telework

Organization

JNDI

Number of Days Onsite

5 days per Week

Hours

Full-Time, up to 40 hours

Additional Information

This assignment potentially could transition to routine telework at the manager's discretion.

Overtime

10% anticipated

On-Call

Yes One week every 4-5 weeks

Travel

N/A

FN Status

NOT open to Foreign Nationals

* Current telework, remote work and onsite support is based on BPA's business needs and is subject to change or termination at any time.

** Assignments with the "Remote" Designation must reside in WA, OR, ID or MT. Case-by-case exceptions may apply only when in the best interest of BPA.

OVERVIEW

Assignment

This contract System Administrator primarily focuses on Domain Administration. This assignment plays an integral role in building and maintaining the authentication and authorization environment, administering and troubleshooting hybrid identity environments (ensuring synchronization between on-premises Active Directory and Entra ID), planning for and managing capacity and providing Domain support services. This work required of this assignment must adhere to BPA's Cyber Security policies and be performed in a manner that is compliant with BPA's audit requirements.

Organization

This System Administrator 3 assignment will work within the Converged Infrastructure (JNDI) organization within Data Center Services (JND) subgroup within the Infrastructure Services (JN) group in the Information Technology (J) business line of *** (BPA). The JNDI organization provides storage, compute, virtualization, virtual desktop, authentication and authorization services as a part of the greater JN infrastructure services group. JND also augments facilities support for the production data centers.

ASSIGNMENT RESPONSIBILITIES

Note: All official drafts, documents and recommendations, as listed below, must be reviewed, finalized and approved / accepted by appropriate BPA manager or other federal personnel with the authority to do so.

Research, test and document standardized technical procedures for the deployment / troubleshooting of server hardware, the associated operating systems and application software.

Perform system vulnerability assessments using vendor native (MS SCT) and third party tools (Nessus), recommending mitigation options based on risk of exploit after consideration of environmental factors.

Schedule and perform risk assessments regularly and when vulnerabilities are identified on operational network equipment, such as computer systems devices and various software packages.

Act as a service response escalation point, working with teams of varying technical ability in response to service availability and/or performance related incidents / problems.

Provide recommendations for process / procedural changes that may become necessary due to environmental changes, upgrades.

Support disaster recovery by verifying continuous availability of domain services such as Active Directory, DNS, DHCP, IPAM, Client.

Serve as a technical advisor for project and service response and related tasks.

Apply the aforementioned processes/procedures in support of the following technologies:

Microsoft Windows Server 2019/2022/2025

Microsoft Active Directory

Microsoft DNS

Microsoft ADFS

Microsoft Client

Microsoft Public Key Infrastructure solutions

Hardware Security Module support for protection of private keys

SAML, OAuth 2.0, OpenID Connect and SCIM

FIDO2 security keys

As requested, provide system administration expertise for special projects, which may include working with internal and external clients and vendors. This includes technical input and recommendations; automation solutions; and, other system administration actions. Confer with BPA workplace manager or federal team lead on a routine basis for project status updates and/or any project issues.

Provide technical input and recommendations, as a non-voting participant, for potential acquisitions in area of expertise.

Provide systems administration support for any new systems added to BPA's IT infrastructure, assisting with testing, configuration, integration and implementation efforts, including developing test plans, implementation schedule, scope, dependencies, documentation, and user training.

Create, develop / draft and recommend cross training and functional documentation of subject matter for BPA audiences; conduct User training on an individual or group basis as requested.

Participate in BPA process workshops, including project lessons learned, group improvement and documentation efforts for procedures, processes, standards, guidelines, practices, and other technical and instructional material.

UREQUIREMENTS

Education & Corresponding Experience (required on matrix)

Bachelor's Degree in Computer Science, Information Technology, Engineering, or a related technical field is preferred.

With an Associate's or Bachelor's Degree in applicable fields, 8 years of experience is required.

With an Associate's or Bachelor's Degree not in applicable fields or without a degree, 10 years of experience is required.

Applicable Certifications may count for 1 year of experience.

Experience must include direct work experience in Information Technology performing System Administration.

Required Technical Skills & Experience (required on matrix)

5 Years of knowledge and experience sufficient to administer disparate Active Directory domains and services necessary to support these domains such as DNS, ADCS, Client.

7 Years of knowledge of and experience sufficient to successfully troubleshoot Windows operating systems using text-based logs, windows event logs, and various utilities.

5 Years of knowledge of and experience with TCP/IP and related services.

5 Years knowledge of and experience with Kerberos authentication in enterprise environments and a strong understanding of Active Directory (AD) integration, LDAP, and hybrid-joined infrastructure.

2 Years knowledge and experience of Active Directory Federation services as well as federated identity concepts to support authentication in a SaaS environment.

2 years Hands-on experience with Microsoft Entra ID and a solid understanding of SSO and identity protocols such as SAML, OAuth 2.0, OpenID Connect, and SCIM. Implementation of FIDO2 security keys and experience migrating large enterprise user bases from traditional MFA to passwordless solutions is desirable.

Preferred Skills & Experience (optional on matrix)

Direct experience operating an enterprise cyber vulnerability scanning and assessment infrastructure such as Nessus.

Experience configuring and managing systems using Puppet Enterprise.

Strong knowledge and experience with PowerShell to automate processes, gather information and make infrastructure configuration changes.

Windows operating system and software packaging, installation, and troubleshooting.

VMware vSphere administration and operation.

Additional Requirements (not required on matrix)

Valid U.S. Driver's License is required.

Appendices

The following appendices apply to this assignment and may be downloaded from the Fieldglass Reference Library:

Offsite Work

Training Expectations (Worker is expected to keep current on the latest technologies and skills required for the assignment.)

Training Type

Details

Provided by

Attendance at all conferences, workshops, training, etc. must be pre-approved by SLMO. Requests will be reviewed on a case-by-case basis. Approval is subject to the most current guidance provided to SLMO by BPA or DOE and is subject to change at any time. SLMO reserves the right to negotiate attendance on billable/non-billable hours and reimbursement of travel costs with the supplier. Reimbursable travel costs must adhere to the Federal Travel Regulations and be submitted via an expense sheet in Fieldglass.

CLOSELY ASSOCIATED RESPONSIBILITIES & REQUIRED ASSOCIATED MITIGATION MEASURES

The following is a list of potential inherently governmental risk areas and the measures that SLMO-Compliance has determined must be in place, via processes and procedures, to mitigate the associated risks. The BPA manager's acceptance of the API or CWSD serves as their attestation that all applicable mitigation measures listed below are or will be established and adhered to in their organization.

Area of potential Closely Associated / Inherently Government function

Mitigation Measures

Access to Confidential / Sensitive Information

CFTE must sign NDA (Non-Disclosure Agreements) at beginning of assignments. (Does not apply to Craft assignments)

CFTE must complete annual Information Security and Privacy Awareness training.

CFTE must complete and pass background investigations of an appropriate level.

Acquisition Planning / Source Selection

CFTE are not permitted to serve as "voting" members for acquisition selections.

All purchasing decisions must be made by appropriate federal personnel (Contracting Officers).

All acquisition documents (requirements,
SOW's, evaluation criteria, etc.) must be reviewed, finalized and approved by appropriate BPA federal personnel.

Only Contracting Officers are authorized to obligate BPA funds.

Agency / Org Planning

All drafts, documents, materials and recommendations must be reviewed, finalized and approved by appropriate BPA federal personnel.

Budget / Finance Prep

Only Federal Employees may determine budget priorities & allocations.

BFTE must control and finalize / approve all budgets and related documentation, including that for projects, programs and Organizations.

Contract Management

All Contractual documents, including invoices must be finalized / approved by appropriate Federal personnel.

All contract-related decisions (modifications, changes, performance) must be determined by appropriate federal personnel (COs).

Decision Making

CFTE may provide input and recommendations to decision-makers.

Only appropriate federal personnel may make decisions which obligate BPA resources or to a specific course of action.

Direction & Control
(directing BFTE)

CFTE are not permitted to direct the actions of federal employees (BFTE) or have any control or input into their performance.

Work of BFTE must be assigned by federal manager, supervisor, Program / Resource manager or another appropriate designee.

Disposing Govt. Property

All decisions regarding the disposal of BPA property must be made by appropriate federal personnel; and all property dispositions must be directed and controlled by the Investment Recovery Center (IRC).

Dissemination of Agency/Policy Information / Training

All training and any information that is to be disseminated must be either 1) per established policy, process, procedure, or practice; or, 2) reviewed, finalized and approved by appropriate BPA federal personnel.

Inspection / IT Testing

Processes and procedures must ensure Federal personnel review inspection findings and CFTE recommendations before acceptance or rejection of material(s) / item(s).

HR Support

CFTE may assist with HR functions per established procedures, processes and guidelines (e.g., timekeeping).

All work products must be reviewed and finalized by appropriate federal employees.

Policy Development

BPA's process for Policy development includes multiple levels of federal review prior to acceptance / adoption.

Interpretation of Policy/Regulations

Only BPA federal employees may determine the applicability and interpretation of regulations.

CFTE are not permitted to "interpret" regulations for or on behalf of BPA. Regulations are interpreted by federal personnel and communicated via standards, guides, policies and processes.

Representing BPA

Contract workers are required to identify themselves and their employer in signature blocks, in introductions and have a nameplate outside their cubicle.

CFTE must receive written VP approval to represent BPA at outside events, such as workshops, seminars or conferences.

Page 4 of 4 F_0121_API_TEMPLATE_030626
CFTE NON-CRAFT HIRING SAFETY TRAINING MATRIX

CONTRACT FULL TIME EQUIVALENT (CFTE)

NON-CRAFT HIRING SAFETY TRAINING MATRIX

Purpose:

The Contract Full Time Equivalent (CFTE) Hiring Safety Training Matrix is a hazard assessment for CFTE personnel routine tasks. It is intended to set a common understanding on training requirements between the CFTE personnel and the *** (BPA) managers/supervisors. BPA Requesting Managers should complete this form and coordinate with BPA Supplemental Labor Office during the procurement process to ensure the CFTE position includes a list of required trainings associated with identified tasks, conditions, and exposures. Each task, condition, and exposure indicate which training courses are required, who shall provide those trainings, and when those trainings shall occur.

This form is intended only as a reference document for contractors.

BPA Requesting Manager

(Last, First MI)

Bingaman, Paul R

Date

6/17/2026

CFTE Job Title

System Administrator 3 - Domain Administration

Org

JNDI

PPE provided by Supplier or Contractor?
• Yes ☒ No

If yes, list required PPE: Click or tap here to enter text.

Identify which Supplier or Contractor medical surveillance programs are required, if any*
• Respirator User
• Asbestos
• Lead
• Silica
• Hearing Conservation
• Other: Click or tap here to enter text.

☒ No Medical Surveillance

*BPA Requesting Managers may use equivalent Job Title Position Hazard

Similar Jobs

More Jobs at First Tek, Inc.

  • Design Engineer
    $80K — $95K *
    Orlando, FL 32828 (Orange County)
    Aerospace & Defense
    In-Person
  • System Administrator 3
    $88K — $105K *
    Portland, OR 97229 (Washington County)
    Information Technology
    Hybrid
  • Safety Engineer
    $95K — $115K *
    Remote
    Aerospace & Defense
    Remote in Liverpool, NY
  • Safety Engineer
    $80K — $95K *
    Liverpool, NY 13090 (Onondaga County)
    Aerospace & Defense
    In-Person
  • Contract Specialist III
    $88K — $105K *
    Houston, TX 77084 (Harris County)
    Energy & Utilities
    In-Person

More Information Technology Jobs

Find similar System Administrator 3 jobs: