System Administrator 3

First Tek, Inc.

$88K — $105K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, Information Technology, Engineering, or related field preferred
  • 8 years of experience with Associate's or Bachelor's Degree in applicable field
  • 10 years of experience without a relevant degree
  • Minimum 2 years of experience with Windows Server Tools like Active Directory
  • Experience supporting Remote Access Administration

Responsibilities

  • Act as point of contact for access administration support
  • Support creation and maintenance of security groups in BPA domains
  • Provide Active Directory support for directory maintenance
  • Automate Identity and Access Management workflows
  • Deliver technical expertise to Help Desk on access-related issues
  • Administer IT systems software and configurations related to IAM
  • Assist with documenting and validating security compliance

Benefits

  • Routine telework eligibility after initial training period
  • On-call support in rotation every one to three weeks
  • Training on new technologies and skills related to the job
  • Potential opportunities for professional development
  • Ability to work with internal and external clients and vendors
Full Job Description


*** | SUPPLEMENTAL LABOR MANAGEMENT OFFICE

ADDITIONAL PROCUREMENT INFORMATION (API)

Title & Level

System Administrator 3

Work Group Location

Portland, OR

Specialty

Identity and Access Management

Offsite Work Eligibility*

Routine Telework Eligible

Organization

JNDI

Number of Days Onsite

2 days per week

Hours

Full-Time, up to 40 hours

Additional Information

Routine telework will be available after an initial training period and at the manager's discretion.

Overtime

5% anticipated

On-Call

Yes regular rotation one-to-three

Travel

N/A

FN Status

NOT open to Foreign Nationals

* Current telework, remote work and onsite support is based on BPA's business needs and is subject to change or termination at any time.

** Assignments with the "Remote" Designation must reside in WA, OR, ID or MT. Case-by-case exceptions may apply only when in the best interest of BPA.

OVERVIEW

Assignment

This full-time, contract Systems Administrator 3 assignment will provide high-level support to Converged Infrastructure (JNDI) organization within the IT department at *** (BPA). This assignment will serve on the Identity and Access Management (IAM) team supporting Access Control and Remote Access administration in a Windows server environment. Access Administration support is performed using a combination of Active Directory Users and Computers (ADUC), PowerShell scripts, and Windows Workflow management tools, following the Role Based Access Control (RBAC) model where accounts are placed into defined security groups, i.e., best practices for least privilege access. This System Administrator will also perform routine systems administration tasks (i.e., testing, configuring, migrating, upgrading, patching, enhancing, documenting, validating security compliance).

Organization

This System Administrator 3 assignment will work within the Converged Infrastructure (JNDI) organization within Data Center Services (JND) subgroup within the Infrastructure Services (JN) group in the Information Technology (J) business line of *** (BPA). The JNDI organization provides storage, compute, virtualization, virtual desktop, authentication and authorization services as a part of the greater JN infrastructure services group. JND also augments facilities support for the production data centers.

ASSIGNMENT RESPONSIBILITIES

Note: All official drafts, documents and recommendations, as listed below, must be reviewed, finalized and approved / accepted by appropriate BPA manager or other federal personnel with the authority to do so.

As directed by the BPA manager, act as the JNDI point of contact (POC) for access administration in support of the Help Desk ticketing and/or incident management requests for permissions to applications, files, and servers, via membership in security groups.

Support the creation, deletion, and maintenance of security groups and their related memberships in the BPA domains.

Support Microsoft Active Directory by verifying security groups with IO, ISO, and Delegates, converting security groups to new Role Based Access Control (RBAC) methods, and migrating security groups as requested.

Provide Microsoft Windows Active Directory support in the administration of directory maintenance and tasks.

Provide automations for Identity and Access Management workflows:

Collaborate and work with internal organizations to assist with assessing, identifying, documenting, and recommending automated Identity and Access Management (IAM) workflows.

Present or support presentation of possible automation for IAM workflows to appropriate BPA management.

Develop /draft documentation to support the BPA management-approved workflows and automation, capturing necessary workflow adjustments for all changes and enhancements.

Maintain and administer IT systems software, applications software, and all configurations, as they pertain to the IAM program.

This work includes tasks for system upgrades, patches, and enhancements and other changes.

Provide remote administration services which includes:

Remote Access (RSA) account creation, deletion, workflow processes and management, and connectivity issues.

RSA Authentication software testing, configuration, installation, implementation, and troubleshooting

Supporting load balanced RSA servers

Facilitating RSA security activities, reporting, and maintenance of RSA Authentication Tokens.

Support for YubiKey

Provide technical expertise to Help Desk regarding calls related to Identity Management, Remote Access, and Account Administration.

Resolve client service problems and disruptions related to access control problems.

As directed, collaborate with vendor technical resources to resolve issues not resolved by the (IAM) Support team.

Provide required documentation for all corrective actions and/or system changes.

Facilitate and participate in IT planning, analytical support, and coordination of technical resources.

Perform analysis of system capabilities:

Develop functional and system requirements.

Complete business process design and workflow.

Verify integration with other modules, system components, and other BPA applications.

Apply and maintain system security documentation and act as point of contact for the BPA Cyber and Physical Security organizations for issues related to Identity Management and Access Control security issues.

Validate IAM security requirements and implementation timelines.

Create requirements documentation; review with user representatives, recommend priorities and obtain user signoff.

Collaborate with internal users and stakeholders, coordinating interviews and joint requirements planning sessions.

Collaborate with Information System Owners (ISOs) to develop, create, edit, and define system alerts and monitoring requirements.

Provide system administration expertise for special projects, working with internal and external clients and vendors.

Confer with BPA workplace manager or Federal team lead on a routine basis for project status updates and/or any project issues.

Collaborate with BPA's IT Security Office to update, revise, and validate assigned systems compliance with all BPA security requirements.

Provide technical input and recommendations, as a non-voting participant, for potential acquisitions in area of expertise.

Provide systems administration support for any new systems added to BPA's IT infrastructure, assisting with testing, configuration, integration, and implementation efforts,

This work includes developing test plans, implementation schedule, scope, dependencies, documentation, and user training.

Collaborate with BPA's Legal Office to enact 'Litigation Hold' administrative actions.

Confer with BPA workplace manager on a routine basis for status updates and/or any issues or concerns.

Create, develop / draft, and recommend cross-training and functional documentation of subject matter for BPA audiences.

Conduct User training on an individual or group basis as requested.

Training is expected to be infrequent and limited to activities as defined in this API.

Participate in BPA process workshops, including project lessons learned, group improvement, and documentation efforts for procedures, processes, standards, guidelines, practices, and other technical and instructional material.

Mark documents and maintain filing system(s), files, emails, and records in accordance with compliance requirements. Share and disperse documents only to appropriate personnel (those with a Lawful Government Purpose (LGP) to know). Mark and maintain all official records in accordance with the Information Security (INFOSEC) and Information Governance & Lifecycle Management (IGLM) standards and procedures. Validate official records are accurately maintained for auditing purposes.

REQUIREMENTS

Education & Corresponding Experience (required on matrix)

Bachelor's Degree in Computer Science, Information Technology, Engineering, or a related technical field is preferred.

With an Associate's or Bachelor's Degree in applicable fields, 8 years of experience is required.

With an Associate's or Bachelor's Degree not in applicable fields or without a degree, 10 years of experience is required.

Applicable Certifications may count for 1 year of experience.

Experience must include direct work experience in Information Technology performing System Administration.

Required Technical Skills & Experience (required on matrix)

Minimum 2 years of experience with:

Windows Server Tools (such as Active Directory Users and Computers).

Microsoft Entra ID

System administration support for Remote Access Administration.

Assistance in analysis of system capabilities.

Facilitating and delivering system training.

Participating in enterprise information technology planning.

Preferred Skills & Experience (optional on matrix)

Demonstrated experience:

Working in a large production environment.

RSA Security Administration.

YubiKey.

Additional Requirements (not required on matrix)

Valid U.S. Driver's License is required.

Other Assignment Considerations

Provide on-call and backup support for existing systems and functions.

Location for on-call and backup support may be at BPA facilities or off-site.

Appendices

The following appendices apply to this assignment and may be downloaded from the Fieldglass Reference Library:

Offsite Work

Training Expectations (Worker is expected to keep current on the latest technologies and skills required for the assignment.)

Training Type

Details

Provided by

Attendance at all conferences, workshops, training, etc. must be pre-approved by SLMO. Requests will be reviewed on a case-by-case basis. Approval is subject to the most current guidance provided to SLMO by BPA or DOE and is subject to change at any time. SLMO reserves the right to negotiate attendance on billable/non-billable hours and reimbursement of travel costs with the supplier. Reimbursable travel costs must adhere to the Federal Travel Regulations and be submitted via an expense sheet in Fieldglass.

CLOSELY ASSOCIATED RESPONSIBILITIES & REQUIRED ASSOCIATED MITIGATION MEASURES

The following is a list of potential inherently governmental risk areas and the measures that SLMO-Compliance has determined must be in place, via processes and procedures, to mitigate the associated risks. The BPA manager's acceptance of the API or CWSD serves as their attestation that all applicable mitigation measures listed below are or will be established and adhered to in their organization.

Area of potential Closely Associated / Inherently Government function

Mitigation Measures

Access to Confidential / Sensitive Information

CFTE must sign NDA (Non-Disclosure Agreements) at beginning of assignments. (Does not apply to Craft assignments)

CFTE must complete annual Information Security and Privacy Awareness training.

CFTE must complete and pass background investigations of an appropriate level.

Acquisition Planning / Source Selection

CFTE are not permitted to serve as "voting" members for acquisition selections.

All purchasing decisions must be made by appropriate federal personnel (Contracting Officers).

All acquisition documents (requirements,
SOW's, evaluation criteria, etc.) must be reviewed, finalized and approved by appropriate BPA federal personnel.

Only Contracting Officers are authorized to obligate BPA funds.

Agency / Org Planning

All drafts, documents, materials and recommendations must be reviewed, finalized and approved by appropriate BPA federal personnel.

Budget / Finance Prep

Only Federal Employees may determine budget priorities & allocations.

BFTE must control and finalize / approve all budgets and related documentation, including that for projects, programs and Organizations.

Contract Management

All Contractual documents, including invoices must be finalized / approved by appropriate Federal personnel.

All contract-related decisions (modifications, changes, performance) must be determined by appropriate federal personnel (COs).

Decision Making

CFTE may provide input and recommendations to decision-makers.

Only appropriate federal personnel may make decisions which obligate BPA resources or to a specific course of action.

Direction & Control
(directing BFTE)

CFTE are not permitted to direct the actions of federal employees (BFTE) or have any control or input into their performance.

Work of BFTE must be assigned by federal manager, supervisor, Program / Resource manager or another appropriate designee.

Disposing Govt. Property

All decisions regarding the disposal of BPA property must be made by appropriate federal personnel; and all property dispositions must be directed and controlled by the Investment Recovery Center (IRC).

Dissemination of Agency/Policy Information / Training

All training and any information that is to be disseminated must be either 1) per established policy, process, procedure, or practice; or, 2) reviewed, finalized and approved by appropriate BPA federal personnel.

Inspection / IT Testing

Processes and procedures must ensure Federal personnel review inspection findings and CFTE recommendations before acceptance or rejection of material(s) / item(s).

HR Support

CFTE may assist with HR functions per established procedures, processes and guidelines (e.g., timekeeping).

All work products must be reviewed and finalized by appropriate federal employees.

Policy Development

BPA's process for Policy development includes multiple levels of federal review prior to acceptance / adoption.

Interpretation of Policy/Regulations

Only BPA federal employees may determine the applicability and interpretation of regulations.

CFTE are not permitted to "interpret" regulations for

Similar Jobs

More Jobs at First Tek, Inc.

  • Design Engineer
    $80K — $95K *
    Orlando, FL 32828 (Orange County)
    Aerospace & Defense
    In-Person
  • System Administrator 3
    $88K — $105K *
    Portland, OR 97229 (Washington County)
    Information Technology
    Hybrid
  • Safety Engineer
    $95K — $115K *
    Remote
    Aerospace & Defense
    Remote in Liverpool, NY
  • Safety Engineer
    $80K — $95K *
    Liverpool, NY 13090 (Onondaga County)
    Aerospace & Defense
    In-Person
  • Contract Specialist III
    $88K — $105K *
    Houston, TX 77084 (Harris County)
    Energy & Utilities
    In-Person

More Information Technology Jobs

Find similar System Administrator 3 jobs: