*** | SUPPLEMENTAL LABOR MANAGEMENT OFFICE
ADDITIONAL PROCUREMENT INFORMATION (API)
Title & Level
System Administrator 3
Work Group Location
Vancouver, WA
Specialty
N/A
Offsite Work Eligibility*
Situational Telework
Organization
JOV
Number of Days Onsite
5 days per Week
Hours
Full-Time, up to 40 hours
Additional Information
Enter additional info regarding the offsite work arrangement, if applicable.
Overtime
10% anticipated
On-Call
Yes May work non-core hours
Travel
Up to 10% local and field travel
FN Status
NOT open to Foreign Nationals
* Current telework, remote work and onsite support is based on BPA's business needs and is subject to change or termination at any time.
** Assignments with the "Remote" Designation must reside in WA, OR, ID or MT. Case-by-case exceptions may apply only when in the best interest of BPA.
OVERVIEW
Assignment
This contract System Administrator 3 position will work within Operational Infrastructure (JOV subgroup within Transmission Technology (J) group in the Transmission Services (J-OT) business line of *** (BPA). JOV provides hardware maintenance lifecycle support for the BPA's Control Center systems. JOV also provides General Support System (GSS) infrastructure maintenance, troubleshooting, repair, emergency response, client support, system energization/acceptance testing, and performance analysis and trending.
Organization
Operational Infrastructure provides 24 X 7 hardware maintenance lifecycle support for the BPA's Control Center systems. Functions performed include providing General Support System (GSS) infrastructure maintenance, troubleshooting, repair, emergency response, client support, system energization/acceptance testing, and performance analysis and trending. Responsibilities include supporting clients that use Control Center systems for both mission critical and business critical services. Operational Infrastructure provides agency expert level (Tier 3) support for the GSS infrastructure in the control centers. Services in these support systems include authentication and access, storage and virtualization, malicious code protection, dispatch and scheduling display infrastructure, operating system platforms, vulnerability detection, patch management, network security and configuration management, cabling infrastructure, facilities management systems, and critical area security. Included in these responsibilities are the documentation and compliance activities required to perform these functions.
ASSIGNMENT RESPONSIBILITIES
Note: All official drafts, documents and recommendations, as listed below, must be reviewed, finalized and approved / accepted by appropriate BPA manager or other federal personnel with the authority to do so.
With BPA Manager BPA technical lead oversight, use professional level skills/ knowledge to perform system administration of the following systems, including the following:
Configuring applicable software and systems, maintaining local documentation, installing/updating/removing software, applying change control processes and procedures, planning and preparing for future growth, trouble-shooting and resolving technical issues, and performing system-related training for the following systems:
Server administration
Vulnerability Scanning, including Nessus
Cyber Vulnerability Assessment and Mitigation Research
Implementation, design, and maintenance of least privileged and role based access control models
Patch Management of network and compute devices
Server Virtualization, i.e. Hyper-V, VMWare vSphere
Network Virtualization, i.e. VMWare NSX, Cisco ACI
Antivirus, antimalware, and malicious code prevention
Storage services, i.e. Nexgen, Pure, vSAN, other network-attached storage arrays
Display infrastructure
Laptop and workstation support
Software deployment services
Virtualization infrastructure
Windows & Linux operating systems
Windows infrastructure, i.e. active directory, group policy, PKI, et al
Support of in-house developed applications
Network time distribution
Windows file services
Linux infrastructure (deployment services, CentOS)
With BPA Manager oversight and approval provide the following support:
Research, test and draft / document standardized technical procedures for the deployment of server and workstation computer hardware and associated operating systems; organize, store and dispose of superseded documents in accordance with Information Governance & Lifecycle Management (IGLM) standards.
Perform regular assessments of newly discovered vulnerabilities on a wide range of operational network devices, computer systems devices and various software packages. Document patch and vulnerability applicability assessments and recommend vulnerability mitigation options. Report any concerns to the BPA manager.
Implement, design, and maintain least privileged and role based access control models.
Research, test and document standardized technical procedures for the deployment of server and workstation computer hardware and associated operating systems for final review and approval by BPA manager /staff.
Respond to help desk client support calls utilizing change management software to process and complete the tasks necessary for resolution of technical client issues; unusually complex issues may include involvement of the appropriate BPA manager or team lead.
Maintain files / filing system(s) in accordance with compliance requirements. File and disperse documents/letters as appropriate. Validate that all official records are accurately maintained for auditing purposes. Maintain file records in accordance with the Information Governance & Lifecycle Management (IGLM) standards and procedures.
Provide advice and recommendations for process / procedural changes that may become necessary due to system changes, upgrades, etc. to appropriate BPA manager / team lead / BPA stakeholders.
Provide input and recommendations, to the BPA manager, technical lead and staff, regarding computer infrastructure decisions and create tasks to fulfill management-directed goals.
Support and assist the BPA team lead and North American Electric Reliability Corporation - Critical Infrastructure Protection (NERC-CIP) subject matter experts (SMEs) with implementing, analyzing, and reporting on the operational compliance of all Control Center cyber assets.
Develop, draft and recommend improvements to the Control Center's procedures and processes for compliance with BPA and NERC-CIP standards and policies.
Develop, draft and recommend improvements to the Control Center's procedures and processes for BPA's Grid Modernization project, as well as other capital and expense projects.
Assist BPA management with the implementation and promotion of approved operational compliance process improvement efforts, specifically as relates to the administration of the above referenced systems.
REQUIREMENTS
Education & Corresponding Experience (required on matrix)
A degree in Computer Science, Information Technology, or a directly-related technical discipline is preferred.
With an Associate's or Bachelor's degree in applicable fields, 8 years of experience is required.
Without an applicable degree, 10 years of experience is required.
Experience must include direct work experience in Information Technology performing System Administration.
Experience includes a minimum combination of work-related experience, on-the-job training, and/or vocational training.
Required Technical Skills & Experience (required on matrix)
2 years' experience with the following:
Working knowledge and experience sufficient to successfully support and maintain a virtualized and converged compute environment.
Working knowledge and experience sufficient to successfully support, maintain, and troubleshoot enterprise Windows infrastructure using active directory, group policy, Powershell, and other Windows utilities.
Preferred Skills & Experience (optional on matrix)
Experience setting up and administering an enterprise cyber vulnerability scanning and assessment infrastructure.
Experience administering computer systems in a 24/7 high availability operational environment.
Administration and maintenance of network systems infrastructure management tools or systems including anti-virus, patch deployment, log management, software deployment and backup and recovery functions.
Experience administrating and performing and analyzing scans using Nessus.
Experience in researching vulnerabilities and deploying security patches in a large IT infrastructure environment.
Windows operating systems packaging, installation, and troubleshooting.
Administration of virtualization technologies including VMWare and Hyper-V.
Experience with administering both network and host based firewalls.
Experience troubleshooting LAN connectivity problems.
Experience using specific technologies such as Splunk, Remote Desktop Services, IIS, Wireshark, App-V, Tripwire, Trend Micro, LANDesk, Sysinternals Tools, Puppet Enterprises, Checkpoint Firewall, Veeam backup, Client and Cisco server hardware, KVM hardware, PowerShell.
Additional Requirements (not required on matrix)
Valid U.S. Driver's License is required.
Other Assignment Considerations
May be required to carry a BPA supplied cell phone and work non-core hours when requested. BPA-provided mobile devices are to be used solely for BPA purposes.
This position will be required to successfully complete NERC-CIP Control Center Training as a condition of this contract assignment.
Appendices
The following appendices apply to this assignment and may be downloaded from the Fieldglass Reference Library:
Offsite Work
Training Expectations (Worker is expected to keep current on the latest technologies and skills required for the assignment.)
Training Type
Details
Provided by
NERC-CIP Control Center training
Required
BPA
Attendance at all conferences, workshops, training, etc. must be pre-approved by SLMO. Requests will be reviewed on a case-by-case basis. Approval is subject to the most current guidance provided to SLMO by BPA or DOE and is subject to change at any time. SLMO reserves the right to negotiate attendance on billable/non-billable hours and reimbursement of travel costs with the supplier. Reimbursable travel costs must adhere to the Federal Travel Regulations and be submitted via an expense sheet in Fieldglass.