Type of Requisition:Regular
Clearance Level Must Currently Possess:None
Clearance Level Must Be Able to Obtain:None
Public Trust/Other Required:NACI (T1)
Job Family:IT Infrastructure and Operations
Job Qualifications:Skills:Oracle Solaris, Red Hat Enterprise Linux (RHEL), ServiceNow IT Service Management (ITSM), Shell Scripting
Certifications:None
Experience:5 + years of related experience
US Citizenship Required:No
Job Description:GDIT is seeking a
UNIX/Linux/Solaris Engineer to support NIH CIT's HSS program. You will keep mission-critical systems stable, secure, and performant across Solaris (Zones/LDOMs) and Red Hat Linux on VMware, while applying careful, responsible automation to reduce toil-modernizing only where it strengthens reliability, security, and customer outcomes.
Location: Hybrid (3 days/week onsite, Bethesda, MD)
Responsibilities:- Operate and administer Solaris and Red Hat estates: Solaris-administer Zones and Logical Domains (LDOMs); manage OS lifecycle, patching, and hardware (Oracle platforms such as T-series where applicable). Red Hat-administer RHEL systems virtualized on VMware (in partnership with the Windows/VMware team).
- Patching & change execution: Drive Solaris patching using Alternate Boot Environments (ABE)-build, patch, and reboot into ABEs on standard cycles (e.g., 3rd Friday for non-prod, 4th Friday for prod) with rapid rollback capability if needed.
- Adapt to Oracle's revised patch cadence (security bundles every ~6 weeks, with potential interim bundles) and plan out-of-band updates when required by vulnerability severity.
- Maintain Red Hat patching via Puppet, ensuring customer-managed servers also receive monthly OS updates.
- Automation & tool transitions: Lead the transition off Oracle Ops Center (EOL/waiver ends Dec 31) toward Ansible (preferred) or Puppet playbooks for Solaris patch automation; author playbooks/modules and operational runbooks for the new process.
- Support upgrade from Oracle OEM 13.5 to 24 AI and ensure monitoring/administration workflows remain reliable during and after the migration.
- Monitoring & security operations: Configure and consume SL1 monitoring for OS/hardware health (CPU/memory/filesystems) and notifications; coordinate with DCOB (operations management) for platform configuration as needed.
- Triage security alerts from Tenable scans and follow-on tickets in Tripwire (file integrity) and Splunk (log-based anomalies such as SSH attempts); enforce host-level firewalls and raise network blocks when needed.
- Implement account policies (e.g., password expiration changes) safely across environments; validate changes in non-prod first to avoid service impact.
- Service models & customer engagement: Solaris-own root and full OS/hardware administration; grant sudo for customer application operations. Red Hat-support both managed (GDIT administers OS; customers manage apps) and customer-managed servers (customers hold root; GDIT ensures OS patching and provides consulting on request).
- Incident response & governance: Use ServiceNow for change and incident management; adhere to CAB approvals and standard change windows; deliver post-incident RCA where applicable.
- Participate in XMatters on-call rotations (15-minute acknowledge; tiered escalation), coordinating with NOC bridge during enterprise events (e.g., DNS or network issues).
- Documentation & collaboration: Maintain SharePoint-hosted SOPs/runbooks (with screenshots) covering patch orchestration (ABE), rollback, automation playbooks, OEM upgrade steps, SL1 alerting, and security/vulnerability remediation workflows; align with weekly UNIX-security syncs and customer meetings.
Required Qualifications:- BS/BA or equivalent experience.
- 5+ years administering Oracle Solaris (Zones/LDOMs) and/or Red Hat Enterprise Linux at scale, including OS patching and change execution in regulated environments.
- Hands-on with ABE-based Solaris patching, rollback, and vendor bundle planning; experience adjusting to non-monthly patch cadences.
- Practical experience with Puppet and Ansible for UNIX automation (playbooks/modules), plus strong shell scripting (bash/ksh).
- Familiarity with VMware-hosted Linux operations and coordination with platform teams.
- Operational monitoring and security tooling: SL1, Tenable, Tripwire, Splunk; host-level firewall management and security policy enforcement (e.g., password lifecycles).
- Proven use of ServiceNow (CAB/change templates; incident/RCA) and on-call processes via XMatters.
- Strong documentation habits (SOPs/runbooks with screenshots) and collaborative posture with customers and cyber teams.
- Must be able to obtain and maintain a Public Trust.
Preferred Qualifications:- Designed Ansible-first automation to replace legacy tools (e.g., Oracle Ops Center) for Solaris patch management; integrated automation outputs with ServiceNow tasks/approvals.
- Experience upgrading Oracle OEM and validating monitoring/administration flows during cutover.
- Familiarity with CIS controls and practical hardening for UNIX/Linux (file integrity, SSH posture, logging, firewall).
- Capacity to coach customers on reliable application monitoring (SL1 hooks or customer tools like SiteScope) while keeping OS monitoring/alerting clean.
Clearance: Ability to obtain and maintain Public Trust (onsite fingerprinting required)
The likely salary range for this position is $127,500 - $172,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:40
Travel Required:Less than 10%
Telecommuting Options:Hybrid
Work Location:USA MD Bethesda
Additional Work Locations: