Network/Systems Engineer

Emerald Technical SolutionsMaryland, United StatesOn-siteFull-timeSenior, 5–8 yearsListed 1 week ago

Apply now

About this role

Position Title: Systems and Network Engineer
Position Type: Full-Time, On-Site
Location: Aberdeen Proving Ground, MD
Clearance Requirement: Top Secret (Active)
Salary Range: $120,000 - $140,000 | Start Date: 10/01 tentative

Position Overview

Emerald Technical Solutions is seeking a Systems and Network Engineer to support the sustainment and operation of a mission-critical, controlled development enclave supporting a new project at Aberdeen Proving Ground. This position owns the build and the run - keeping the domain, endpoints, network, and infrastructure services operating, implementing changes, and maintaining the as-built record that the program's compliance work depends on. The Systems and Network Engineer will work on-site full time and may be called on to provide occasional direct support to the broader program as needed.

Key Responsibilities
Identity and Directory Services

- Operate the reactdev.com Active Directory domain, including domain controller health, replication, DNS, DHCP, and enclave time synchronization

- Administer Group Policy, including domain account policy, domain controller hardening, workstation baseline, legal notice banner, and update policy objects

- Maintain organizational unit structure, security groups, service accounts, and group managed service account rotation per the Personnel Roster and Access Model

- Provision, modify, and disable user and privileged accounts in accordance with the access model and tiered administration boundaries

- Operate the just-in-time elevation service granting developers time-boxed local administrator rights

- Operate the two-tier internal public key infrastructure, including issuance, revocation, certificate revocation list publication, and offline root custody

Endpoint and Imaging

- Maintain Windows 11 and Linux golden images, unattended installation answer files, and post-deployment configuration scripts

- Operate the PXE and imaging pipeline, including boot services, image distribution, driver packs, and hostname assignment

- Deploy, re-image, refresh, and decommission suite workstations, including full disk encryption enrollment and key escrow

- Perform profile migration for users moving from local to domain accounts

- Maintain the approved application baseline on endpoints and remove prohibited software

Network and Infrastructure

- Configure and maintain the enclave firewall, access switching, and, once authorized, wireless infrastructure

- Maintain VLAN segmentation, firewall rule base, port security, and network access control

- Operate the controlled update path used by network security devices

- Administer the virtualization platform, VM lifecycle, host hardening, and resource allocation

- Complete migration of the domain controller and virtual machines from interim hardware to the production server platform

- Design and implement secure remote access once authorized, including MFA, validated cryptography, and session logging

Sustainment

- Operate backup and recovery, including scheduled restore testing

- Operate in-enclave patch and content distribution services for Windows and Linux, including offline repository synchronization

- Apply security patches and firmware updates on the agreed maintenance cadence; remediate assigned findings

- Maintain equipment inventory, including serial numbers, hostnames, network addresses, and asset categorization

- Keep build/discovery documentation, network diagrams, and configuration records current

- Provide technical input to procurement specifications, bills of materials, and vendor quotes

Required Qualifications

- Bachelor's degree in computer science, information technology, or a related field, or an equivalent combination of education and experience

- Five years of hands-on systems and network engineering experience, including at least two years in a controlled or disconnected environment

- Windows Server and Active Directory administration, including Group Policy authoring and PowerShell automation

- Linux administration (RHEL or Ubuntu), including Active Directory integration through SSSD and realmd

- Cisco IOS XE switching and Cisco firewall administration, including VLAN segmentation and rule base management

- Virtualization platform administration and VM lifecycle management

- DoD 8570/8140 IAT Level II certification, or ability to obtain within 90 days of start

- Active Top Secret clearance, with ability to obtain and maintain facility access required for the program

Preferred Qualifications

- Cisco CCNP Security or equivalent; Red Hat Certified Engineer or equivalent

- Experience applying DISA Security Technical Implementation Guides (STIGs) and SCAP content

- Experience with network installation imaging at scale (PXE, unattended installation, automated provisioning)

- Public key infrastructure and smart card/PIV credential experience

- Prior work inside a CMMC or NIST SP 800-171 assessed boundary

Benefits

- Competitive salary and performance-based bonuses

- Comprehensive health, dental, and vision insurance

- 401(k) with company match

- Paid time off and federal holidays

- Professional development and certification reimbursement

- Long-term career growth within a growing SDVOSB defense contractor

##