About this role
Join SAIC's team and play a pivotal role in defending North America. We are seeking an experienced Cyber Defense Specialist to streamline operations and lead advanced cybersecurity infrastructure defense for the critical North American Aerospace Defense Command and United States Northern Command (N-NC) Information Technology (IT) Enterprise Services (NITES) contract. In this role, you will be responsible for protecting and hardening critical enterprise identity services, domain environments, and server systems against advanced threats. You will play a vital role in analyzing Active Directory configurations, responding to Cyber Tasking Orders (CTAs/CTASKORDs), performing proactive threat hunting, and executing log analysis and vulnerability remediation.
While your primary focus is dedicated to advanced, security-centric tasks, you will maintain hands-on experience with Red Hat Enterprise Linux (RHEL) systems and Nutanix Hyper-Converged Infrastructure (HCI) to secure the host platforms of our cybersecurity tools. Additionally, you will augment and support the core System Administrator team during high-urgency surge patching or rapid configuration requirements, ensuring critical security objectives are met while maintaining infrastructure stability and optimization.
Responsibilities:
The selected candidate will be responsible for the following:
- Analyze, secure, and recommend hardening actions for Active Directory configurations, identity services, and enterprise domain environments to mitigate risks such as credential theft, lateral movement, and persistence.
- Track, coordinate, and execute rapid, intensive vulnerability remediation and patching efforts in response to Cyber Tasking Orders (CTAs/CTASKORDs), emerging zero-day threat mandates, and JFHQ-DODIN directives.
- Perform proactive threat hunting and forensic-level log analysis across specialized security infrastructure, host servers, and network devices to detect and neutralize advanced adversary tactics.
- Provide specialized security configuration, patching, and maintenance support for Red Hat Enterprise Linux (RHEL) servers and Nutanix Hyper-Converged Infrastructure (HCI) hosting cybersecurity tools.
- Augment the core System Administrator team during high-priority security surges, operational patching, or complex virtualization infrastructure configuration requirements.
- Conduct in-depth technical research on unfamiliar vulnerabilities, zero-day threat landscapes, and exploit techniques to proactively protect monitoring systems and core IT infrastructure from service outages.
- Implement strict DISA STIGs and apply kernel-level operating system hardening across diverse Windows and Linux server platforms.
Required Qualifications:
- Active TS/SCI security clearance.
- Certification required per DoDD 8140.03, Intermediate Level (e.g., Security+ CE, CySA+, GSEC, CND, or equivalent).
- BS or equivalent work experience in Cybersecurity, Information Technology, or a related field.
- 8+ years of overall IT administration or cybersecurity experience.
- 3+ years of practical experience maintaining, patching, and securing Red Hat Enterprise Linux (RHEL) operating systems and/or Nutanix virtualized environments.
- Flexible, independent, self-motivated, and punctual.
Desired Qualifications:
- Direct experience tracking, reporting, and responding to Cyber Tasking Orders (CTAs/CTASKORDs) and JFHQ-DODIN directives within a DoD environment.
- Deep knowledge of credential theft mitigation, preventing lateral movement, and eliminating persistent threats within Active Directory and domain environments.
- Relevant technical vendor certifications such as Red Hat Certified System Administrator (RHCSA) or Nutanix Certified Professional (NCP).
- Familiarity with the North American Aerospace Defense Command and United States Northern Command (N-NC) IT enterprise architecture.
- In-depth understanding of network security appliances, SIEM solutions, and enterprise monitoring tools (e.g., SolarWinds, Cisco ISE).
- Demonstrated hands-on experience in cyber defense tasks, including threat hunting, log analysis (SIEM), vulnerability remediation, and Active Directory/domain hardening.