Systems Administrator/Configuration Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+23 more
Job description
The System Administrator / Configuration Manager sustains the availability, integrity, and security of the systems that support the Systems Team. This role owns day-to-day administration of servers, virtualized infrastructure, and networked services while serving as the authority for configuration and change management across the environment. The incumbent applies a cybersecurity lens to every configuration and change so that security is built in rather than bolted on, keeps baselines accurate and changes controlled and auditable, and owns the service-level and operational documentation that keeps the environment supportable. This is a hands-on, mid-level position that operates with periodic guidance and is expected to resolve most operational issues independently., System Administration
- Install, configure, patch, and maintain Windows and Linux (RHEL) servers, workstations, and virtualized infrastructure (VMware / Hyper-V), on premises and in accredited cloud enclaves.
- Administer core services - Active Directory, DNS, DHCP, group policy, file/print, backup and recovery - and monitor system health, capacity, and performance.
- Perform account provisioning, access control, and privileged-access management in accordance with least-privilege principles.
- Execute backup, restore, and disaster-recovery procedures; participate in continuity-of-operations testing.
Configuration & Change Management
- Establish, document, and maintain authoritative configuration baselines for hardware, software, and firmware across the system inventory.
- Serve as the team’s Configuration Manager: administer the change-control process, prepare and present change requests to the Configuration Control Board (CCB), and track approvals, implementation, and verification.
- Maintain the configuration management database (CMDB) / asset inventory and ensure version control, traceability, and audit readiness for all controlled items.
- Apply and document DISA Security Technical Implementation Guides (STIGs) and manage deviations, waivers, and Plans of Action & Milestones (POA&Ms).
Service Levels & Documentation
- Own and maintain service-level documentation - service catalog, standard operating procedures, runbooks, and as-built/system documentation - keeping it current, accurate, and audit-ready.
- Define, monitor, and report against service-level objectives (SLAs/OLAs) for availability, response, and patch/remediation timelines, and drive continuous improvement against them.
- Partner with the Technical Writing function to formalize operating and maintenance procedures and ensure documentation reflects the current configuration baseline.
Security & Compliance
- Apply a cybersecurity lens to every configuration and change - harden to secure baselines, assess the security impact of proposed changes before implementation, and enforce least-privilege, least-functionality, and defense-in-depth so security is designed in from the start.
- Support the Risk Management Framework (RMF) lifecycle by maintaining system documentation, hardening baselines, and evidence needed to sustain the Authorization to Operate (ATO).
- Remediate findings from ACAS/Nessus vulnerability scans and STIG assessments within required timelines.
- Coordinate with the Cybersecurity and Technical Writing functions to keep system security plans and operating procedures current.
Requirements
Clearance: Active DoD SECRET required; ability to obtain TOP SECRET/SCI preferred, * Bachelor’s degree in Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.
- 3-5 years of hands-on system administration experience, including at least 1 year performing configuration or change management in a controlled environment.
Certification (DoD 8140 / DCWF)
- CompTIA Security+ (CE) required at hire, or another certification qualifying for the assigned DCWF work role and Intermediate proficiency tier under DoDM 8140.03.
- A computing-environment (CE) certification relevant to the assigned platform (e.g., Microsoft, Red Hat, or VMware) required within the position’s qualification window.
Technical Skills
- Proficiency administering Windows Server and Active Directory, and enterprise Linux (RHEL/CentOS).
- Working knowledge of virtualization, networking fundamentals (TCP/IP, VLANs, firewalls), and scripting for automation (PowerShell and/or Bash).
- Practical experience applying DISA STIGs and interpreting vulnerability-scan results.
- Familiarity with a formal configuration/change-management process and supporting tooling (e.g., a CCB workflow, ticketing/ITSM, and version control), and with maintaining service-level documentation and reporting against SLAs., * Experience with eMASS and direct participation in an RMF authorization package.
- Exposure to Infrastructure-as-Code and configuration-management tooling (Ansible, Puppet, or Git-based workflows).
- ITIL Foundation certification or equivalent service-management background.
- Experience in an accredited cloud environment (AWS GovCloud or Azure Government).
Standards & Frameworks
- DoDM 8140.03 / DoD Cyber Workforce Framework (DCWF)
- NIST SP 800-37 (RMF)
- NIST SP 800-53 security controls
- DISA STIGs configuration-management best practices (e.g., ITIL / EIA-649).
Benefits & conditions
Pulled from the full job description
- 401(k)
- Health insurance
- Paid time off
- Vision insurance
- Dental insurance, * 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Everything a Developer Needs to Know About MCP with Neo4j
Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents