Senior Systems Infrastructure Engineer & Architect (Enterprise M

Virginia Tech Applied Research Corporation
Arlington, VA, United States
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$200,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Amazon Web Services Proxy Servers Systems Engineering Audit Trail User Authentication Microsoft Azure Backup Devices Bash Shell Cloud Computing Cloud Engineering
+70 more
Cluster Analysis Configuration Management Cyber Security Dynamic Host Configuration Protocol Linux Domain Name System (DNS) VMware ESX Servers Network Interface Controllers Monitoring of Systems HTTP Secure Hyper-V Identity and Access Management IP Addressing Subnetting Virtual Private Networks (VPN) Python (Programming Language) Key Management Kernel-Based Virtual Machine Lightweight Directory Access Protocols (LDAP) Linux Servers Log Analysis Microsoft Software System Center Configuration Manager Windows Servers Network Connections Routing Network Segmentation Packet Analyzer Network Time Protocols OpenShift Performance Tuning Public Key Infrastructure Windows PowerShell Red Hat Enterprise Linux Remote Administration Ansible Runbook Security Information and Event Management Systems Architecture Systems Integration Virtual Local Area Networks Virtual Machines Virtualization Technology VMware VSphere Software Vulnerability Management Wide Area Networks Data Logging Enterprise Software Applications Load Balancing System Availability Firewalls (Computer Science) Gitlab Build Management Integration Tests Kubernetes Infrastructure Automation Frameworks Storage Technologies Deployment Automation Vcenter Patch Management Microsoft Sentinel Nutanix Firewall Services Module Terraform Splunk Devsecops Wsus Qualys Docker Vulnerability Analysis

Job description

VT-ARC is seeking a Senior Systems Infrastructure Engineer & Architect (Enterprise Mission Systems SME) to support enterprise systems engineering, secure infrastructure modernization, classified enclave implementation, and operational transition for mission-critical enterprise communications, network modernization, and cyber programs within TS/SCI environments.

This role is focused on systems infrastructure engineering across the full implementation lifecycle, from requirements interpretation and architecture input through detailed design, build, integration, hardening, automation, validation, documentation, and transition to operations.

The selected candidate will design, implement, and sustain secure enterprise systems capabilities across Windows, Linux, virtualization, directory services, DNS/DHCP/NTP, PKI/certificates, storage, backup and recovery, monitoring, patching, configuration management, and automation. The role will also coordinate closely with network and cyber teams to ensure systems are connected, secured, monitored, scanned, accredited, and operationally supportable., * Design, implement, integrate, maintain, and modernize secure enterprise systems infrastructure supporting classified, sensitive, multi-enclave, lab, test, and mission operating environments.

  • Engineer Windows and Linux server environments, virtualization platforms, storage services, backup and recovery capabilities, monitoring tools, management services, and infrastructure automation capabilities.
  • Implement and sustain core infrastructure services such as Active Directory/LDAP, Group Policy, DNS, DHCP, NTP, PKI/certificates, file services, authentication services, administrative access, and enterprise management services.
  • Build and maintain virtualization and compute environments, including host configuration, virtual machine templates, golden images, resource allocation, clustering, high availability, capacity planning, performance tuning, and lifecycle management.
  • Develop scripts and automation using PowerShell, Bash, Python, Ansible, Terraform, or similar tools to standardize provisioning, configuration, hardening, validation, reporting, remediation, and operational support workflows.
  • Apply security hardening, DISA STIGs, patch management, vulnerability remediation, configuration baselines, system health checks, access controls, audit logging, and continuous monitoring practices across server and infrastructure environments.
  • Coordinate network-dependent systems requirements, including IP addressing, VLANs and subnets, DNS records, firewall rules, ports and protocols, routing dependencies, load balancers, proxies, VPN or management access, and out-of-band or administrative paths.
  • Integrate systems infrastructure with cybersecurity platforms, including SIEM log forwarding, EDR/XDR agents, vulnerability scanning, asset inventory, configuration monitoring, identity services, and operational monitoring tools.
  • Support lab validation, proof-of-concept activities, infrastructure builds, migration events, integration testing, failover testing, cutovers, troubleshooting, operational acceptance testing, and transition to operations.
  • Troubleshoot complex issues across systems, virtualization, storage, identity, DNS, certificates, endpoint management, network connectivity, firewalls, performance, logging, and security tooling.
  • Develop system architecture diagrams, build guides, configuration records, interface control documentation, ports and protocols matrices, runbooks, test procedures, migration plans, cutover plans, and operational handoff materials.
  • Coordinate technical dependencies with systems engineering, network engineering, cybersecurity, identity, cloud, infrastructure, operations, vendors, integrators, and Government stakeholders.
  • Support RMF, ATO, STIG, security control implementation, continuous monitoring, asset management, vulnerability remediation, and compliance evidence activities as they relate to enterprise systems infrastructure.
  • Provide mentoring and technical guidance to engineers, administrators, and operations teams on secure systems design, infrastructure automation, operational supportability, and cross-domain troubleshooting.

Requirements

You are a senior systems infrastructure engineer, enterprise systems architect, or mission infrastructure engineer with deep hands-on experience designing, deploying, and sustaining secure server, virtualization, directory, storage, management, and monitoring capabilities in complex environments.

You understand that systems engineering in classified and mission environments does not stop at installing servers. You know how identity, DNS, certificates, patching, hardening, backups, monitoring, logs, vulnerability scanning, network segmentation, firewall rules, management paths, and operational handoff all come together to make infrastructure supportable.

You are comfortable working across Windows, Linux, virtualization, storage, core infrastructure services, automation, cyber tooling, and network dependencies. You can translate architecture intent into buildable designs, deployment plans, validated configurations, and sustainment documentation.

You bring enough networking depth to work effectively with WAN/LAN engineers and cyber teams on subnetting, routing dependencies, ports and protocols, load balancers, proxies, firewalls, enclave boundaries, and troubleshooting across the system/network/security boundary., * Senior-level experience as a systems engineer, infrastructure engineer, systems architect, mission infrastructure engineer, platform engineer, or equivalent role supporting classified, DoD, IC, federal, or high-assurance enterprise environments.

  • Strong hands-on experience designing, deploying, administering, and sustaining Windows Server and Linux infrastructure, including system build, configuration, hardening, patching, monitoring, troubleshooting, and lifecycle management.
  • Strong working knowledge of virtualization, compute, storage, backup and recovery, high availability, performance tuning, capacity planning, and enterprise infrastructure operations.
  • Experience with core infrastructure services such as Active Directory/LDAP, Group Policy, DNS, DHCP, NTP, PKI/certificates, authentication, administrative access, and enterprise management services.
  • High proficiency with scripting and automation using PowerShell, Bash, Python, Ansible, Terraform, or similar tools to automate provisioning, configuration, validation, patching, reporting, and operational support tasks.
  • Strong network-adjacent systems knowledge, including IP addressing, subnets, VLANs, routing dependencies, firewall rules, load balancers, proxies, ports and protocols, remote administration paths, and troubleshooting across system/network boundaries.
  • Experience implementing security hardening, DISA STIGs, patch management, vulnerability remediation, access controls, audit logging, endpoint protection, and continuous monitoring for enterprise systems.
  • Ability to coordinate technical dependencies across systems, network, cybersecurity, identity, cloud, infrastructure, operations, vendors, integrators, and mission stakeholders.
  • Experience supporting RMF, ATO, STIG, security control implementation, continuous monitoring, asset management, or equivalent cybersecurity compliance activities for systems infrastructure.
  • Ability to produce clear technical documentation, including architecture diagrams, build guides, configuration records, runbooks, implementation plans, ports and protocols matrices, test procedures, and operational handoff materials.
  • Candidates should bring senior systems engineering and infrastructure ownership experience; help desk-only, desktop support-only, or narrowly scoped administration experience is not sufficient for this role.

Desired Education, Certification, Skills, Capabilities:

  • Experience with VMware vSphere/vCenter/ESXi, Hyper-V, Nutanix, KVM, SAN/NAS platforms, enterprise backup tools, or similar virtualization, compute, and storage technologies.
  • Experience with Red Hat Enterprise Linux, Windows Server, Microsoft MECM/SCCM, WSUS, Red Hat Satellite, Ansible Automation Platform, Group Policy, DISA STIG automation, or equivalent enterprise management tooling.
  • Experience with cloud or hybrid infrastructure in DoD or federal environments, including AWS GovCloud, Azure Government, IL5/IL6 environments, cloud identity, cloud networking dependencies, or cloud-native management services.
  • Experience with container or platform environments such as Kubernetes, OpenShift, Docker, GitLab, artifact repositories, secrets management, or DevSecOps infrastructure.
  • Experience with PKI, certificate lifecycle management, identity federation, MFA, privileged access management, service accounts, secrets handling, or secure administrative access patterns.
  • Experience integrating systems infrastructure with cyber tools such as Splunk, Elastic, Microsoft Sentinel, EDR/XDR platforms, Tenable/ACAS, Qualys, Rapid7, asset inventory, or configuration compliance tools.
  • Experience supporting classified enclaves, multi-enclave environments, air-gapped networks, lab/test environments, mission partner connectivity, or secure infrastructure modernization programs.
  • Experience with packet capture, log analysis, certificate troubleshooting, DNS troubleshooting, system performance analysis, storage troubleshooting, backup/restore testing, failover testing, or operational acceptance testing.
  • Professional certifications such as Security+, CASP+/SecurityX, CISSP, RHCSA, RHCE, VCP, Microsoft, AWS, Azure, CCNA, CCNP, Linux+, Server+, ITIL, or equivalent systems, security, cloud, or network credentials.

Primary Work Location: Work is expected to be fully onsite in Arlington, VA. The selected candidate must be able to support in-person program, customer, and technical coordination activities as required.

Benefits & conditions

Security:

  • Must be a U.S. Citizen
  • Active Top Secret/SCI clearance is required

Competitive Salary: VT-ARC offers a competitive salary and benefits package designed to attract and retain senior technical talent supporting mission-critical programs.

Salary Range: $200,000$275,000 annually

Virginia Tech Applied Research Corporation: VT-ARC is a 501(c)(3), non-profit R&D organization affiliated with Virginia Polytechnic Institute and State University (Virginia Tech or VT). Our mission is to provide superior analytic and technology solutions across multiple domains by leveraging Virginia Techs multidisciplinary research and innovation ecosystem. With unique access to the broad and rich research enterprise found at Virginia Tech, VT-ARC forms multi-disciplinary teams to apply innovative solutions to the real-world problems that strain our social, political, industrial, and economic foundations.

About the company

VT-ARC, a technical services and applied research company, has built an organizational culture marked by four primary values: Teamwork, Integrity, Excellence, and Service. Integral to our success is our staffs enthusiasm for solving tough problems by working together in teams to get the job done. We foster a culture where every employees contribution is valued and performed with integrity while maintaining a fun work environment. VT-ARC strives for excellence in all that is done for our clients, and such achievement is recognized through service/merit awards. Moreover, we promote a sense of community larger than VT-ARC alone, where staff and institutional resources can be applied in service to our country.

We are proud to be the recipient of the Best Workplace in Defense Award by Emergent Magazine, an honor that recognizes companies with positive cultures that not only impact their people but also make a meaningful difference in the community.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

4:54 min

Implementing geographic salary tiers for compensation equity and fairness

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

Videos

See all

Related articles

See all