> Markdown version of [/jobs/ext/1973319-nmcc-systems-admin](https://www.wearedevelopers.com/jobs/ext/1973319-nmcc-systems-admin). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NMCC Systems Admin - **Company:** KaylaTek, Inc. - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $130,000.0 - $132,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Technology Operations, Sysadmin, Information Technology, Nessus, Plan of Action and Milestones - **Published:** August 7, 2026 - **Apply:** https://www.juju.com/job/00000000gm2r9a ## About the Role KaylaTek has an exciting Systems Admin opportunity supporting the AFNCR IT contract at the National Military Command Center. The primary responsibilities for the position are to support the Risk Management Framework (RMF) activities for the 844CS National Military Command Center (NMCC). The nature of the work requires that the candidate demonstrates initiative, organization, responsibility, customer service skills, and the ability to be flexible and adaptive to a fast-paced environment. The candidate must be able to communicate effectively and decisively with all levels of the organization and be able to solve practical problems as well as exercise sound judgement with regards to sensitive and confidential information The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), Office of the Secretary of Defense (OSD), Joint Chiefs of Staff, and other Air Force activities within the AFNCR, missions to include the Pentagon, Joint Base Andrews (JBA), Joint Base Anacostia-Bolling (JBAB), and other locations, leased spaces, and alternate sites. The major support areas required are: IT Operations and Maintenance; Plans, Projects, and Engineering (PP&E); and National Military Command Center (NMCC). The senior leaders and national defense missions that are supported require that the AFNCR operations never fail, resulting in a fast-paced, challenging, but also rewarding environment. Job Type: Full time - Core Hours are 0600 - 1800 Clearance required: Active TS/SCI/SCI eligible Certificate required: DOD 8140 Level II - Security + CE, + Bachelor Degree or equivalent work experience and certifications + Current DoD 8570baseline certification for IAT II(one of the following: GSEC, Security+, SCNPand SSCP certifications) + 8-10 years of Cyber Security experience + Familiarity with DoD STIG process. + Excellent verbal and written communication skills. + Familiarity with ACAS, eMASS and XACTASTIG Analysis Desired Skills: + Nessus + System Admin experience + Experience with CCRI scoring. + Security Control Knowledge and Self-Assessment Experience + Received an ATO for a system and has worked the system through the entire process. The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified. MUST BE A US CITIZEN The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified. ## Description + Run and review Evaluate STIG scan and manually validate STIG + Analyze vulnerability scans and STIG checklists results to determine critical vulnerabilities that are still open and need to be remediated. + Using Analysis results, work with the system owners and work centers to determine if open vulnerabilities can be closed, mitigated or if a POAM needs to be submitted to give the work centers time to work on remediation efforts + Consider and identify impacts as well as consideration of existing risk mitigation strategies and work with the system POC to either close the vulnerability or mitigate the vulnerability using known mitigation strategies. + Provide recommendations to system owners on remediation steps based on DoW and AF guidance and directives. + Validate system Hardware/Software list to ensure information aligns with assets for system. + Create and maintain Standard Operating Procedures (SOP) and Work Instructions (WI)Creation and tracking of Plans of Actions & Milestones (POA&Ms) for all System Impact Assessments through the lifecycle of the project. + Create Remedy tickets to track progress of STIG implementation. + Complete monthly application STIG status reporting and POA&M updates + Completed and validated STIG/SRG checklists for RMF, quarterly. + Strong verbaland written skills required providing management status reports and document system changes. + Analyze problems and provide focused solutions to effectively communicate information to various audiences verbally and through written communications. + Develops and maintains POAMs and supports remediation activities + Experience with continuous monitoring and Plans of Actions and Milestones (POA&Ms) ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre](https://www.wearedevelopers.com/videos/1793-fake-or-news-self-driving-cars-on-subscription-crypto-attacks-rising-and-working-while-you-sleep-theodore-lefevre) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)