Classified (CSfC) Systems Engineer SME

Nabout Leidos
United States
4 days ago
Apply on jobs.military.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$131,300.0 - $237,350.0
Working hours
Regular working hours

Tech stack

Systems Engineering Bash Shell Cyber Security System Configuration Key Management Windows Servers Windows PowerShell Red Hat Enterprise Linux Ansible Security Information and Event Management Syslog Information Technology
+3 more
Nutanix Splunk Vmware

Requirements

  • Bachelor’s degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of prior relevant experience or Masters with 10 - 13 years of prior relevant experience. May possess a Doctorate in technical domain. Specific experience, education and training may be considered in lieu of degree.\n
  • 12+ years of progressive systems engineering experience within DoD/DoW, federal, or defense contractor enterprise environments.\n
  • Active TS/SCI Clearance\n
  • Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).\n
  • Active Computing Environment certification, including one of: VMware VCP/VCAP, Nutanix NCP, Red Hat Certified Engineer (RHCE), Microsoft Certified: Windows Server Hybrid Administrator Associate\n
  • Direct experience drafting CSfC Key Management Plans (KMPs) and Continuous Monitoring Plans (CMPs) for NSA CSfC PMO approval.\n
  • Proficiency with PowerShell, Bash, and Ansible for automated STIG remediation, configuration drift detection, and certificate deployment\n
  • Advanced configuration of syslog daemons (Rsyslog, Syslog-ng) and forwarding architectures to enterprise SIEM platforms (e.g., Splunk, Elastic).\n, * Experience Designing, deploying, and maintaining IT infrastructures for DTRA or other DoW organizations\n

Benefits & conditions

The \nCommercial Solutions for Classified (CSfC) Systems Engineer SME will architect and maintain mission-critical Public Key Infrastructure (PKI) and Hardware Security Modules (HSMs), oversee VMware or Nutanix hyperconverged infrastructure (HCI) with vSAN, and implement resilient backup and disaster recovery frameworks. This role will also build and administer hardened Windows Server and Red Hat Enterprise Linux (RHEL) platforms, establish robust Syslog aggregation, and enforce rigorous DoW vulnerability patching and DISA STIG compliance to sustain full Authorization to Operate (ATO), and assist with automating gold-image provisioning via SCCM.\n \n \nClearance: Active TS/SCI Clearance at time of consideration.\n \n \nCore Responsibilities:\n \n \n

  • Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks.\n
  • Design, configure, and maintain multi-layered CSfC architectures in alignment with NSA Data-At-Rest (DAR) and Mobile Access (MA) Capability Packages.\n
  • Architect, deploy, maintain Certificate Authority (CA), Online Certificate Status Protocol (OCSP) responders, and hardware-backed key protection via Hardware Security Modules (HSMs) in accordance with CSfC Key Management Requirements.\n
  • Build, manage, and optimize virtualized compute and storage fabrics utilizing VMware vSphere / ESXi or Nutanix AHV with vSAN/distributed storage. Design resilient, air-gapped backup and disaster recovery (DR) pipelines.\n
  • Deploy, configure, and administer hardened Microsoft Windows Server (Active Directory, DNS, Group Policy) and Red Hat Enterprise Linux (RHEL) systems.\n
  • Establish centralized, tamper-resistant Syslog and audit logging infrastructure across all network and system devices, hypervisors, and operating systems to support continuous monitoring and SIEM ingestion.\n
  • Understanding of cross-domain systems and forwarding log data through it to a centralized SIEM\n
  • Build and maintain automated OS deployment and gold image pipelines using Microsoft Configuration Manager (MCM/SCCM) for CSfC End User Devices (EUD).\n
  • Apply and validate patching and STIGs across all virtual and physical infrastructure. Execute vulnerability scans, track IAVMs, and remediate findings to maintain Authorization to Operate (ATO).\n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · World Congress 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · World Congress 2024

Videos

See all

Related articles

See all