Systems Architect SME
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+33 more
Job description
We are seeking a strategic Systems Architect SME to lead a highly technical team of systems, network, software and database engineers supporting the Defense Threat Reduction Agency’s (DTRA) Defense Stockpile Management System (DSMS) Enterprise. This program provides full lifecycle sustainment for a system supporting accountability and reporting for DTRA’s Nuclear Enterprise Directorate. In this role, you will serve as the program’s technical lead and senior advisor to Program Management, overseeing the reliability, security, and modernization of the DSMS enterprise infrastructure, including the DIAMONDS system of record, the JADE development environment, and the NIMACS application platform. You will serve as the critical bridge between technical execution and Government stakeholder requirements, guiding the enterprise modernization roadmap, including the ongoing JADE-to-Azure IL5 cloud migration, while ensuring seamless collaboration across all IT engineering disciplines in a highly secure, regulated environment governed by DoW Risk Management Framework and continuous Authority to Operate (ATO) requirements., * Serve as the Technical Lead for the program, providing senior technical advisory support to the Program Manager and Deputy Program Manager on architecture decisions, technical risk, resource trade-offs, and modernization priorities across all task areas.
- Represent the technical position of the program in Government management reviews, technical exchange meetings, and design review boards, and translate technical risk into terms Program Management can be used to inform cost, schedule, and staffing decisions.
- Direct, mentor, and empower a team of systems administrators and infrastructure engineers, driving operational excellence, workload prioritization, and technical skill development in support of a 99.7% monthly operational availability requirement across the DIAMONDS Enterprise and Central/Core virtual computing environments.
- Drive the architectural design and health of a complex environment, including but not limited to VMware vSphere (vSAN, vROPs, SRM, vRA, Horizon VDI), Windows core service servers, Red Hat Enterprise Linux, 3rd party applications, IIS, Tomcat Apache, and databases (Microsoft SQL Server, Oracle). Support the DIAMONDS, JADE, and DATS operating environments, including Dell EMC server hardware and Cisco network devices.
- Enforce strict security governance across the enterprise systems infrastructure. Ensure continuous compliance with DISA STIG security policies and implementation scheduling, manage the Plan of Action and Milestones (POA&M), update System Security Plan and Risk Management Framework (RMF) control documentation, manage PKI certificate servers, Active Directory, Group Policy, and oversee RSA user authentication servers.
- Support the planning, design, and fielding of Zero Trust architecture and Comply-to-Connect (C2C) requirements in accordance with mandated DoW policy deadlines.
- Break down silos by partnering closely with Network Engineering, Cybersecurity, Application Development, Database Administration, Field Support, and the DIAMONDS Support Center (DSC) to deliver cohesive, highly available services across all task areas.
- Support quarterly Disaster Recovery switchover testing, meeting a two-hour Recovery Time Objective (RTO) and Recovery Point Objective (RPO) and translate complex stakeholder requirements into actionable modernization strategies.
- Bridge the gap between legacy infrastructure constraints and future-state performance and security goals, including support for the migration of the JADE environment from on-premises infrastructure to the J6 IL5 Azure cloud.
- Develop and maintain DoD Architecture Framework (DoDAF) artifacts for all network, host, workstation, and database systems, and support formal Government design reviews with zero major rework.
- Support enterprise lifecycle management activities, including hardware and software refresh planning, end-of-life tracking, and cost estimation for full lifecycle refresh, ensuring 180-day advance alerts for all affected items.
Requirements
Bring your technology expertise and drive for innovation to GDIT. The Systems Architect SME must have proven work experience in these areas of IT expertise along with these current IT certifications:
- Skills: Enterprise Infrastructure Architecture, Virtualization Engineering (VMware vSphere), DoDAF Systems Design, RMF/Continuous ATO Compliance, Zero Trust Architecture
- Certifications: DoW 8140 IAT Level II required (e.g., Security+ CE or equivalent) at time of hire. VMware Certified Professional (VCP) preferred. CMMI-DEV/SVC Level 3 process familiarity preferred., * BA/BS degree or equivalent, and 15+ years of related work experience.
- Proven experience serving as a technical lead or chief architect advising program or senior management on technical strategy, risk, and resourcing decisions on a large, complex IT program, ideally within a Defense or Intelligence Community operational setting.
- Proven experience managing, leading, and mentoring technical teams (systems administrators, infrastructure engineers, or similar) in an enterprise environment.
- Deep technical expertise managing mixed operating system environments, specifically Red Hat Enterprise Linux (RHEL) and Windows Server, within a DISA STIG-compliant environment.
- Hands-on architectural experience with enterprise virtualization (VMware vSphere/vCenter) and physical server hardware management, including experience supporting high-availability (99%+ uptime) production environments.
- Strong foundational knowledge of Active Directory Domain Services (AD DS) and Microsoft Exchange.
- Working knowledge of Risk Management Framework (RMF), continuous monitoring principles (NIST SP 800-137), and POA&M management in a DoD accredited system environment.
- Exceptional interpersonal skills with a demonstrated ability to present technical roadmaps, risks, and solutions clearly to non-technical stakeholders and Government program leadership.
- Must currently possess a Top-Secret clearance and be able to obtain and maintain SCI eligibility. TS/SCI preferred.
- Must obtain and maintain DoD 8140 IAT Level II certification within the timeline required by contract policy. (e.g., Security+ CE or equivalent at time of hire.)
- Work location is Fort Belvoir, VA, with occasional CONUS travel in support of programming requirements. (Less than 10% travel). Not a remote role., * Extensive experience operating within Department of War (DoW) frameworks, with a deep understanding of DISA STIGs and zero-trust architecture principles, including hands-on experience implementing Comply-to-Connect (C2C) network access controls.
- Proficiency in designing and managing enterprise telemetry and vulnerability remediation using tools such as the SolarWinds product suite, Shavlik (Ivanti), and ACAS/Nessus scanning platforms.
- Strong understanding of how virtualized systems interact with the physical network fabric (vSwitches, VLAN routing, and firewall rule integration), including TACLANE KG175 and COMSEC-adjacent network segments.
- A track record of evaluating legacy processes and successfully implementing automation to reduce manual administration overhead, consistent with CMMI-DEV/SVC Maturity Level 3 process discipline.
- Experience supporting cloud migration efforts, particularly on-premises to Azure IL5 or similar DoW-accredited cloud environments.
- Familiarity with Appian-based or similar low-code enterprise application platforms in a sustainment context.
- VMware Certified Professional (VCP) preferred. CMMI-DEV/SVC Level 3 process familiarity preferred., Years of Experience
15 + years of related experience
- may vary based on technical training, certification(s), or degree Certification
| CompTIA Security+ CE | CompTIA - CompTIA |
| Capability Maturity Model Integration for Development (CMMI-DEV) | CMMI Institute - CMMI Institute |
VMware Certified Professional - Cloud (VCP-Cloud) | VMware - VMware Travel Required
Less than 10% Citizenship
Benefits & conditions
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
- Growth: AI-powered career tool that identifies career steps and learning opportunities
- Support: An internal mobility team focused on helping you achieve your career goals
- Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
- Community: Award-winning culture of innovation and a military-friendly workplace, The likely salary range for this position is $187,179 - $253,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
About the company
Own your opportunity to support our nation’s defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure., We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Is Software Engineering Over-Saturated?
Highest Paying Tech Companies for Developers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.