Systems Administrator/Configuration Manager
Role details
Job location
Tech stack
Job description
The System Administrator / Configuration Manager sustains the availability, integrity, and security of the systems that support the Systems Team. This role owns day-to-day administration of servers, virtualized infrastructure, and networked services while serving as the authority for configuration and change management across the environment. The incumbent applies a cybersecurity lens to every configuration and change so that security is built in rather than bolted on, keeps baselines accurate and changes controlled and auditable, and owns the service-level and operational documentation that keeps the environment supportable. This is a hands-on, mid-level position that operates with periodic guidance and is expected to resolve most operational issues independently., System Administration
- Install, configure, patch, and maintain Windows and Linux (RHEL) servers, workstations, and virtualized infrastructure (VMware / Hyper-V), on premises and in accredited cloud enclaves.
- Administer core services - Active Directory, DNS, DHCP, group policy, file/print, backup and recovery - and monitor system health, capacity, and performance.
- Perform account provisioning, access control, and privileged-access management in accordance with least-privilege principles.
- Execute backup, restore, and disaster-recovery procedures; participate in continuity-of-operations testing.
Configuration & Change Management
- Establish, document, and maintain authoritative configuration baselines for hardware, software, and firmware across the system inventory.
- Serve as the team's Configuration Manager: administer the change-control process, prepare and present change requests to the Configuration Control Board (CCB), and track approvals, implementation, and verification.
- Maintain the configuration management database (CMDB) / asset inventory and ensure version control, traceability, and audit readiness for all controlled items.
- Apply and document DISA Security Technical Implementation Guides (STIGs) and manage deviations, waivers, and Plans of Action & Milestones (POA&Ms).
Service Levels & Documentation
- Own and maintain service-level documentation - service catalog, standard operating procedures, runbooks, and as-built/system documentation - keeping it current, accurate, and audit-ready.
- Define, monitor, and report against service-level objectives (SLAs/OLAs) for availability, response, and patch/remediation timelines, and drive continuous improvement against them.
- Partner with the Technical Writing function to formalize operating and maintenance procedures and ensure documentation reflects the current configuration baseline.
Security & Compliance
- Apply a cybersecurity lens to every configuration and change - harden to secure baselines, assess the security impact of proposed changes before implementation, and enforce least-privilege, least-functionality, and defense-in-depth so security is designed in from the start.
- Support the Risk Management Framework (RMF) lifecycle by maintaining system documentation, hardening baselines, and evidence needed to sustain the Authorization to Operate (ATO).
- Remediate findings from ACAS/Nessus vulnerability scans and STIG assessments within required timelines.
- Coordinate with the Cybersecurity and Technical Writing functions to keep system security plans and operating procedures current.
Requirements
Clearance: Active DoD SECRET required; ability to obtain TOP SECRET/SCI preferred, * Bachelor's degree in Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.
- 3-5 years of hands-on system administration experience, including at least 1 year performing configuration or change management in a controlled environment.
Certification (DoD 8140 / DCWF)
- CompTIA Security+ (CE) required at hire, or another certification qualifying for the assigned DCWF work role and Intermediate proficiency tier under DoDM 8140.03.
- A computing-environment (CE) certification relevant to the assigned platform (e.g., Microsoft, Red Hat, or VMware) required within the position's qualification window.
Technical Skills
- Proficiency administering Windows Server and Active Directory, and enterprise Linux (RHEL/CentOS).
- Working knowledge of virtualization, networking fundamentals (TCP/IP, VLANs, firewalls), and scripting for automation (PowerShell and/or Bash).
- Practical experience applying DISA STIGs and interpreting vulnerability-scan results.
- Familiarity with a formal configuration/change-management process and supporting tooling (e.g., a CCB workflow, ticketing/ITSM, and version control), and with maintaining service-level documentation and reporting against SLAs., * Experience with eMASS and direct participation in an RMF authorization package.
- Exposure to Infrastructure-as-Code and configuration-management tooling (Ansible, Puppet, or Git-based workflows).
- ITIL Foundation certification or equivalent service-management background.
- Experience in an accredited cloud environment (AWS GovCloud or Azure Government).
Standards & Frameworks
- DoDM 8140.03 / DoD Cyber Workforce Framework (DCWF)
- NIST SP 800-37 (RMF)
- NIST SP 800-53 security controls
- DISA STIGs configuration-management best practices (e.g., ITIL / EIA-649).
Benefits & conditions
Pulled from the full job description
- 401(k)
- Health insurance
- Paid time off
- Vision insurance
- Dental insurance, * 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance