Systems Administrator (Linux & Windows)
JOB SUMMARY
Seeking a versatile and mission-driven Systems Administrator (Linux & Windows) with dedicated experience as a Microsoft Endpoint Configuration Manager (MECM / SCCM) administrator. In this role, you will maintain, configure, and secure a heterogeneous enterprise hosting and laboratory testing environment comprising Red Hat Enterprise Linux (RHEL), modern Microsoft Windows Server (2019/2022), and Windows 10/11 endpoints.
You will be responsible for end-to-end endpoint life cycle management, centralized patch orchestration, operating system deployments, system hardening, and continuous cyber-compliance. Working closely with cybersecurity leads and infrastructure engineers, you will ensure high system availability, rapid vulnerability remediation, and rigorous adherence to defense cybersecurity frameworks.
JOB RESPONSIBILITIES
Endpoint Lifecycle Management & MECM/SCCM Administration
- Serve as the primary administrator for Microsoft Endpoint Configuration Manager (MECM / SCCM), managing infrastructure health, site systems, distribution points, and client agent health across all connected enclaves.
- Engineer, test, deploy, and maintain standardized Windows Operating System Deployment (OSD) task sequences and baseline golden images.
- Package, test, distribute, and automate application installations, scripts, and software updates across heterogeneous lab and hosting workstations and servers.
- Manage and orchestrate enterprise-wide software update distribution using Software Update Points (SUP) integrated with Windows Server Update Services (WSUS).
- Create and deploy custom compliance baselines and configuration items (CIs) to enforce security settings, STIG configurations, registry keys, and audit controls.
- Develop custom MECM queries, device collections, and reports (SSRS) to provide real-time hardware/software inventory, asset discovery, and compliance auditing.
Systems Administration (Linux & Windows)
- Administer, build, configure, and maintain physical and virtual Red Hat Enterprise Linux (RHEL) servers, modern Windows Servers (2019/2022), and Windows 10/11 workstations.
- Manage core directory and identity infrastructure, including Active Directory Domain Services (AD DS), Group Policy Objects (GPOs), DNS, DHCP, and role-based access control.
- Troubleshoot and maintain enterprise Linux services, including SE Linux policies/security contexts, daemon services (systemd, chronyd), file systems (/opt, logical volumes), and local package managers.
- Maintain hypervisor and storage infrastructure, including Nutanix, VMware ESXi/vCenter, and enterprise backup/restore solutions (e.g., Cohesity, snapshots).
- Support basic multi-tier database hosting and connectivity for Oracle and Microsoft SQL server backends.
- Process, approve, and maintain user access documentation and account provisioning via DD Form 2875 and identity management systems.
- Issue, configure, and troubleshoot Public Key Infrastructure (PKI) certificates, CAC authentication, and secure remote protocols across all client and server endpoints.
Cybersecurity, Vulnerability Management & Compliance
- Maintain strict system security posture in compliance with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
- Execute, review, and analyze weekly Assured Compliance Assessment Solution (ACAS / Tenable Nessus) vulnerability scans and monthly STIG evaluations.
- Rapidly remediate identified CVEs, IAVM alerts, CTO/DTO directives, and vendor patches across both Windows and Linux fleets.
- Draft, track, and update Plans of Action and Milestones (POA&Ms) for items requiring architectural mitigations or extended test schedules.
- Maintain endpoint security agents across all hosts, including Trellix/ePO agents, endpoint detection and response (EDR), and application whitelisting tools (e.g., fapolicyd).
- Monitor and analyze system, security, and application logs using SIEM and centralized log management tools (e.g., LogRhythm, Elastic Fleet).
QUALIFICATIONS & EDUCATION
Required Certifications
- Active DoD 8570/8140 IAT Level II Baseline Certification (e.g., CompTIA Security+ CE, CCNA Security, CySA+, GICSP, GSEC, or SSCP).
- Relevant computing environment (CE) / vendor training or certification in Microsoft Windows Server/MECM or Red Hat Enterprise Linux (or ability to complete within 6 months of hire).
Education
- Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related STEM discipline (equivalent relevant professional experience may be substituted in lieu of degree).
Years of Experience:
- Minimum of 3–5+ years of hands-on systems administration experience across mixed Linux (RHEL) and Windows enterprise server/workstation environments.
- Minimum of 2+ years of dedicated, hands-on administration of Microsoft Endpoint Configuration Manager (MECM / SCCM) in an enterprise or lab environment.
ADDITIONAL & PREFERRED SKILLS
- Demonstrable proficiency configuring, operating, and troubleshooting MECM/SCCM (OSD, application packaging, software update deployments, collection management).
- Strong working knowledge of Linux administration, specifically Red Hat Enterprise Linux (RHEL), CLI troubleshooting, package management, daemon tuning, and SELinux enforcement.
- Solid experience with Windows Server (2019/2022) administration, Active Directory, GPO authoring/troubleshooting, and DNS.
- Experience with DoD vulnerability and compliance tooling: ACAS (Tenable/Nessus), SCAP Compliance Checker (SCC), and STIG Viewer (.ckl generation).
- Understanding of enterprise backup technologies, bare-metal server recovery, and hypervisor virtualization (Nutanix AHV, VMware).
- Excellent written communication skills for authoring Standard Operating Procedures (SOPs), weekly status reports, and technical troubleshooting documentation.
Preferred Skills
- Prior experience administering systems within DoD enterprise testing facilities, operational lab environments, or defense staging enclaves.
- Proficiency with PowerShell scripting and Linux Shell (Bash) scripting to automate routine administration, reporting, and deployment tasks.
- Hands-on experience managing and troubleshooting enterprise backup appliances (e.g., Cohesity) and application whitelisting tools (e.g., fapolicyd).
- Familiarity with Elastic Agent/Fleet management, LogRhythm, or enterprise SIEM architectures.
- Basic understanding of perimeter network components (firewalls, VPNs, F5 BIG-IP load balancers) and cloud hosting environments (AWS GovCloud).
WORKING ENVIRONMENT
Strength Demands
- Light to Medium Work: Must be able to exert up to 30–50 pounds of force occasionally, and/or up to 20 pounds of force frequently to lift, carry, push, pull, or otherwise move rack-mounted hardware, server components, workstations, peripherals, and network cabling.
Physical Requirements
- Sitting or standing at computer workstations for extended periods.
- Dexterity of hands and fingers to operate computer keyboards, mice, test equipment, and hand tools (e.g., rack installation tools, screwdrivers).
- Stooping, kneeling, crouching, reaching, and bending required when installing or cabling servers, switches, or workstations in server racks and lab benches.
- Visual acuity to read fine print, computer monitors, wiring labels, and console screens for extended periods.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Skills
As published by lever · 22 questions · 5 written answers
Basics
Resume/CV, Full name, Email, Phone, Current location, Current company
Short answers (2)
- What is your full street address? (Street, City, State, Zip)
- What is your desired salary?
Pick from a list (14)
- Do you have a Department of Defense (DOD) Recognized Security Clearance?
- What level of DOD clearance do you have?
- Are you authorized to work in the United States?
- Will you now or in the future require sponsorship for employment visa status (e.g., H-1B visa status)?
- Are you open to relocating for this position, or another position with Agile Defense?
- Are you a current employee of Agile Defense or any of its subsidiaries, affiliates, or acquired companies?
- Have you ever been employed by Agile Defense or any of its subsidiaries, affiliates, or acquired companies?
- How did you hear about us?
- Do you have a higher education degree?
- What is your highest level of education?
- Do you have any active industry related certifications?
- Are you a current or former U.S. Government employee or U.S. armed forces?
- Are you currently subject to any post-employment obligations from a current or former employer that could restrict your ability to perform this role if hired?
- I certify that the information provided is accurate to the best of my knowledge and understand that additional details may be requested later in the hiring process.
Written answers (5)
- If you were referred, please list the referrer's name and any other details here: optional
- What active industry related certifications do you have?
- If yes, please briefly describe the type of obligation and its duration (you may exclude employer names and confidential terms). If no, please respond with "N/A".
- If hired, would you have any ongoing outside employment, consulting, or business activities that could conflict with this role or the company’s interests?
- If yes, please briefly describe. If no, please respond with "N/A".
Attachments (1)
- Please upload a copy of your certification(s) if applicable optional
