System Administrator II

Alex-alternative Experts, Inc

Fort Meade (MD)

On-site

USD 150,000 - 165,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ALEX is seeking an experienced Linux-focused System Administrator (Level 2) to support a mission-critical program at Fort Meade, MD. This on-site role requires handling Linux infrastructure, security compliance, and RMF/NIST controls within an SCIF environment.

You will lead STIG implementation, SSP maintenance, and vulnerability remediation across virtualized and containerized platforms, including Docker/Podman, Kubernetes/OpenShift, and DoD PKI.

Qualifications

  • 5+ years of system administration in classified or secure DoD/IC environments.
  • Hands-on experience with RMF/SSP/A&A processes.
  • FIPS cryptography and DoD PKI management knowledge.
  • Experience with DISA STIGs and SCAP scanning.

Responsibilities

  • Administer, configure, harden, and maintain Linux server environments (RHEL/ Rocky/ CentOS).
  • Implement STIGs, manage patching, and remediate findings.
  • Support SSP maintenance, RMF activities, and risk assessments.
  • Manage STE/STN infrastructure and related cryptographic controls.
  • Operate containerized workloads and manage virtualization infrastructure.

Skills

Linux proficiency
DISA STIGs
RMF/ NIST controls
PKI/TLS/cryptography
Container platforms
Kubernetes/OpenShift
VMware vSphere / KVM
Scripting: Bash/Python
DoD/IC security compliance

Education

Bachelor’s degree in IT / CS / Cybersecurity

Tools

Docker
Podman
Kubernetes/OpenShift
VMware vSphere

Job description

Fort Meade, MD • Clearance Level: TS/SCI with FSP

Job Type: Full-time

ALEX is seeking an experienced Linux-focused System Administrator (Level 2) to support a mission-critical program within the Intelligence Community at Fort Meade, MD. This is an on-site position in a Sensitive Compartmented Information Facility (SCIF) environment. The successful candidate will be responsible for the day-to-day administration, security compliance, and operational health of complex Linux-based infrastructure spanning virtualized environments, container platforms, and classified networked systems.

The SA Level 2 operates with a high degree of independence and serves as a technical authority on Linux systems engineering, PKI/cryptographic policy enforcement, storage management, IP networking, and security compliance. This role carries significant responsibility for System Security Plan (SSP) maintenance, STIG implementation, and supporting Secure Telephone Equipment/Network (STE/STN) infrastructure within a heavily regulated RMF/NIST framework.

Key Responsibilities
  • Administer, configure, harden, and maintain Red Head Enterprise Linux (RHEL), Rocky Linux, and/or CentOS Stream server environments.
  • Apply and maintain DISA STIG configurations using OpenSCAP and other SCAP‑compliant tooling; remediate findings from automated scans.
  • Manage system performance tuning, patch management (yum/dnf), software package management, and OS lifecycle operations.
  • Configure and manage system services, daemons, scheduled tasks, logging (rsyslog/journald), and audit frameworks (auditd).
  • Provide Tier 1 and Tier 2 application support and general troubleshooting across all Linux-based systems.
Compliance – SSP, RMF, and STIG
  • Support ongoing System Security Plan (SSP) development, maintenance, and compliance activities in accordance with NIST SP 800‑53 Rev 5 controls.
  • Conduct and document Risk Management Framework (RMF) activities including control implementation statements, POAM tracking, and continuous monitoring.
  • Perform and respond to vulnerability assessments; coordinate CVE remediation and ensure timely patching.
  • Maintain system authorization boundaries, support activities, and coordinate with the ISSO/ISSM.
STE/STN Support
  • Install, configure, and maintain Secure Telephone Equipment (STE) and Secure Telephone Network (STN) infrastructure.
  • Coordinate STE/STN provisioning, moves, adds, and changes (MACs) with communications and security personnel.
  • Troubleshoot STE/STN connectivity and interoperability issues.
  • Maintain accurate inventory and documentation for all STE/STN endpoints.
PKI, TLS, and Cryptographic Management
  • Manage DoD PKI operations including certificate issuance, renewal, revocation, and trust store management.
  • Configure and maintain TLS/SSL for system services and applications.
  • Administer hardware security modules (HSMs) and software-based key management systems where deployed.
  • Apply and enforce system crypto policies to ensure FIPS compliance across all managed systems.
Containers and Cloud Environments
  • Deploy, operate, and maintain containerized workloads using Docker and/or Podman.
  • Administer Kubernetes or OpenShift container orchestration clusters within classified/air‑gapped environments.
  • Manage container image pipelines including base image hardening, vulnerability scanning, and approved image registries.
  • Support lifecycle management of containerized applications.
  • Administer VMware vSphere/vCenter environments including ESXi host management.
  • Manage KVM/QEMU-based virtual environments on Linux hosts.
  • Coordinate capacity planning and resource optimization across virtualized infrastructure.
Storage Management
  • Administer NAS and SAN systems; manage LUN provisioning, zoning, and multipath I/O.
  • Operate and maintain Ceph distributed storage clusters.
  • Configure and manage LVM, RAID arrays, and filesystem operations.
  • Implement and verify data‑at‑rest encryption requirements.
IP Networking and Firewall Management
  • Configure and manage host-based firewalls (firewalld, iptables/nftables) on Linux systems.
  • Troubleshoot TCP/IP networking issues including routing, DNS, DHCP, VLAN segmentation.
  • Interface with network engineers on firewall rule changes and ACLs.
Requirements
  • Deep hands‑on Linux proficiency across RHEL, Rocky Linux, and/or CentOS.
  • Demonstrated experience with DISA STIGs and SCAP compliance scanning.
  • Working knowledge of NIST SP 800‑53 controls and RMF process.
  • Experience with SSP development and A&A/ATO activities.
  • Hands‑on STE/STN installation, configuration, and support experience.
  • Solid understanding of PKI/TLS/cryptographic standards including DoD PKI and FIPS enforcement.
  • Strong IP networking fundamentals and host-based firewall management.
  • Experience with container platforms (Docker, Podman, Kubernetes, or OpenShift).
  • Experience with virtualization platforms (VMware vSphere, KVM/QEMU).
  • Storage management experience with NAS, SAN, LVM, and/or distributed storage.
Desired Skills
  • Experience with Ansible, Puppet, SaltStack, or Chef.
  • Proficiency in Bash and Python scripting.
  • OpenShift Container Platform experience in classified deployments.
  • Experience with cross-domain solutions (CDS).
  • Familiarity with DoD cloud environments (AWS GovCloud, C2S).
  • Red Hat RHCSA or RHCE certification.
Experience
  • 5+ years of system administration experience in classified or secure DoD/IC environments.
Certifications
  • DoD 8140 IAT Level II compliance (Security+, CASP+, or equivalent).
Education
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or related field. Equivalent experience may be substituted.

ALEX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, protected veteran status, or disability. Applicants must be able to perform the essential functions of the job.

In order to comply with the Equal Pay for Equal Work Act, we reasonably believe the pay range for this position is between $150k - $165k.

Reasonable accommodations will be made to allow employees to meet the essential functions of the job unless those accommodations cause undue hardships to the employer. To request a reasonable accommodation, contact the Human Resources Department at hr@alexinc.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Administrator (Clearance Required)
System Administrator (Clearance Required)

Kroll • Fort Meade (MD)

On-site
USD 100,000 - 150,000
Comprehensive healthcare coverage
401(k) with company matching
Generous PTO and leave policies
Systems Engineer III, Senior
Systems Engineer III, Senior

Alex-alternative Experts, Inc • Fort Meade (MD)

On-site
USD 185,000 - 200,000
Software Engineer II
Software Engineer II

Alex-alternative Experts, Inc • Fort Meade (MD)

On-site
USD 155,000 - 165,000
Software Engineer III
Software Engineer III

Alex-alternative Experts, Inc • Fort Meade (MD)

On-site
USD 190,000 - 205,000
Linux Systems Administrator
Linux Systems Administrator

Peraton • Silver Spring (MD)

On-site
USD 86,000 - 138,000
System Administrator - TS/SCI
System Administrator - TS/SCI

The Fountain Group • Washington

On-site
Sr. Linux Systems Administrator
Sr. Linux Systems Administrator

Astrion • Columbia (MD)

On-site
USD 145,000 - 165,000
On-Site Senior Linux Systems Admin II — Classified IC Infra
On-Site Senior Linux Systems Admin II — Classified IC Infra

Alex-alternative Experts, Inc • Fort Meade (MD)

On-site
USD 150,000 - 165,000
Linux Systems Administrator II
Linux Systems Administrator II

CACI International Inc • Fort Meade (MD)

On-site
USD 103,000 - 219,000
System Engineer (Clearance Required)
System Engineer (Clearance Required)

Kroll • Fort Meade (MD)

On-site
USD 100,000 - 150,000
Healthcare Coverage
Generous paid time off
401(k) plans with company matching