Linux Systems Administrator - Active TS/SCI Required!

Full Time
Suitland, MD 20746
Posted
Job description

Description

Job Description:

Are your ready for your next challenge?


We are in search for a Linux System Administrator - Active TS/SCI Required to work at our customer site at the National Maritime Intelligence Center, Suitland, MD.

In this role you will provide operations, engineering, and technical support services and associated supplies to support AWS resources, Red Hat Enterprise Linux servers, Splunk software, Python scripting language, REGEX parsing, and .xml presentation format development, architecture, administration, and RMF requirements and operations of the Hopper ISC CYBERDEP Security Information Event Management and NAVINTEL Enterprise Audit Capability (SIEM/NEAP).

THE MISSION

The Hopper Information Services Center (ISC) is an IT service provider for the Office of Naval Intelligence (ONI) and for 70+ Navy Intelligence Community (IC) ashore organizations across the globe with the mission to deploy and operate classified information systems, networks, communications systems, and cybersecurity capabilities.

Within Hopper ISC, the Cybersecurity Department (CYBRDEP) is comprised of four divisions (Defensive Cybersecurity Operations [N62], Cybersecurity Mission Operations [N63], Assessment & Validation [N64], and Cybersecurity Engineering [N66]), and these divisions collectively secure, protect, assess, and monitor fielded Information Technology (IT) capabilities against a full range of internal and external threats.

Security Information Event Management (SIEM) platforms support threat detection, compliance, and security incident management through the collection and analysis (both near real-time and historical) of security events, as well as a wide variety of other event and contextual data sources. The core capabilities are a broad scope of log event collection and management, the ability to analyze log events and other data across disparate sources, and operational capabilities (such as incident management, dashboards, and reporting). Enterprise Audit is an activity that “provides authorized personnel with the ability to review and examine any action that can potentially cause access to, generation of, or affect the release of classified or sensitive information.”

If this sounds like the kind of environment where you can thrive, keep reading!

THE CHALLENGE

  • Deploying, developing, maintaining, operating, administering, and supporting the technology capable of SIEM ingest and display as well as automating auditing in accordance with ICS-500-27 to identify, record, and report anomalous user activities that might be indicative of potential compromises of classified or sensitive information.

  • Act as the subject matter expert (SME) In a System Administration capacity and participate in meetings, working groups, system demonstrations, and conferences in support of the effort. Consider and present various alternatives for implementation including identification and prioritization of resource requirements, the cost for additional tools, timeframe for implementation, and risks.

  • Coordinate across IT domains and multiple teams (internal and external) and influence Hopper ISC regarding solution design, process and/or approaches to ensuring all SIEM and EAC systems are up-to-date, working efficiently and ensure all mission requirements are met.

  • Build, configure, implement, develop, and maintain the NAVINTEL Enterprise Audit Capability (EAC), which currently consists of Splunk Enterprise, Splunk Enterprise Security, and a Filtered Audit Data (FAD) Distribution Point (DP) to support both the transmitting and receiving of audit data to and from the EAC.

  • Perform upgrades, performance tuning, configuration management and on-going operations and maintenance of the EAC to ensure effectiveness, health, performance, security, scalability, and proper ingest of pertinent log information from all NAVINTEL endpoints.

  • Support in the Assessment and Authorization of the Enterprise Audit hardware and software.

  • Participate in meetings, working groups, system demonstrations, and conferences in support of the effort. This includes the monthly Intelligence Community Audit Subcommittee (ICAS) and meetings/correspondence with Program of Record stakeholders/system administrators to get their data ingested properly.

  • Make recommendations to resolve identified discrepancies, evaluating existing rule sets, and tuning, modifying, or developing existent/new search/dashboard/rule sets to achieve program objectives.

  • Build, configure, implement, develop, and maintain servers to support the EAC. This includes a number of distributed Splunk Search Heads, Indexers, Cluster Master, Forwarders, Heavy Forwarders, Licensing Server, Deployment Server, and ITS server.

  • Build, configure, implement, develop, and maintain all servers and related infrastructure within Amazon Web Services (AWS) by utilizing the AWS console. This includes a number of Elastic Compute Cloud (EC2s), Elastic Block Storage (EBS), Simple Storage Service buckets, etc. to include monitoring the AWS burn rate and advise the Government on configuration changes to ensure that the expenditure does not exceed the amount budgeted.

  • Develop and maintain project schedules and Plan of Actions and Milestones (POA&M) to support the system lifecycle activities in this effort and those, as required, for the NAVINTEL Information Assurance (IA) Program as a whole such as answers to security controls for RMF documentation.

MINIMUM QUALIFICATIONS

  • Active DoD TS/SCI clearance

  • Active CASP+CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP certification

  • An OS-specific (Linux) administration certification

  • BS and 8+ yrs of experience or 12+ yrs of systems administration experience

without a degree

  • 8+ years experience in the installation, implementation, configuration, testing (functional and security), operations, maintenance and patching of Red Hat Enterprise Linux (RHEL) .

  • 8+ years of experience in complex pattern matching with REGEX and writing and implementing scripts to automate tasks within Linux systems, Python preferred.

  • 5+ years AWS console experience, including creating AMI/EC2s; managing snapshots; cloning systems from snapshots; managing EBS, S3, and Glacier volumes; start/stop/restarting instances, etc.

  • 5+ years experience in architecture design, installation, configuration, testing (functional and security) and administration of Splunk Enterprise and Enterprise Security software, Add-Ons, Apps, and other components.

  • Experience in scripting the parsing and movement of log data to and from encoded .xml files to Splunk indexers utilizing REGEX functions and cron jobs.

  • Experience in continuous monitoring and the Risk Management Framework, creating documents for the RMF body of evidence such as System Security Plans, answers to security controls and POA&Ms, running SCAP scans, etc.)

  • Experience in the development of architecture diagrams utilizing diagramming software such as Microsoft Visio.

Salary to be determined by applicant’s education, experience, knowledge, skills and abilities, internal equity, market data, and contractual requirements.


HOPPER


Pay Range:

Pay Range $84,500.00 - $130,000.00 - $175,500.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

#Featuredjob

jjbodyshop.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, jjbodyshop.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, jjbodyshop.com is the ideal place to find your next job.

Intrested in this job?

Related Jobs

All Related Listed jobs