This position owns the build and the run - keeping the domain, endpoints, network, and infrastructure services operating, implementing changes, and maintaining the as-built record that the program's compliance work depends on. Emerald Technical Solutions is seeking a Systems and Network Engineer to support the sustainment and operation of a mission-critical, controlled development enclave supporting a new project at Aberdeen Proving Ground.
Numbers & Facts
Location
Maryland
Website
https://emeraldsolutions.tech
Description
Position Title: Systems and Network Engineer Position Type: Full-Time, On-Site Location: Aberdeen Proving Ground, MD Clearance Requirement: Top Secret (Active) Salary Range: $120,000 - $140,000 | Start Date: 10/01 tentative
Position Overview
Emerald Technical Solutions is seeking a Systems and Network Engineer to support the sustainment and operation of a mission-critical, controlled development enclave supporting a new project at Aberdeen Proving Ground. This position owns the build and the run - keeping the domain, endpoints, network, and infrastructure services operating, implementing changes, and maintaining the as-built record that the program's compliance work depends on. The Systems and Network Engineer will work on-site full time and may be called on to provide occasional direct support to the broader program as needed.
Key Responsibilities Identity and Directory Services
Operate the reactdev.com Active Directory domain, including domain controller health, replication, DNS, DHCP, and enclave time synchronization
Administer Group Policy, including domain account policy, domain controller hardening, workstation baseline, legal notice banner, and update policy objects
Maintain organizational unit structure, security groups, service accounts, and group managed service account rotation per the Personnel Roster and Access Model
Provision, modify, and disable user and privileged accounts in accordance with the access model and tiered administration boundaries
Operate the just-in-time elevation service granting developers time-boxed local administrator rights
Operate the two-tier internal public key infrastructure, including issuance, revocation, certificate revocation list publication, and offline root custody
Endpoint and Imaging
Maintain Windows 11 and Linux golden images, unattended installation answer files, and post-deployment configuration scripts
Operate the PXE and imaging pipeline, including boot services, image distribution, driver packs, and hostname assignment
Deploy, re-image, refresh, and decommission suite workstations, including full disk encryption enrollment and key escrow
Perform profile migration for users moving from local to domain accounts
Maintain the approved application baseline on endpoints and remove prohibited software
Network and Infrastructure
Configure and maintain the enclave firewall, access switching, and, once authorized, wireless infrastructure
Maintain VLAN segmentation, firewall rule base, port security, and network access control
Operate the controlled update path used by network security devices
Administer the virtualization platform, VM lifecycle, host hardening, and resource allocation
Complete migration of the domain controller and virtual machines from interim hardware to the production server platform
Design and implement secure remote access once authorized, including MFA, validated cryptography, and session logging
Sustainment
Operate backup and recovery, including scheduled restore testing
Operate in-enclave patch and content distribution services for Windows and Linux, including offline repository synchronization
Apply security patches and firmware updates on the agreed maintenance cadence; remediate assigned findings
Maintain equipment inventory, including serial numbers, hostnames, network addresses, and asset categorization
Keep build/discovery documentation, network diagrams, and configuration records current
Provide technical input to procurement specifications, bills of materials, and vendor quotes
Required Qualifications
Bachelor's degree in computer science, information technology, or a related field, or an equivalent combination of education and experience
Five years of hands-on systems and network engineering experience, including at least two years in a controlled or disconnected environment
Windows Server and Active Directory administration, including Group Policy authoring and PowerShell automation
Linux administration (RHEL or Ubuntu), including Active Directory integration through SSSD and realmd
Cisco IOS XE switching and Cisco firewall administration, including VLAN segmentation and rule base management
Virtualization platform administration and VM lifecycle management
DoD 8570/8140 IAT Level II certification, or ability to obtain within 90 days of start
Active Top Secret clearance, with ability to obtain and maintain facility access required for the program
Preferred Qualifications
Cisco CCNP Security or equivalent; Red Hat Certified Engineer or equivalent
Experience applying DISA Security Technical Implementation Guides (STIGs) and SCAP content
Experience with network installation imaging at scale (PXE, unattended installation, automated provisioning)
Public key infrastructure and smart card/PIV credential experience
Prior work inside a CMMC or NIST SP 800-171 assessed boundary
Benefits
Competitive salary and performance-based bonuses
Comprehensive health, dental, and vision insurance
401(k) with company match
Paid time off and federal holidays
Professional development and certification reimbursement
Long-term career growth within a growing SDVOSB defense contractor