$200,000–$275,000 Per Year
Acceptance Testing, Affirmative Action, Analysis Skills, Ansible, Application Programming Interface (API), Applications Security, Atlassian JIRA, Authentication, Automation, Bash Scripting, Cloud Computing, Communications Security (COMSEC), Computer Security, Configuration Management, Continuous Deployment/Delivery, Continuous Integration, Cross-Functional, DNS (Domain Name System), Data Management, Data Quality, Data Recovery, Digital Certificates, Documentation, Ecosystems, Endpoint Security, Equal Employment Opportunity (EEO), Federal Contracts, Field Mapping, Firewalls, Git, Government, High Availability, Identify Issues, Identity Data Management, Integrated Circuits (ICs), Internet Security, Jenkins, LDAP (Lightweight Directory Access Protocol), Linux Operating System, Maintain Compliance, Mentoring, Microsoft Active Directory, Microsoft Product Family, Microsoft Windows Operating System, Nessus, Network Architecture/Engineering, Nonprofit, On Site Support, Onboarding, Operational Support, Operations Processes, Organizational Culture, Organizational Skills, Performance Analysis, Performance Tuning/Optimization, Problem Solving Skills, Procedure Implementation, Proof of Concept, Public Key Infrastructure (PKI), Python Programming/Scripting Language, Quality Monitoring, Rehabilitation Act, Reliability Engineering, Reporting Dashboards, Research & Development (R&D), Resource Management, SSL-TLS (Secure Socket Layer - Transport Layer Security), Scripting (Scripting Languages), Security Architecture, Security Compliance, Security Information and Event Management (SIEM), Security Infrastructure, Security Monitoring, Sensitive Compartmented Information (SCI), ServiceNow, Software Patches, Splunk, Standard Operating Procedures (SOP), System Architecture, Systems Administration/Management, Systems Engineering, Team Player, Technical Leadership, Technical Research, Technical Writing, Telemetry, Test Automation, Testing, Top Secret Clearance, U.S. National Institute of Standards and Technology (NIST), United States Citizen, United States Department of Defense (DoD), Use Cases, Validation Documentation, Vulnerability Scanners, Web Infrastructure, Willing to Travel, Windows PowerShell
About Us:
VT-ARC, a technical services and applied research company, has built an organizational culture marked by four primary values: Teamwork, Integrity, Excellence, and Service. Integral to our success is our staff’s enthusiasm for solving tough problems by working together in teams to get the job done. We foster a culture where every employee’s contribution is valued and performed with integrity while maintaining a fun work environment. VT-ARC strives for excellence in all that is done for our clients, and such achievement is recognized through service/merit awards. Moreover, we promote a sense of community larger than VT-ARC alone, where staff and institutional resources can be applied in service to our country.
We are proud to be the recipient of the Best Workplace in Defense Award by Emergent Magazine, an honor that recognizes companies with positive cultures that not only impact their people but also make a meaningful difference in the community.
About You:
You are a senior cyber infrastructure engineer, security platform engineer, or cyber systems architect with hands-on experience building and sustaining the platforms that cybersecurity operations teams depend on. You know how to make SIEM, EDR/XDR, vulnerability scanning, log collection, telemetry, and security workflow platforms work in real enterprise environments.
You are not limited to policy, GRC, audit, or SOC alert triage. You bring the architect and systems administration depth needed to deploy tools, integrate data sources, tune performance, automate workflows, troubleshoot failures, and transition capabilities into reliable day-to-day operations.
You understand how cyber platforms connect to endpoints, servers, network devices, firewalls, identity systems, cloud services, vulnerability scanners, ticketing systems, CMDBs, and mission applications. You can work across cybersecurity, systems, network, identity, cloud, infrastructure, and operations teams to turn security requirements into operational capability.
You are comfortable serving as a senior technical focal point for cybersecurity infrastructure decisions, especially where security tools must be engineered, automated, accredited, monitored, and sustained in classified or sensitive environments.
Position Overview:
VT-ARC is seeking a Senior Cyber Infrastructure Engineer & Architect (Security Platforms SME) to support cybersecurity platform engineering, security infrastructure modernization, automation, and operationalization for mission-critical enterprise communications, network modernization, and secure infrastructure programs within TS/SCI environments.
This role is focused on hands-on security infrastructure engineering across the full implementation lifecycle, from requirements interpretation and architecture input through detailed design, deployment, integration, tuning, automation, validation, documentation, and transition to operations.
The selected candidate will help architect, deploy, integrate, and sustain security operations platforms such as SIEM, EDR/XDR, enterprise vulnerability scanning, security telemetry pipelines, log collection infrastructure, compliance and configuration monitoring, and API-driven security workflows. The role requires strong system administration instincts, scripting depth, and the ability to make complex security platforms operationally supportable.
Active Top Secret/SCI clearance is required.
VT-ARC offers a competitive signing bonus for qualified candidates.
Duties/Responsibilities:
- Architect, deploy, integrate, tune, maintain, and modernize core cybersecurity operations platforms, including SIEM, EDR/XDR, enterprise vulnerability scanning, log collection, telemetry, compliance monitoring, and related security infrastructure capabilities.
- Engineer security data flows across endpoints, servers, network devices, firewalls, identity systems, cloud services, mission applications, vulnerability scanners, management platforms, and operational support tools.
- Configure and maintain complex log ingestion pipelines, including data source onboarding, parser and field mapping support, normalization, enrichment, indexing, retention, storage sizing, source health monitoring, and data quality validation.
- Support SIEM and detection engineering teams by ensuring reliable data coverage, correlation readiness, dashboard support, alert quality, use-case enablement, and operational visibility across enterprise and mission environments.
- Support EDR/XDR deployment and sustainment activities, including sensor rollout, policy configuration, telemetry validation, exclusions, health monitoring, upgrade planning, and endpoint coverage reporting.
- Support enterprise vulnerability management infrastructure, including scanner placement, credentialed scanning, agent-based coverage, asset inventory alignment, scan policy configuration, results validation, remediation tracking support, and rescanning workflows.
- Develop scripts, API integrations, and automation in Python, PowerShell, Bash, or similar languages to automate platform administration, data source onboarding, reporting, enrichment, ticketing, remediation support, and repetitive operational tasks.
- Integrate cyber platforms with Active Directory/LDAP, PKI, identity and access management, endpoint management, CMDB, ticketing, SOAR, DevSecOps, monitoring, and enterprise management systems.
- Tune platform performance, storage utilization, retention policies, indexing, alert volume, job scheduling, resource allocation, high availability, backup, recovery, and monitoring to support mission-scale operations.
- Coordinate technical dependencies with cybersecurity, systems engineering, network engineering, cloud, identity, infrastructure, COMSEC, operations, vendors, integrators, and Government stakeholders.
- Support lab validation, proof-of-concept activities, integration events, operational testing, troubleshooting, deployment planning, cutovers, and transition to operations.
- Develop architecture diagrams, data flow diagrams, port/protocol matrices, integration plans, implementation guides, SOPs, runbooks, configuration records, test procedures, and operational handoff documentation.
- Support RMF, ATO, STIG, continuous monitoring, security control implementation, vulnerability remediation, and compliance evidence activities as they relate to cybersecurity infrastructure platforms.
- Mentor technical staff on security platform administration, automation practices, logging architecture, operational sustainment, troubleshooting, and secure infrastructure implementation.
Required Education, Certification, Skills, Capabilities:
- Senior-level experience as a cyber infrastructure engineer, security platform engineer, cyber systems architect, cyber systems administrator, security tools engineer, or equivalent role supporting classified, DoD, IC, federal, or high-assurance enterprise environments.
- Proven hands-on experience architecting, deploying, integrating, and continuously maintaining core cybersecurity operations platforms, such as SIEM, EDR/XDR, enterprise vulnerability scanning, log collection, telemetry, or compliance monitoring systems.
- High proficiency in scripting and automation using Python, PowerShell, Bash, or similar languages to automate routine operational tasks, build API integrations, orchestrate security workflows, and improve platform reliability.
- Demonstrated ability to configure complex log ingestion pipelines, tune system performance, manage data source onboarding, validate telemetry, monitor source health, and troubleshoot data quality or platform availability issues.
- Strong working knowledge of Windows, Linux, Active Directory/LDAP, DNS, PKI/certificates, TLS, endpoint management, authentication, ports/protocols, firewalls, proxies, and enterprise management services as they relate to cybersecurity platform integration.
- Experience operationalizing security platforms, including monitoring, health checks, patching/upgrades, role-based access, high availability, backup and recovery, configuration management, runbooks, and transition to operations.
- Ability to coordinate technical dependencies across cybersecurity, systems, network, cloud, identity, infrastructure, operations, vendors, integrators, and mission stakeholders.
- Experience supporting vulnerability management, endpoint security, security telemetry, continuous monitoring, RMF, ATO, STIG, NIST, or equivalent cybersecurity requirements for enterprise infrastructure.
- Ability to produce clear technical documentation, including architecture diagrams, data flow diagrams, implementation guides, standard operating procedures, automation documentation, test procedures, and operational support materials.
- Candidates should bring hands-on platform engineering and administration depth; GRC-only, audit-only, or SOC alert-triage experience without engineering ownership is not sufficient for this role.
Desired Education, Certification, Skills, Capabilities:
- Experience with SIEM or security analytics platforms such as Splunk Enterprise/Splunk ES, Elastic, Microsoft Sentinel, QRadar, ArcSight, or equivalent technologies.
- Experience with log pipeline, data routing, or telemetry platforms such as Cribl, Logstash, Kafka, Fluent Bit, syslog-ng, or equivalent tools.
- Experience with EDR/XDR, endpoint security, or endpoint management platforms such as Microsoft Defender, CrowdStrike, SentinelOne, Trellix, Tanium, Carbon Black, or equivalent technologies.
- Experience with enterprise vulnerability scanning and exposure management platforms such as Tenable/ACAS, Nessus, SecurityCenter, Qualys, Rapid7, or equivalent technologies.
- Experience with SOAR, ticketing, CMDB, and workflow integration using platforms such as ServiceNow, Jira, Cortex XSOAR, Splunk SOAR, Phantom, or equivalent tools.
- Experience with automation, configuration management, or DevSecOps tools such as Ansible, Terraform, Git, GitLab, Jenkins, PowerShell DSC, or CI/CD pipelines.
- Experience supporting classified enclaves, air-gapped environments, cloud IL5/IL6, Zero Trust-aligned architectures, continuous diagnostics and mitigation, or high-assurance mission networks.
- Experience with packet capture, API troubleshooting, certificate troubleshooting, endpoint telemetry validation, agent deployment troubleshooting, or performance analysis across complex enterprise environments.
- Professional certifications such as Security+, CySA+, CASP+/SecurityX, CISSP, CISM, GCIH, GCIA, GCED, GDSA, GCFA, CCSP, Splunk, Elastic, Microsoft, AWS, Azure, Red Hat, VMware, or equivalent technical credentials.
Primary Work Location: Work is expected to be fully onsite in Arlington, VA. The selected candidate must be able to support in-person program, customer, and technical coordination activities as required.
Special Work Conditions: Travel may be required, up to 10%.
Security:
- Must be a U.S. Citizen
- Active Top Secret/SCI clearance is required
Competitive Salary: VT-ARC offers a competitive salary and benefits package designed to attract and retain senior technical talent supporting mission-critical programs.
Salary Range: $200,000–$275,000 annually
Virginia Tech Applied Research Corporation: VT-ARC is a 501(c)(3), non-profit R&D organization affiliated with Virginia Polytechnic Institute and State University (Virginia Tech or VT). Our mission is to provide superior analytic and technology solutions across multiple domains by leveraging Virginia Tech’s multidisciplinary research and innovation ecosystem. With unique access to the broad and rich research enterprise found at Virginia Tech, VT-ARC forms multi-disciplinary teams to apply innovative solutions to the real-world problems that strain our social, political, industrial, and economic foundations.
To learn more about VT-ARC’s Benefits, Perks, Culture & more visit our Careers page: https://vt-arc.org/careers/
Virginia Tech Applied Research Corporation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other status protected by law. As a federal contractor, we are committed to providing equal employment opportunity and affirmative action for qualified individuals with disabilities under Section 503 of the Rehabilitation Act of 1973. If you need a reasonable accommodation to complete the application or interview process, please contact Human Resources at hr@vt-arc.org
Virginia Tech Applied Research Corporation uses E-Verify to confirm the employment eligibility of all newly hired employees. To learn more about E-Verify, including your rights and responsibilities, please visit www.E-Verify.gov.