Job Requirements
Santa Rita, GU
Top Secret Polygraph Unspecified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Essential Duties and Responsibilities
Required Qualifications
Preferred Certifications
Relevant computing environment, networking, routing/switching, industrial networking, and firewall certifications are highly desirable, including:
Preferred Experience
Security clearance requirements
- Configure, administer, secure, and troubleshoot industrial and OT network infrastructure, including switches, routers, firewalls, Data Diodes, and related technologies.
- Design, maintain, and support resilient Layer 2 and Layer 3 network architectures for FRCS, ICS, SCADA, and BMS environments.
- Manag industrial network redundancy and resiliency technologies, including Resilient Ethernet Protocol (REP), Device Level Ring (DLR), and similar technologies supporting rapid failover and deterministic traffic flow.
- Implement and maintain network segmentation and micro-segmentation using the Purdue Enterprise Reference Architecture/Purdue Model.
- Configure and manage OT-specific Next-Generation Firewalls, access control lists, and Unidirectional Gateways/Data Diodes.
- Manage Ports, Protocols, and Services Management (PPSM) requirements across IT/OT boundaries.
- Support industrial and building automation protocols including BACnet/IP, LonWorks, Modbus TCP, DNP3, CIP, Fox Protocol, and related technologies.
- Apply and maintain network-specific Security Technical Implementation Guides (STIGs) using OT-safe methodologies that minimize the risk of disruption to physical equipment and facility operations.
- Serve as the Tier III escalation point for complex network outages, packet loss, routing failures, connectivity issues, and other network degradation affecting OT systems.
- Perform advanced packet and protocol analysis using tools such as Wireshark to identify and resolve network issues affecting physical machinery and facility control systems.
- Coordinate troubleshooting and remediation activities with facility engineers, mechanical engineers, SCADA/BMS vendors, cybersecurity personnel, and other technical stakeholders.
- Evaluate network capacity, performance, latency, jitter, bandwidth utilization, and equipment lifecycle requirements.
- Develop and maintain network topology diagrams, hardware/software inventories, system baselines, configuration documentation, and Standard Operating Procedures.
- Maintain comprehensive backups of industrial switches, routers, firewalls, and other critical network device configurations.
- Support DoD Risk Management Framework activities for Platform IT and FRCS environments, including development and maintenance of technical artifacts, PPSM documentation, topology diagrams, vulnerability scan information, system inventories, and POA&M support.
- Participate in Military Construction (MILCON), Sustainment, Restoration and Modernization (SRM), and facility modernization design reviews at applicable design phases.
- Review proposed network architectures, Bills of Materials, firewall requirements, and PPSM submissions for compliance with NAVFAC, DoD cybersecurity, and OT architecture requirements.
- Provide subject matter expertise during system integration, testing, cybersecurity commissioning, and commissioning of new control systems and building automation systems.
- Support incident root-cause analysis and develop corrective actions designed to prevent recurrence of OT network outages or service degradation.
- Maintain all network activities in accordance with applicable DoD, Department of the Navy, NAVFAC, cybersecurity, CUI, and information safeguarding requirements.
Required Qualifications
- U.S. citizenship is required.
- Minimum of five (5) years of advanced network administration experience.
- Minimum of three (3) years of experience specifically supporting ICS, SCADA, BMS, FRCS, or comparable IT/OT network environments.
- Demonstrated expertise in Operational Technology network administration, network segmentation, firewall rule development, routing, switching, and industrial network protocols.
- Demonstrated knowledge of the Purdue Model/Purdue Enterprise Reference Architecture and its application to secure IT/OT network segmentation.
- Experience supporting industrial protocols such as BACnet/IP, Modbus TCP, DNP3, CIP, or similar facility and industrial control protocols.
- Knowledge of DoD cybersecurity requirements and NIST SP 800-82 concepts applicable to Industrial Control Systems and Operational Technology.
- Ability to apply cybersecurity controls, monitoring, patching, and network configuration changes using OT-safe methodologies that avoid disruption to mission-critical facility systems.
- Experience troubleshooting complex Layer 2/Layer 3 networking, routing failures, packet loss, firewall issues, and connectivity problems.
- Experience with network and protocol analysis tools such as Wireshark.
- Ability to develop technical documentation, Standard Operating Procedures, network diagrams, reports, system baselines, and other engineering documentation.
- Strong oral and written English communication skills, including the ability to communicate technical information to Government personnel, engineers, cybersecurity professionals, vendors, and contract management.
- Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Outlook.
- Must satisfy the DoD Cyberspace Workforce foundational qualification requirements established under DoDM 8140.03 for Work Role Code (WRC) 441, FRCS Network Administrator, Intermediate proficiency level.
- Must possess and maintain at least one approved qualifying certification prior to onboarding. Intermediate-level qualifying certifications include CEH, Cloud+, GCIH, GICSP, GSEC, Security+, or SSCP. Approved higher-level certifications that automatically satisfy the requirement include SecurityX (CASP+), CCNA, CCNP Security, CCSP, GCED, GCIA, GCLD, GDSA, and GFACT.
- Must maintain required certifications in active and good standing and complete required Continuous Professional Development (CPD), including a minimum of 20 hours annually or the minimum required to maintain the applicable commercial certification, whichever is greater.
- Ability to work in mechanical and facility environments and lift or move equipment weighing up to 25 pounds.
Preferred Certifications
Relevant computing environment, networking, routing/switching, industrial networking, and firewall certifications are highly desirable, including:
- Cisco Certified Network Associate (CCNA)
- Cisco Certified Network Professional (CCNP)
- Cisco CCNP Security
- Palo Alto Networks Certified Network Security Administrator (PCNSA)
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- Juniper Networks Certified Associate (JNCIA)
- Juniper Networks Certified Specialist (JNCIS)
- Cisco Managing Industrial Networks with Cisco Networking Technologies (IMINS)
- Other current certifications relevant to industrial networking, OT cybersecurity, routing and switching, or enterprise firewall administration
Preferred Experience
- Experience supporting DoD, Department of the Navy, NAVFAC, or other Federal Government OT environments.
- Hands-on experience with FRCS, ICS, SCADA, BMS, HVAC controls, PLCs, DDCs, or related facility control systems.
- Experience with Cisco Industrial Ethernet, Allen-Bradley Stratix, Ruggedcom, Palo Alto firewalls, Data Diodes, or comparable OT networking technologies.
- Experience implementing Purdue Model segmentation, IT/OT boundary security, PPSM, firewall rules, and industrial network resiliency technologies.
- Experience supporting RMF, STIGs, vulnerability remediation, POA&M, and system authorization activities.
- Experience supporting MILCON, SRM, facility modernization, technical design reviews, integration, testing, or commissioning.
- Experience working in mission-critical OT environments where network changes must be carefully controlled to prevent disruption to physical or life-safety systems.
Security clearance requirements
- Must possess an active Tier 5 (T5) Top Secret security clearance or be able to obtain an interim T5 clearance prior to onboarding and the start of performance.
- The required security clearance must be maintained in active and good standing throughout the period of contract performance.
- Personnel must comply with all applicable DoD, Department of the Navy, NAVFAC, and site-specific information security and safeguarding requirements.
group id: 91142803