user avatar

Systems Engineer (SME)

TEKsystems c/o Allegis Group

Posted today

Job Requirements

Fort Belvoir, VA
Top Secret/SCI Polygraph not specified
Senior Level Career (10+ yrs experience)
$150,000 - $205,000

Job Description

TEKsystems is seeking an experienced Systems Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA). The Systems Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio.

Primary Responsibilities:

The Commercial Solutions for Classified (CSfC) Systems Engineer SME will architect and maintain mission-critical Public Key Infrastructure (PKI) and Hardware Security Modules (HSMs), oversee VMware or Nutanix hyperconverged infrastructure (HCI) with vSAN, and implement resilient backup and disaster recovery frameworks. This role will also build and administer hardened Windows Server and Red Hat Enterprise Linux (RHEL) platforms, establish robust Syslog aggregation, and enforce rigorous DoW vulnerability patching and DISA STIG compliance to sustain full Authorization to Operate (ATO), and assist with automating gold-image provisioning via SCCM.



Clearance: Active TS/SCI Clearance at time of consideration.



Core Responsibilities:

Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks.
Design, configure, and maintain multi-layered CSfC architectures in alignment with NSA Data-At-Rest (DAR) and Mobile Access (MA) Capability Packages.
Architect, deploy, maintain Certificate Authority (CA), Online Certificate Status Protocol (OCSP) responders, and hardware-backed key protection via Hardware Security Modules (HSMs) in accordance with CSfC Key Management Requirements.
Build, manage, and optimize virtualized compute and storage fabrics utilizing VMware vSphere / ESXi or Nutanix AHV with vSAN/distributed storage. Design resilient, air-gapped backup and disaster recovery (DR) pipelines.
Deploy, configure, and administer hardened Microsoft Windows Server (Active Directory, DNS, Group Policy) and Red Hat Enterprise Linux (RHEL) systems.
Establish centralized, tamper-resistant Syslog and audit logging infrastructure across all network and system devices, hypervisors, and operating systems to support continuous monitoring and SIEM ingestion.
Understanding of cross-domain systems and forwarding log data through it to a centralized SIEM
Build and maintain automated OS deployment and gold image pipelines using Microsoft Configuration Manager (MCM/SCCM) for CSfC End User Devices (EUD).
Apply and validate patching and STIGs across all virtual and physical infrastructure. Execute vulnerability scans, track IAVMs, and remediate findings to maintain Authorization to Operate (ATO).

Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of prior relevant experience or Masters with 10 – 13 years of prior relevant experience. May possess a Doctorate in technical domain. Specific experience, education and training may be considered in lieu of degree.

12+ years of progressive systems engineering experience within DoD/DoW, federal, or defense contractor enterprise environments.

Active TS/SCI Clearance

Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).

Active Computing Environment certification, including one of: VMware VCP/VCAP, Nutanix NCP, Red Hat Certified Engineer (RHCE), Microsoft Certified: Windows Server Hybrid Administrator Associate

Direct experience drafting CSfC Key Management Plans (KMPs) and Continuous Monitoring Plans (CMPs) for NSA CSfC PMO approval.

Proficiency with PowerShell, Bash, and Ansible for automated STIG remediation, configuration drift detection, and certificate deployment

Advanced configuration of syslog daemons (Rsyslog, Syslog-ng) and forwarding architectures to enterprise SIEM platforms (e.g., Splunk, Elastic).

Eligibility requirements apply to some benefits and may depend on your job
classification and length of employment. Benefits are subject to change and may be
subject to specific elections, plan, or program terms. If eligible, the benefits
available for this temporary role may include the following:

• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)
group id: 10105424
Find TEKsystems c/o Allegis Group on Social Media
Recruiters
user avatar
About Us
We’re partners in transformation. We help customers activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services and real-world application, we work with progressive leaders to drive change. That’s the power of true partnership. TEKsystems is an Allegis Group company.

TEKsystems c/o Allegis Group Jobs


Job Category
IT - Software
Clearance Level
Top Secret/SCI