About The Position

VT-ARC is seeking a Senior Cyber Infrastructure Engineer & Architect (Security Platforms SME) to support cybersecurity platform engineering, security infrastructure modernization, automation, and operationalization for mission-critical enterprise communications, network modernization, and secure infrastructure programs within TS/SCI environments. This role is focused on hands-on security infrastructure engineering across the full implementation lifecycle, from requirements interpretation and architecture input through detailed design, deployment, integration, tuning, automation, validation, documentation, and transition to operations. The selected candidate will help architect, deploy, integrate, and sustain security operations platforms such as SIEM, EDR/XDR, enterprise vulnerability scanning, security telemetry pipelines, log collection infrastructure, compliance and configuration monitoring, and API-driven security workflows. The role requires strong system administration instincts, scripting depth, and the ability to make complex security platforms operationally supportable.

Requirements

  • Senior-level experience as a cyber infrastructure engineer, security platform engineer, cyber systems architect, cyber systems administrator, security tools engineer, or equivalent role supporting classified, DoD, IC, federal, or high-assurance enterprise environments.
  • Proven hands-on experience architecting, deploying, integrating, and continuously maintaining core cybersecurity operations platforms, such as SIEM, EDR/XDR, enterprise vulnerability scanning, log collection, telemetry, or compliance monitoring systems.
  • High proficiency in scripting and automation using Python, PowerShell, Bash, or similar languages to automate routine operational tasks, build API integrations, orchestrate security workflows, and improve platform reliability.
  • Demonstrated ability to configure complex log ingestion pipelines, tune system performance, manage data source onboarding, validate telemetry, monitor source health, and troubleshoot data quality or platform availability issues.
  • Strong working knowledge of Windows, Linux, Active Directory/LDAP, DNS, PKI/certificates, TLS, endpoint management, authentication, ports/protocols, firewalls, proxies, and enterprise management services as they relate to cybersecurity platform integration.
  • Experience operationalizing security platforms, including monitoring, health checks, patching/upgrades, role-based access, high availability, backup and recovery, configuration management, runbooks, and transition to operations.
  • Ability to coordinate technical dependencies across cybersecurity, systems, network, cloud, identity, infrastructure, operations, vendors, integrators, and mission stakeholders.
  • Experience supporting vulnerability management, endpoint security, security telemetry, continuous monitoring, RMF, ATO, STIG, NIST, or equivalent cybersecurity requirements for enterprise infrastructure.
  • Ability to produce clear technical documentation, including architecture diagrams, data flow diagrams, implementation guides, standard operating procedures, automation documentation, test procedures, and operational support materials.
  • Candidates should bring hands-on platform engineering and administration depth; GRC-only, audit-only, or SOC alert-triage experience without engineering ownership is not sufficient for this role.
  • Active Top Secret/SCI clearance is required.

Nice To Haves

  • Experience with SIEM or security analytics platforms such as Splunk Enterprise/Splunk ES, Elastic, Microsoft Sentinel, QRadar, ArcSight, or equivalent technologies.
  • Experience with log pipeline, data routing, or telemetry platforms such as Cribl, Logstash, Kafka, Fluent Bit, syslog-ng, or equivalent tools.
  • Experience with EDR/XDR, endpoint security, or endpoint management platforms such as Microsoft Defender, CrowdStrike, SentinelOne, Trellix, Tanium, Carbon Black, or equivalent technologies.
  • Experience with enterprise vulnerability scanning and exposure management platforms such as Tenable/ACAS, Nessus, SecurityCenter, Qualys, Rapid7, or equivalent technologies.
  • Experience with SOAR, ticketing, CMDB, and workflow integration using platforms such as ServiceNow, Jira, Cortex XSOAR, Splunk SOAR, Phantom, or equivalent tools.
  • Experience with automation, configuration management, or DevSecOps tools such as Ansible, Terraform, Git, GitLab, Jenkins, PowerShell DSC, or CI/CD pipelines.
  • Experience supporting classified enclaves, air-gapped environments, cloud IL5/IL6, Zero Trust-aligned architectures, continuous diagnostics and mitigation, or high-assurance mission networks.
  • Experience with packet capture, API troubleshooting, certificate troubleshooting, endpoint telemetry validation, agent deployment troubleshooting, or performance analysis across complex enterprise environments.
  • Professional certifications such as Security+, CySA+, CASP+/SecurityX, CISSP, CISM, GCIH, GCIA, GCED, GDSA, GCFA, CCSP, Splunk, Elastic, Microsoft, AWS, Azure, Red Hat, VMware, or equivalent technical credentials.

Responsibilities

  • Architect, deploy, integrate, tune, maintain, and modernize core cybersecurity operations platforms, including SIEM, EDR/XDR, enterprise vulnerability scanning, log collection, telemetry, compliance monitoring, and related security infrastructure capabilities.
  • Engineer security data flows across endpoints, servers, network devices, firewalls, identity systems, cloud services, mission applications, vulnerability scanners, management platforms, and operational support tools.
  • Configure and maintain complex log ingestion pipelines, including data source onboarding, parser and field mapping support, normalization, enrichment, indexing, retention, storage sizing, source health monitoring, and data quality validation.
  • Support SIEM and detection engineering teams by ensuring reliable data coverage, correlation readiness, dashboard support, alert quality, use-case enablement, and operational visibility across enterprise and mission environments.
  • Support EDR/XDR deployment and sustainment activities, including sensor rollout, policy configuration, telemetry validation, exclusions, health monitoring, upgrade planning, and endpoint coverage reporting.
  • Support enterprise vulnerability management infrastructure, including scanner placement, credentialed scanning, agent-based coverage, asset inventory alignment, scan policy configuration, results validation, remediation tracking support, and rescanning workflows.
  • Develop scripts, API integrations, and automation in Python, PowerShell, Bash, or similar languages to automate platform administration, data source onboarding, reporting, enrichment, ticketing, remediation support, and repetitive operational tasks.
  • Integrate cyber platforms with Active Directory/LDAP, PKI, identity and access management, endpoint management, CMDB, ticketing, SOAR, DevSecOps, monitoring, and enterprise management systems.
  • Tune platform performance, storage utilization, retention policies, indexing, alert volume, job scheduling, resource allocation, high availability, backup, recovery, and monitoring to support mission-scale operations.
  • Coordinate technical dependencies with cybersecurity, systems engineering, network engineering, cloud, identity, infrastructure, COMSEC, operations, vendors, integrators, and Government stakeholders.
  • Support lab validation, proof-of-concept activities, integration events, operational testing, troubleshooting, deployment planning, cutovers, and transition to operations.
  • Develop architecture diagrams, data flow diagrams, port/protocol matrices, integration plans, implementation guides, SOPs, runbooks, configuration records, test procedures, and operational handoff documentation.
  • Support RMF, ATO, STIG, continuous monitoring, security control implementation, vulnerability remediation, and compliance evidence activities as they relate to cybersecurity infrastructure platforms.
  • Mentor technical staff on security platform administration, automation practices, logging architecture, operational sustainment, troubleshooting, and secure infrastructure implementation.

Benefits

  • Competitive signing bonus for qualified candidates.
  • Competitive salary and benefits package designed to attract and retain senior technical talent supporting mission-critical programs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service