Systems Administrator (Linux & Windows)

Agile Defense•Fort Huachuca, AZ
•Onsite

About The Position

Seeking a versatile and mission-driven Systems Administrator (Linux & Windows) with dedicated experience as a Microsoft Endpoint Configuration Manager (MECM / SCCM) administrator. In this role, you will maintain, configure, and secure a heterogeneous enterprise hosting and laboratory testing environment comprising Red Hat Enterprise Linux (RHEL), modern Microsoft Windows Server (2019/2022), and Windows 10/11 endpoints. You will be responsible for end-to-end endpoint life cycle management, centralized patch orchestration, operating system deployments, system hardening, and continuous cyber-compliance. Working closely with cybersecurity leads and infrastructure engineers, you will ensure high system availability, rapid vulnerability remediation, and rigorous adherence to defense cybersecurity frameworks.

Requirements

  • Active DoD 8570/8140 IAT Level II Baseline Certification (e.g., CompTIA Security+ CE, CCNA Security, CySA+, GICSP, GSEC, or SSCP).
  • Relevant computing environment (CE) / vendor training or certification in Microsoft Windows Server/MECM or Red Hat Enterprise Linux (or ability to complete within 6 months of hire).
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related STEM discipline (equivalent relevant professional experience may be substituted in lieu of degree).
  • Minimum of 3–5+ years of hands-on systems administration experience across mixed Linux (RHEL) and Windows enterprise server/workstation environments.
  • Minimum of 2+ years of dedicated, hands-on administration of Microsoft Endpoint Configuration Manager (MECM / SCCM) in an enterprise or lab environment.
  • Demonstrable proficiency configuring, operating, and troubleshooting MECM/SCCM (OSD, application packaging, software update deployments, collection management).
  • Strong working knowledge of Linux administration, specifically Red Hat Enterprise Linux (RHEL), CLI troubleshooting, package management, daemon tuning, and SELinux enforcement.
  • Solid experience with Windows Server (2019/2022) administration, Active Directory, GPO authoring/troubleshooting, and DNS.
  • Experience with DoD vulnerability and compliance tooling: ACAS (Tenable/Nessus), SCAP Compliance Checker (SCC), and STIG Viewer (.ckl generation).
  • Understanding of enterprise backup technologies, bare-metal server recovery, and hypervisor virtualization (Nutanix AHV, VMware).
  • Excellent written communication skills for authoring Standard Operating Procedures (SOPs), weekly status reports, and technical troubleshooting documentation.

Nice To Haves

  • Prior experience administering systems within DoD enterprise testing facilities, operational lab environments, or defense staging enclaves.
  • Proficiency with PowerShell scripting and Linux Shell (Bash) scripting to automate routine administration, reporting, and deployment tasks.
  • Hands-on experience managing and troubleshooting enterprise backup appliances (e.g., Cohesity) and application whitelisting tools (e.g., fapolicyd).
  • Familiarity with Elastic Agent/Fleet management, LogRhythm, or enterprise SIEM architectures.
  • Basic understanding of perimeter network components (firewalls, VPNs, F5 BIG-IP load balancers) and cloud hosting environments (AWS GovCloud).

Responsibilities

  • Serve as the primary administrator for Microsoft Endpoint Configuration Manager (MECM / SCCM), managing infrastructure health, site systems, distribution points, and client agent health across all connected enclaves.
  • Engineer, test, deploy, and maintain standardized Windows Operating System Deployment (OSD) task sequences and baseline golden images.
  • Package, test, distribute, and automate application installations, scripts, and software updates across heterogeneous lab and hosting workstations and servers.
  • Manage and orchestrate enterprise-wide software update distribution using Software Update Points (SUP) integrated with Windows Server Update Services (WSUS).
  • Create and deploy custom compliance baselines and configuration items (CIs) to enforce security settings, STIG configurations, registry keys, and audit controls.
  • Develop custom MECM queries, device collections, and reports (SSRS) to provide real-time hardware/software inventory, asset discovery, and compliance auditing.
  • Administer, build, configure, and maintain physical and virtual Red Hat Enterprise Linux (RHEL) servers, modern Windows Servers (2019/2022), and Windows 10/11 workstations.
  • Manage core directory and identity infrastructure, including Active Directory Domain Services (AD DS), Group Policy Objects (GPOs), DNS, DHCP, and role-based access control.
  • Troubleshoot and maintain enterprise Linux services, including SE Linux policies/security contexts, daemon services (systemd, chronyd), file systems (/opt, logical volumes), and local package managers.
  • Maintain hypervisor and storage infrastructure, including Nutanix, VMware ESXi/vCenter, and enterprise backup/restore solutions (e.g., Cohesity, snapshots).
  • Support basic multi-tier database hosting and connectivity for Oracle and Microsoft SQL server backends.
  • Process, approve, and maintain user access documentation and account provisioning via DD Form 2875 and identity management systems.
  • Issue, configure, and troubleshoot Public Key Infrastructure (PKI) certificates, CAC authentication, and secure remote protocols across all client and server endpoints.
  • Maintain strict system security posture in compliance with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
  • Execute, review, and analyze weekly Assured Compliance Assessment Solution (ACAS / Tenable Nessus) vulnerability scans and monthly STIG evaluations.
  • Rapidly remediate identified CVEs, IAVM alerts, CTO/DTO directives, and vendor patches across both Windows and Linux fleets.
  • Draft, track, and update Plans of Action and Milestones (POA&Ms) for items requiring architectural mitigations or extended test schedules.
  • Maintain endpoint security agents across all hosts, including Trellix/ePO agents, endpoint detection and response (EDR), and application whitelisting tools (e.g., fapolicyd).
  • Monitor and analyze system, security, and application logs using SIEM and centralized log management tools (e.g., LogRhythm, Elastic Fleet).

Benefits

  • Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental.
  • Our culture is alive and evolving, but it always stays true to its roots.
  • Here, you are valued as a family member, and we believe that we can accomplish great things together.
  • Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
  • We call it the 6Hs, the values that define our culture and guide everything we do.
  • Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions.
  • It's how we show up every day.
  • It's who we are.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service