GBTI Solutions Inc

Network Administrator

GBTI Solutions Inc · Sånta Rita-Sumai Municipality, Guam, United States

Information Technology & Services · 11-50 employees

9 h ago
Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Network Administrator will design, manage, and secure complex industrial and building automation network infrastructure while ensuring deterministic performance and cybersecurity. Responsibilities include configuring industrial-grade hardware, managing network segmentation, and serving as the primary Tier III escalation point for network failures.

What they look for

Network Administration Industrial Control Systems SCADA Cybersecurity Network Segmentation Firewall Management Purdue Model DoD Cybersecurity Protocol Analysis Infrastructure Design Risk Management Framework Hardware Configuration Troubleshooting System Maintenance Technical Documentation

Requirements

Candidates must possess U.S. citizenship, an active Top Secret security clearance, and at least 5 years of advanced network administration experience with a focus on OT/ICS environments. Proficiency in DoD cybersecurity mandates and relevant professional certifications such as Security+ or CCNA are required.

Full description

Position Overview

Provide senior-level Network Administrator support for Facility-Related Control Systems (FRCS), Industrial Control Systems (ICS), and Building Management Systems (BMS)/Building Control Systems. Design, manage, secure, and maintain complex industrial and building automation network infrastructure supporting mission-critical physical and facility environments. Ensure deterministic performance, strict boundary defense, high availability, and cybersecurity while protecting physical safety and environmental stability. Work involves SCADA servers, PLCs, DDCs, HVAC, power distribution, and life-safety systems under a strict “safety-first,” OT-safe methodology (no standard IT actions that could disrupt physical equipment).

Key Responsibilities

  • Configure and maintain industrial-grade and ruggedized network hardware (e.g., Cisco Industrial Ethernet, Palo Alto, Data Diodes, Allen-Bradley Stratix, Ruggedcom, and enterprise switches adapted for OT) in mechanical rooms and harsh environments.
  • Manage resilient topologies (e.g., REP, DLR) for rapid failover and continuous deterministic traffic for time-sensitive control and environmental processes.
  • Maintain comprehensive backups of all industrial/building switch, router, and firewall configurations.
  • Implement strict network segmentation and micro-segmentation aligned with the Purdue Enterprise Reference Architecture (PERA).
  • Manage Ports, Protocols, and Services Management (PPSM) across the IT/OT boundary; allow only authorized industrial protocols (BACnet/IP, LonWorks, Modbus TCP, Fox, DNP3, CIP, etc.).
  • Configure and manage OT-specific Next-Generation Firewalls (NGFW) and Unidirectional Gateways (Data Diodes).
  • Apply network-specific STIGs using OT-safe testing in non-production environments to avoid physical equipment impacts.
  • Serve as primary Tier III escalation for severe network degradation, packet loss, or routing failures; perform root-cause analysis with industrial protocol analyzers (e.g., Wireshark).
  • Coordinate with facility/mechanical engineers, SCADA/BMS vendors, and IT cybersecurity teams.
  • Evaluate network capacity; recommend lifecycle replacements, bandwidth upgrades, and hardware specifications.
  • Author network SOPs and system baselines; support RMF for Platform IT (PIT) and FRCS (topology diagrams, HW/SW lists, PPSM, vulnerability scan support, POA&M).
  • Participate in MILCON/SRM project design reviews (35%/65%/95%/100%); evaluate contractor architectures, BOMs, and PPSM for compliance with Command OT standards, Purdue Model, and DoD cybersecurity requirements.
  • Provide SME oversight during integration, testing, commissioning, and CyCx coordination prior to government acceptance.
  • Produce required deliverables per the Performance Assessment Plan (network topology diagrams, PPSM/firewall audits, incident reports, performance analysis, configuration backup validation, RMF/STIG artifacts).

Mandatory Qualifications

  • U.S. Citizenship.
  • Active Top Secret security clearance.
  • Minimum 5 years advanced network administration experience, including at least 3 years focused on ICS, SCADA, BMS, FRCS, or IT/OT environments.
  • Deep expertise in OT network administration: strict segmentation, firewall rule development, industrial protocol routing (BACnet/IP, Modbus TCP, etc.), DoD cybersecurity mandates, NIST SP 800-82, OT-safe monitoring, and Purdue Model implementation while ensuring deterministic, highly available connectivity without disrupting critical facility or life-safety systems.
  • DoD Cyberspace Workforce (CWF) compliance per DoDM 8140.03: Work Role Code 441 – FRCS Network Administrator, Intermediate proficiency.

Required: At least one approved Intermediate certification (CEH, Cloud+, GCIH, GICSP, GSEC, Security+, SSCP) or higher/Advanced certification (SecurityX/CASP+, CCNA, CCNP Security, CCSP, GCED, GCIA, GCLD, GDSA, GFACT). Certifications must remain active; higher-level certs qualify for lower levels. Minimum 20 hours annual Continuous Professional Development (or certification maintenance requirement, whichever greater).

  • Fluent English (oral and written); ability to prepare reports, correspondence, and communicate effectively with government civilians, military personnel, and contractors.
  • Proficiency with Microsoft Office Suite (Word, Excel, PowerPoint, Outlook).
  • Physical capability for mechanical-room and facility environments: prolonged standing/walking on uneven surfaces, bending, crouching, stooping, reaching, climbing ladders, lifting/moving equipment up to 25 lbs, and sufficient vision to identify safety hazards.

Highly Desirable

  • Computing Environment certifications: Cisco CCNA/CCNP, Palo Alto PCNSA/PCNSE, Juniper JNCIA/JNCIS, or Cisco IMINS (Managing Industrial Networks with Cisco Networking Technologies).