Senior Network Administrator
Omm IT Solutions · Sånta Rita-Sumai Municipality, Guam, United States
IT Services and IT Consulting · 11-50 employees
About the role
The Senior Network Administrator manages, designs, and secures ruggedized network hardware and resilient topologies within industrial and building automation environments. They also enforce strict cybersecurity boundaries, perform protocol analysis, and maintain RMF artifacts to ensure compliance with DoD standards.
What they look for
Requirements
Candidates must have at least 5 years of network administration experience, including 3 years specifically in OT/ICS environments, and hold an active Tier 5 Top Secret clearance. A relevant cybersecurity certification satisfying DoDM 8140.03 WRC 441 is mandatory for this role.
Full description
PLEASE NOTE:
- IT IS A 100 % onsite position
- Employment Type: Full-Time (Up to 40 hours/week, no overtime permitted)
- Clearance: Active Tier 5 (T5) Top Secret security clearance
- Must be a United States citizen.
- Transportation: Must possess a personal vehicle (POV) for commuting between local base sites in Guam (expenses/mileage are non-reimbursable)
POSITION OVERVIEW
The Senior Network Administrator provides specialized network administration, design, maintenance, and security
KEY RESPONSIBILITIES & ESSENTIAL SKILLS:
1.Network Engineering
- Configure, maintain, and manage ruggedized network hardware (e.g., Cisco Industrial Ethernet, Allen-Bradley Stratix, Ruggedcom, Palo Alto, Data Diodes, and enterprise hardware).
- Manage resilient network topologies (e.g., Resilient Ethernet Protocol [REP], Device Level Ring [DLR]) to ensure rapid failover and deterministic traffic flow for time-sensitive control processes.
- Maintain backup for all switch, router, and firewall configurations.
2. OT Cybersecurity & Boundary Defense
- Implement and manage strict network segmentation and micro-segmentation aligned with the Purdue Enterprise Reference Architecture (PERA).
- Enforce Ports, Protocols, and Services Management (PPSM) across the IT/OT boundary, permitting only authorized automation protocols (e.g., BACnet IP, LonWorks, Modbus TCP, Fox Protocol, DNP3, CIP).
- Configure and manage OT Next-Generation Firewalls (NGFW) and Unidirectional Gateways (Data Diodes).
- Apply and maintain network-specific Security Technical Implementation Guides (STIGs) using "OT-safe" methodologies to prevent physical process disruptions or equipment shutdowns.
3. Tier III Escalation & Protocol Analysis
- Act as the primary escalation point for network issues and resolve.
- Perform root-cause analysis on connectivity drops using advanced protocol analyzers (e.g., Wireshark) tailored to industrial/building automation protocols.
4. RMF & MILCON Support
- Develop, validate, and maintain Risk Management Framework (RMF) artifacts for Platform IT (PIT) and FRCS, including topology diagrams, hardware/software baselines, PPSM, and Plan of Action and Milestones (POA&M) updates.
- Conduct MILCON (Military Construction) and SRM project design reviews. Evaluate contractor architectural proposals, Bills of Materials (BOM), and compliance with command OT standards.
- Provide SME oversight during integration, testing, and cybersecurity commissioning (CyCx) prior to final project handover.
Requirements
SKILL SETS & REQUIRED QUALIFICATIONS :
Required Experience
- General Network Administration: Minimum 5 years of advanced network administration experience.
- OT/ICS Focus: Minimum 3 years of hands-on experience explicitly focused on ICS, SCADA, BMS, FRCS, or specialized IT/OT network environments.
Core Subject Matter Expertise (SME)
- Deep technical knowledge of strict network segmentation, firewall ruleset development, and industrial protocol routing (BACnet/IP, Modbus TCP, DNP3, CIP, etc.).
- Strong practical application of NIST SP 800-82 standards, Purdue Model implementation, DoD cybersecurity mandates, and passive/OT-safe monitoring tools.
Required Cyberspace Workforce (CWF) Certification
- Must hold and maintain at least one (1) active commercial certification satisfying DoDM 8140.03 WRC 441 Foundational Qualification prior to onboarding:
- Intermediate Level (Minimum): Security+, CEH, Cloud+, GCIH, GICSP, GSEC, or SSCP.
- Advanced Level (Automatically Qualifies): SecurityX (CASP+), CCNA, CCNP Security, CCSP, GCED, GCIA, GCLD, GDSA, GFACT.
- Note: Must complete a minimum of 20 hours annually of Continuous Professional Development (CPD) or certification-mandated renewal requirements.
Computing Environment (CE) Certifications (Highly Desirable)
- Cisco CCNA / CCNP
- Cisco Managing Industrial Networks with Cisco Networking Technologies (IMINS)
- Palo Alto PCNSA / PCNSE
- Juniper JNCIA / JNCIS
Technical & Communication Capabilities
- Software: Proficient with Microsoft Office Suite (Word, Excel, PowerPoint, Outlook).
- Communication: Fluent written and spoken English; ability to write technical reports, standard operating procedures (SOPs), root-cause analysis reports, and interact professionally with senior civilian, military, and contractor stakeholders.
Physical Requirements
- Ability to perform physical tasks common to mechanical rooms and rough facility settings:
- Extended periods of standing and walking over rough, uneven, or rocky surfaces.
- Recurring bending, stooping, crouching, reaching, and ladder climbing.
- Ability to lift and carry IT/OT equipment up to 25 lbs.
- Adequate vision to identify physical and safety hazards.
Operational Constraints & Expectations
- Safety-First Operational Approach: Standard IT troubleshooting methodologies (e.g., aggressive ping sweeps, active port scanning) can lock up or shut down critical facility systems (chillers, logic controllers, life-safety sensors). All actions must be passive or explicitly validated as "OT-safe" prior to execution.
- Information Security: Must strictly safeguard Controlled Unclassified Information (CUI), IP schemas, topology diagrams, CUI/Privacy Act data, and facility configurations.
- Email & Professionalism: Must perform duties independently under contractor management oversight using official @us.navy.mil (or authorized government) email accounts, with company identification clearly denoted in all communications.