Senior System Engineer
Job Description
Job Description
Position Summary
The Senior System Engineer delivers hands-on senior engineering for the MEDXS/MEDEX enterprise infrastructure, implementing the technical baseline established by the Lead Engineer across CONUS and OCONUS nodes. The position combines deep enterprise systems engineering skill with practical military health IT experience, taking ownership of complex builds, integrations, migrations, and escalated troubleshooting on enterprise servers, virtualization platforms, and the network nodes that carry clinical and executive health data. This engineer operates with substantial independence, mentors junior staff, and is the technical escalation point below the Lead Engineer. Primary duty station is the Defense Health Headquarters (DHHQ), Falls Church, Virginia. On-site presence is required; telework is by Government approval only and is not guaranteed.
Essential Duties and Responsibilities
- Engineer, build, configure, integrate, test, and deploy enterprise server, virtualization, storage, and application infrastructure supporting MEDXS/MEDEX at DHHQ and at OCONUS enterprise network nodes.
- Serve as the senior escalation point for complex incidents that exceed the System Engineer and System Administrator tiers; perform advanced diagnostics across operating system, application, database, storage, and network layers.
- Implement approved engineering changes, patches, upgrades, and technology refresh actions in accordance with the Change Advisory Board schedule, including pre-change validation, execution, post-change verification, and documented rollback readiness.
- Perform IAT Level III duties: apply and validate security configurations, analyze and remediate vulnerability scan findings, conduct security impact analysis on changes, and support incident response for privileged-access systems.
- Execute STIG hardening and SCAP benchmark assessment across Windows and Linux server estates, documenting open findings and authoring mitigation statements for POA&M entry.
- Design and maintain system monitoring, alerting, logging, and audit collection; integrate host and application telemetry into enterprise monitoring and SIEM platforms and tune thresholds to reduce false positives.
- Engineer and validate backup, replication, high availability, failover, and disaster recovery configurations; plan and execute recovery exercises and document results against recovery objectives.
- Support OCONUS node standup and sustainment: pre-stage and image hardware, validate builds prior to shipment, conduct remote or on-site installation and integration, and transition nodes to steady-state operations.
- Engineer and troubleshoot data flow and interface connectivity between MEDXS/MEDEX and upstream and downstream military health IT systems, including messaging, file transfer, and API interfaces.
- Develop and maintain automation for repeatable engineering tasks using PowerShell, Bash, Python, and Ansible; reduce manual configuration drift through codified baselines.
- Author and maintain detailed technical documentation: build books, configuration baselines, standard operating procedures, as-built diagrams, and test plans and results.
- Perform capacity, performance, and utilization analysis; identify bottlenecks and recommend tuning or expansion actions to the Lead Engineer.
- Provide technical mentorship and quality review for System Engineers and System Administrators, including peer review of change plans and configuration work.
- Participate in the on-call rotation and scheduled maintenance windows, including after-hours and weekend work aligned to OCONUS time zones and clinical operating constraints.
- Contribute engineering content to RMF artifacts, control implementation evidence, and audit and inspection responses.
Minimum Qualifications
- Bachelor's Degree in Computer Science or Information Technology from an accredited institution.
- Minimum six (6) years of enterprise systems experience.
- IAT Level III certification in accordance with DoD 8570.01-M (for example, CISSP, CISA, or GCED), current and in good standing.
- Hands-on experience with military health IT systems and enterprise network nodes.
- Ability to obtain and maintain the required security clearance and IT-level designation.
Preferred Qualifications
- Direct hands-on experience with MEDXS, MEDEX, or another Military Health System or Defense Health Agency enterprise system.
- Experience supporting OCONUS or theater-deployed infrastructure.
- Platform certifications such as VMware VCP, Red Hat RHCSA/RHCE, Microsoft Azure Administrator, or Cisco CCNP.
- Experience with eMASS artifact development and ACAS scan analysis at the enterprise level.
- ITIL v4 Foundation.
Required Technical Skills and Competencies
- Windows Server (Active Directory, DNS, DHCP, Group Policy, IIS, failover clustering) and Red Hat Enterprise Linux administration and engineering at an advanced level.
- VMware vSphere or Hyper-V virtualization design and administration; enterprise SAN/NAS storage provisioning and troubleshooting.
- Enterprise patch, image, and configuration management tooling (SCCM/MECM, WSUS, Red Hat Satellite, Ansible).
- Security tooling: ACAS/Nessus, SCAP Compliance Checker, STIG Viewer, HBSS/ESS, SIEM platforms (Splunk or equivalent).
- Scripting and automation in PowerShell, Bash, and Python; Git version control.
- Network troubleshooting: TCP/IP, routing and switching fundamentals, VLANs, VPN, firewall rule analysis, and packet capture.
Performance Standards
- Escalated incidents resolved within the applicable Service Level Agreement response and resolution targets.
- All implemented changes executed within the approved maintenance window with no unplanned service impact.
- Assigned STIG and vulnerability findings remediated or mitigated within directed suspense dates.
- Build and configuration documentation current within the contractually specified update interval.
Work Environment and Conditions
- Primary duty station is the Defense Health Headquarters (DHHQ), Falls Church, Virginia. On-site presence is required per the contract; telework is by Government approval only and is not guaranteed.
- Standard core hours align to Government business hours in the Eastern time zone, with on-call and after-hours support required for scheduled maintenance windows, system outages, and OCONUS time-zone coverage.
- Work is performed in a Government office and data center/NOSC environment. Occasional lifting of equipment up to 40 pounds, work in raised-floor data center spaces, and extended periods at a workstation are expected.
- Position requires a favorably adjudicated background investigation and the ability to obtain and maintain the contract-required security clearance and IT-level designation (ADP/IT-I or IT-II as assigned).
- All personnel must satisfy DoD 8570.01-M / DoD 8140 baseline certification requirements prior to being granted privileged access and must maintain continuing education to keep certifications current.
