Network Administrator with a Top Secret Clearance

Information Technology Santa Rita, Guam


Description

Job Requirements 

CALNET is looking for a Network Administrator to independently design, manage, and secure complex industrial and building automation network environments. The scope encompasses the administration of industrial-grade and ruggedized routing and switching hardware, boundary defense firewalls, protocol analysis, and Risk Management Framework (RMF) compliance. The objective is to maintain secure, segmented network architectures that guarantee zero unplanned disruption to mission-critical physical processes and facility environments.

Key Responsibilities 

  • Configure and maintain industrial-grade network hardware (e.g., Cisco IndustrialEthernet, Palo Alto, Data Diode, Allen-Bradley Stratix, Ruggedcom, standard enterpriseswitches adapted for OT) deployed in mechanical rooms and harsh physical environments.
  • Manage network topologies (e.g., Resilient Ethernet Protocol (REP), Device Level Ring(DLR)) to ensure rapid failover and continuous deterministic traffic flow for time-sensitivecontrol processes and environmental controls.
  • Maintain comprehensive backup solutions for all industrial and building switch, router, and firewall configuration files.
  • Implement strict network segmentation and micro-segmentation adhering to the Purdue Enterprise Reference Architecture (PERA).
  • Manage Ports, Protocols, and Services Management (PPSM) across the IT/OT boundary, ensuring only authorized protocols (e.g., BACnet IP, LonWorks, Modbus TCP, Fox Protocol, DNP3, CIP) traverse network enclaves.
  • Configure and manage OT-specific Next-Generation Firewalls (NGFW) and Unidirectional Gateways (Data Diodes).
  • Apply network-specific Security Technical Implementation Guides (STIGs) securely, testing configurations in non-production settings to prevent accidental physical equipment shutdowns.
  • Act as the primary escalation point for severe network degradation, packet loss, or routing failures within the FRCS/ICS/BMS environment.
  • Utilize advanced protocol analyzers (e.g., Wireshark) tailored for industrial and building protocols to conduct root-cause analysis on connectivity drops impacting physical machinery and facility controls.
  • Coordinate with facility/mechanical engineers, SCADA/BMS vendors, and IT cybersecurity teams to resolve boundary crossing anomalies.
  • Evaluate network capacity and provide engineering recommendations for lifecycle replacements, bandwidth upgrades, and hardware specifications.
  • Author network-specific Standard Operating Procedures (SOPs) and system baselines for the OT environment.
  • Support the RMF process for Platform IT (PIT) and FRCS by providing technical artifacts, topology diagrams, hardware/software lists, PPSM, and supporting vulnerability scans.
  • Participate in facility modernization and Military Construction (MILCON) project design reviews (35%, 65%, 95%, 100% phases).
  • Evaluate proposed contractor network architectures, hardware Bills of Materials (BOM), and PPSM for compliance with Command OT standards, the Purdue Model, and DoD cybersecurity mandates.
  • Provide SME support and oversight during integration, testing, and commissioning of new control systems and HVAC/Building systems.
  • Collaborate with government stakeholders and the cybersecurity commissioning team (CyCx) prior to final project handover and government acceptance.

Certifications (Required):

  • SecurityX(CASP+) or CCNA or CCNP Security or CCSP or GCED or GCIA or GCLD or GDSA or GFACT

AND

  • Cisco CCNA/CCNP or Palo Alto PCNSA/PCNSE or  Juniper JNCIA/JNCIS, or Cisco Managing Industrial Networks with Cisco Networking Technologies (IMINS)

 

 

Typical Educational/Experience Requirements 

  • Bachelor’s degree in Computer Science, IT, or equivalent experience.
  • US Citizen
  • Active Top Secret Clearance
  • Minimum of 5 years of advanced network administration experience, with at least 3 years explicitly focused on ICS, SCADA, BMS, FRCS or IT/OT network environments.
  • Deep technical expertise in Operational Technology (OT) network administration, focusing on strict network segmentation, firewall rule development, and the routing of industrial protocols (e.g., BACnet/IP, Modbus TCP). The candidate must demonstrate a proven ability to securely apply DoD cybersecurity mandates, NIST SP 800-82 standards, and OT-safe network monitoring practices within the Purdue Model, ensuring deterministic traffic flows and highly available connectivity without disrupting critical facility operations or life-safety systems.

This opportunity is onsite in Guam

CALNET, Inc. offers a competitive salary and a generous benefits package.  This package includes medical, dental, vision, life, short- and long-term disability insurances, a 401(k)-retirement savings plan, and generous leave time.

CALNET, Inc. is an Equal Opportunity Employer. EEO/M/F/D/V