Linux Systems Administrator in Orono, Maine at COMPOTECH INC
Explore Related Opportunities
Job Description
Title: Linux Systems Administrator
Department: Information Technology (IT)
Reports To: Information Technology Manager
The Linux Systems Administrator is responsible for administering, maintaining, securing, and supporting company Linux-based systems, including Digital Solutions servers, specialized multi-GPU AI systems, GitLab, monitoring tools, Docker/container workloads, Linux storage, encryption, and related infrastructure that may process, store, or transmit CUI.
The role reports to the IT Manager for supervision, access-control governance, security requirements, change-control compliance, and CMMC evidence expectations. The role coordinates Digital workload priorities with the Digital Solutions Team while following IT governance, security, access-control, change-management, and CMMC evidence requirements.
This position supports CMMC evidence and technical control operation but does not own the SSP, POA&M, risk register, or formal compliance governance. This position also does not replace Digital Solutions’ business ownership of AI workloads, model environments, application requirements, or department use of CUI.
Duties/ Responsibilities:
1. Linux, AI, and Hardware Administration
- Administer Linux servers supporting Digital Solutions workloads and IT infrastructure.
- Support specialized multi-GPU AI servers, including GPU drivers, CUDA stack, AI frameworks, and related dependencies.
- Maintain supported Linux distributions or document approved exceptions.
- Manage services, users, groups, sudo permissions, SSH access, package repositories, host firewalls, time synchronization, logging configuration, and baseline security settings.
- Maintain hardware inventory for assigned Linux/AI systems, including server model, serial number, warranty/support status, GPU model, storage configuration, RAM, NICs, firmware versions, and physical location.
- Monitor hardware health, including GPU status, storage health, RAID status, temperature, power, fans, memory, and system event logs.
- Coordinate hardware troubleshooting, diagnostics, firmware updates, component replacement, vendor support, warranty claims, and maintenance windows.
- Document hardware failures, repairs, firmware changes, replacement parts, and vendor support activity in tickets.
- Support procurement planning, replacement recommendations, warranty renewals, and vendor-support coordination for assigned Linux/AI hardware.
2. GitLab, Docker, Monitoring, and Platform Support
- Administer and support company GitLab systems used by Digital Solutions and related technical teams.
- Manage GitLab users, groups, projects, permissions, runners, access tokens, SSH keys, deploy keys, and service accounts according to approved access-control procedures.
- Support GitLab patching, upgrades, backup verification, restore testing, and vulnerability remediation.
- Administer and support Grafana and Prometheus monitoring for assigned Linux, AI, GitLab, Docker, hardware, and infrastructure systems.
- Maintain dashboards, alert rules, exporters, metrics collection, retention settings, and notification routing.
- Administer Docker and container-based workloads, including Docker Engine, images, containers, volumes, networks, registries, compose files, and related dependencies.
- Review container privileges, mounted volumes, exposed ports, secrets, service accounts, image updates, and vulnerability findings.
- Escalate missing telemetry, failed alerts, disabled monitoring, unresolved critical alerts, exposed secrets, unauthorized access, or security concerns to the IT Manager.
3. CMMC, CUI, Access Control, and Evidence
- Treat Linux systems that process, store, or transmit CUI as in-scope CMMC systems.
- Maintain evidence for patch status, vulnerability review, user/admin access review, log review, privileged access review, backup/data protection status, configuration baseline status, encryption status, and monitoring coverage.
- Support CUI data-flow documentation showing where CUI enters, is stored, is processed, is exported, and is removed.
- Support model/output classification evidence when AI outputs, logs, datasets, screenshots, exports, or model artifacts may contain CUI.
- Maintain named user and administrator accounts.
- Review sudoers, privileged groups, SSH keys, GitLab tokens, deploy keys, service accounts, and stale accounts.
- Support monthly user/admin access reviews and quarterly privileged access reviews.
- Require IT Manager approval for new administrative access, new CUI user groups, remote access changes, privileged access changes, or other access-control changes affecting CUI or security.
4. Patching, Vulnerability Management, Storage, Encryption, and Backups
- Perform or coordinate Linux patching and document approved exceptions.
- Review vulnerability findings for assigned Linux, GitLab, container, and AI systems.
- Remediate vulnerabilities or document approved exceptions with business and technical justification.
- Coordinate downtime with Digital Solutions and IT when needed.
- Administer and document Linux storage configurations, including LUKS, mdadm, file systems, mount points, RAID arrays, and encrypted volumes.
- Maintain evidence of disk encryption status for systems that process, store, or transmit CUI.
- Monitor RAID health, degraded arrays, disk failures, rebuild status, and storage capacity.
- Support encryption key handling, recovery procedures, and documented access restrictions.
- Support FIPS-mode configuration, validation, and exception documentation where required or approved.
- Verify backup or data-protection requirements for Digital Linux systems.
- Support backup configuration, backup monitoring, restore testing, and documentation of systems that do not require backup.
5. Logging, Incident Support, and Change Management
- Ensure Linux authentication, sudo/admin activity, system, security, application, GitLab, Docker, and monitoring logs are enabled and retained where applicable.
- Support log forwarding or approved alternate log-retention methods.
- Review assigned Linux/server logs on the required cadence and provide log-review evidence.
- Escalate failed login spikes, unknown accounts, suspicious processes, unexpected outbound traffic, missing logs, disabled security controls, failed backups, failed restore tests, lost/corrupted CUI, or unresolved vulnerabilities.
- Create or update change tickets for Linux OS, kernel, GPU driver, CUDA, AI framework, GitLab, Docker, monitoring, storage, encryption, access, logging, backup, or security changes.
- Include business reason, affected system, CMMC/security impact, testing plan, rollback plan, approver, result, and evidence in applicable tickets.
- Coordinate with Digital Solutions for operational impact and with IT for network, firewall, VLAN, VPN, remote access, and security-boundary changes.
- Obtain IT Manager approval for high-risk, CUI-impacting, security, access-control, production, exception, or compliance-impacting changes.
Qualifications:
- Linux server administration
- SSH, sudo, users/groups, permissions, package management, services, logs, and shell scripting
- Linux patching and vulnerability remediation
- GPU server support, including NVIDIA drivers, CUDA, and AI/ML framework dependencies
- GitLab administration or support experience
- Grafana/Prometheus monitoring administration
- Docker/container administration
- Linux storage, LUKS encryption, mdadm RAID, and FIPS configuration familiarity
- Backup, logging, and system monitoring concepts
- Ability to document configuration, testing, exceptions, and evidence clearly
- Ability to coordinate technical changes with business owners and IT governance
- Understanding of CUI handling expectations or willingness to follow CMMC/NIST procedures
Preferred Qualifications:
- Experience with Ubuntu, RHEL, Rocky, AlmaLinux, Debian, or similar enterprise Linux distributions
- Experience with NVIDIA multi-GPU systems
- Experience with CUDA, PyTorch, TensorFlow, containerized AI workloads, or HPC-style environments
- Experience with vulnerability scanners and remediation tracking
- Experience supporting CMMC, NIST SP 800-171, DFARS, or other regulated environments
- Security+, Linux+, RHCSA, RHCE, CISSP, CISA, or similar certification
U.S. Citizenship required (due to federal contract obligations).
MUST BE A U.S. CITIZEN