06 ago
|
Astrion
|
Colombia
Overview Senior Windows Systems Administrator
LOCATION: Columbia, MD (Onsite)
JOB STATUS: Full-time
CLEARANCE: Active Top Secret / TS/SCI (Required)
TRAVEL: Less than 10%
SALARY RANGE: $145k - $165k
Astrion has an exciting opportunity for a highly experienced Senior Windows Administrator to build, secure, and sustain the Windows Server estate, the Windows 11 workstation fleet, and the Active Directory and Windows network services that run across three or more isolated classified networks supporting Department of Defense/Department of War (DoD/DoW) environments in Columbia, MD. The adecuado candidate brings deep Windows Server and Active Directory expertise, extensive experience operating inside closed and air-gapped classified enclaves, and a proven record of building and maintaining systems in compliance with Risk Management Framework (RMF), DoD STIG, and Comply-to-Connect (C2C) requirements. This position requires Monday through Friday on-site work at our facility in Columbia, MD.
REQUIRED QUALIFICATIONS / SKILLS
Active TS/SCI security clearance (required)
Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience)
8+ years of Windows systems and network administration experience within DoD/DoW or classified environments
Deep expertise in
Windows Server administration (2016 through 2022): installation, patching, performance tuning, roles and features, storage, and networking
Active Directory Domain Services: Group Policy, DNS, DHCP, DFS, ADCS, sites and replication, and trusts
Scripting and automation (PowerShell and desired-state configuration)
Windows endpoint management (Microsoft Endpoint Configuration Manager, imaging, Group Policy)
End-user support on Classified Windows 11 and Windows Server supporting Operating System, supported applications, and hardware issues
Demonstrated experience implementing and maintaining DoD STIG compliance on Windows Server and workstations
Experience with offline and air-gapped patching (WSUS or MECM in an isolated enclave)
Strong understanding of
RMF (Risk Management Framework)
DISA security requirements and accreditation processes
DCSA accreditation standards
Active DoD 8140 (formerly DoD 8570) compliant baseline certification (e.g., Security+ CE, CISSP)
Active DoD 8140 compliant computing environment certification (e.g., minimum Microsoft certification such as Windows Server Hybrid Administrator Associate or MCSA/MCSE equivalent)
Experience with
ACAS or Nessus and SCAP scanning
SIEM integration and Windows event and log analysis
Continuous monitoring under RMF
KEY COMPETENCIES
Advanced Windows Server and Active Directory administration and troubleshooting
Security hardening and compliance enforcement
Automation and scripting (PowerShell) Strong troubleshooting skills used in end-user support Strong analytical and problem-solving abilities
Excellent communication and documentation skills
Ability to operate in high-security, mission-critical environments
PREFERRED QUALIFICATIONS / SKILLS
On-Premise deployment and administration of Microsoft SharePoint environments
Microsoft certifications such as Windows Server Hybrid Administrator Associate, Azure Administrator (AZ-104), or Identity and Access Administrator
Hyper-V and Windows Failover Clustering, and storage experience (NetApp or SAN)
PKI and Active Directory Certificate Services design and administration
PowerShell automation at scale (desired-state configuration, Git-based configuration management)
Zero Trust architectures and application allowlisting (AppLocker or WDAC) in classified environments
Prior experience supporting Cross Domain Solutions (CDS) programs
Experience with cloud-based DoD environments (e.g., Azure Government, Azure Secret)
Project management experience and experience briefing executive leadership
RESPONSIBILITIES
Administer, patch, and sustain Windows Server (2016 through 2022) and Windows 11 workstations across three or more isolated classified networks, each operated as its own authorization boundary
Provide end-user support for classified Windows Server and Windows 11 workstations to include troubleshooting supported applications,
hardware, and operating system issues.
Administer Active Directory Domain Services across a separate forest per enclave: Group Policy, DNS, DHCP, DFS, Active Directory Certificate Services, sites and replication, and trust health
Build, harden, and baseline Windows systems to DoD Security Technical Implementation Guides (STIGs); remediate findings and control configuration drift
Manage the Windows workstation fleet with Microsoft Endpoint Configuration Manager (MECM), image build and deployment (MDT/WDS), application packaging, and Group Policy on closed networks
Perform patching and updates on air-gapped networks through approved offline processes (WSUS in an isolated enclave, MECM, or trusted media transfer), with a defined cadence and an emergency-patch path
Administer Windows network services: DNS, DHCP, name resolution, time synchronization, PKI and certificate services, and Windows Firewall with IPsec policy
Administer virtualization and clustering where present (Hyper-V, Windows Failover Clustering), including capacity planning and recovery testing
Automate provisioning, configuration, and remediation with PowerShell and desired-state configuration, including on disconnected systems
Administer host-based endpoint protection (Microsoft Defender for Endpoint or approved ESS) and integrate with the security tool stack
Implement and maintain C2C and 802.1x posture for Windows endpoints
Perform vulnerability remediation and continuous monitoring in accordance with RMF controls; run and interpret ACAS and SCAP scans and review Windows event and audit logs
Support the Authority to Operate (ATO) process, including STIG checklists, POA&Ms;, and risk assessments
Maintain backup and recovery for Windows systems and Active Directory, including system state and authoritative and non-authoritative restore
Develop and maintain system documentation, diagrams, SOPs, and security artifacts
Troubleshoot complex issues across multi-network, multi-vendor environments
Collaborate with cybersecurity, network engineering, systems engineering, and mission stakeholders to ensure secure, reliable operations
Support audits, inspections, and compliance validation activities
📌 Sr. Windows Systems Administrator (Colombia)
🏢 Astrion
📍 Colombia