IT/Network System Administrator
One Way Ventures · Boston, MA · 2 days ago
Full-time
Duties & Responsibilities
- Design, deploy, and maintain LAN/WAN, wireless, VPN, and firewall infrastructure across Lynk office and lab locations
- Own network architecture decisions — segmentation, routing, VLANs, redundancy, and capacity planning as the company scales
- Administer and harden core infrastructure: Microsoft Entra ID (Azure AD), Conditional Access, DNS/DHCP, Office 365, and endpoint security (ESET, Microsoft Defender) at the systems-administration level
- Manage endpoint and device compliance through Microsoft Intune and MDM platforms (e.g., NinjaOne), including policy design, patch management, and fleet-wide enforcement
- Deploy, monitor, and maintain security posture via Microsoft Defender (Endpoint/365) — threat detection, alerting, and remediation
- Implement and maintain infrastructure security controls (firewalls, MFA, network segmentation, endpoint protection) in line with ITAR and export-control obligations
- Support Lynk's CMMC Level 2 compliance program — maintain endpoint compliance (patching, configuration baselines, encryption, access control) across the device fleet and evidence controls for audits
- Monitor and remediate endpoint compliance drift via Intune/NinjaOne and Microsoft Defender to keep the environment aligned with NIST SP 800-171 control requirements
- Document network topology, infrastructure architecture, and disaster recovery/business continuity procedures
Qualifications
- 4+ years of experience in network engineering, systems administration, or infrastructure management
- Hands-on experience designing and maintaining LAN/WAN, VPN, firewall, and wireless network infrastructure
- Strong Windows Server and macOS environment administration experience
- Experience managing Microsoft Entra ID (Azure AD), Conditional Access, and Office 365 at an administrative/architectural level
- Hands-on experience with Microsoft Intune for device/endpoint management and compliance policy
- Experience with MDM platforms such as NinjaOne, ManageEngine, or similar
- Experience deploying and managing Microsoft Defender (Endpoint/365) or comparable endpoint security/EDR tooling
- Understanding of network security fundamentals: firewalls, segmentation, and endpoint protection
- Familiarity with CMMC Level 2 / NIST SP 800-171 control requirements and experience maintaining endpoint compliance in a regulated environment
- Strong documentation, troubleshooting, and incident-response skills
- Relevant certification preferred (e.g., CompTIA Network+/Security+, CCNA, Microsoft Certified: Intune/Endpoint Manager, or equivalent experience)
- Bonus: Experience with PowerShell or other scripting/automation tools
- Direct experience preparing for or supporting a CMMC Level 2 assessment (SSP/POA&M development, C3PAO audit support)
- Experience supporting infrastructure in a regulated or export-controlled (ITAR) environment
- Previous startup experience is a strong plus