Lead Server Administrator
Jackson Dawson is looking for a Lead Server Administrator to own the design, deployment, and day-to-day health of our hybrid server environment. You'll be the senior technical voice on the Infrastructure team — bridging on-premises Windows Server with Microsoft Azure IaaS across multiple sites, and serving as the go-to escalation point for anything server-related. This is a hands-on, deeply technical role for someone who enjoys running the platform, mentoring the team around them, and partnering closely with IT Security, Development, and PMO to keep the business running.
Responsibilities
- Windows Server & Virtualization
- Deploy, configure, and manage Windows Server 2016/2019/2022 across on-premises and Azure IaaS (with light AWS support).
- Administer VMware vSphere 9 (ESXi hosts and vCenter): VM provisioning, snapshots, resource allocation, DRS/HA cluster health, and host maintenance.
- Own the server lifecycle end-to-end: patching (BatchPatch), firmware updates (Dell OpenManage), hardware maintenance, and decommissioning.
- Maintain server build standards, CIS baseline hardening, and clean configuration documentation.
- Active Directory & Identity
- Administer Active Directory Domain Services — domain controllers, sites and services, replication, and schema.
- Design, deploy, and troubleshoot Group Policy Objects with a regular review cadence for compliance.
- Manage DNS (AD-integrated zones, conditional forwarders, reverse lookup, split-brain DNS) and DHCP (scopes, reservations, failover).
- Run Entra ID (Azure AD) hybrid identity: Entra Connect sync, hybrid join, and Conditional Access in partnership with IT Security.
- Enforce least-privilege access across on-prem and Azure AD user, group, and OU structure.
- Microsoft Azure IaaS
- Manage Azure IaaS resources: Virtual Machines, Virtual Networks, NSGs, Load Balancers, Azure Bastion, and Storage.
- Administer Resource Groups, subscription cost management, and tagging governance.
- Configure and maintain Azure Site Recovery for DR across HQ and the secondary site.
- Manage Azure DNS zones, Private Endpoints, and VNet peering for hybrid connectivity.
- Support hybrid connectivity via VPN Gateway and/or ExpressRoute alongside the on-premises networking team.
- IIS & Web Server Administration
- Install, configure, and maintain IIS for internal and externally-facing web applications.
- Manage application pools, bindings, SSL/TLS certificates (including renewal workflows), and HTTPS configuration.
- Troubleshoot IIS performance, failed request tracing, event log analysis, and HTTP errors.
- Apply IIS hardening standards: remove unnecessary modules, configure request filtering, manage app permissions.
- Partner with Development on deployment configurations, dependencies, and dev/staging/prod parity.
- SQL Server Infrastructure
- Administer SQL Server at the OS and infrastructure layer: installation, patching, service accounts, and Windows-level performance.
- Configure and maintain HA/DR infrastructure — Always On Availability Groups, Failover Cluster Instances, and witness/quorum.
- Manage SQL Server network configuration, SQL Browser, firewall rules, and named instance connectivity.
- Partner with DBAs on storage provisioning, tempdb placement, I/O configuration, and server-level resource governance.
- Monitor Windows Event and SQL Error logs for infrastructure issues; escalate database-layer issues to the DBA team.
Note: This role owns SQL Server infrastructure. Database administration (schema, query tuning, backup jobs, agent jobs) is handled by the DBA function.
- Backup, DR & Business Continuity
- Own and operate the enterprise backup platform (Veeam Backup & Replication or equivalent) — job scheduling, retention, and media management.
- Run and document regular backup verification and test restores; maintain RTO/RPO logs.
- Design and maintain DR runbooks for all critical workloads across HQ and the AA2 secondary site.
- Administer Azure Site Recovery replication, failover testing, and failback procedures.
- Coordinate DR tabletop exercises with IT leadership and produce post-exercise remediation plans.
- Monitoring, Observability & Log Management
- Own our monitoring stack: Grafana, GrayLog, and VMware Tools (vSphere 9).
- Deploy monitoring agents and data collectors across every managed endpoint — physical servers, VMs, and desktop workstations.
- Build and maintain Grafana dashboards covering CPU, memory, disk I/O, network throughput, and service availability across physical, virtual, and Azure IaaS workloads.
- Configure Grafana alerting rules, notification channels, and escalation policies so the right people hear about the right thresholds.
- Administer GrayLog for centralized log ingestion, parsing, and storage — inputs, extractors, streams, and pipelines for Windows Event, IIS, application, and syslog sources.
- Partner with IT Security on GrayLog retention and SIEM integration.
- Manage VMware Tools across all guest VMs; feed guest performance metrics into Grafana.
- Maintain a complete monitoring-coverage inventory: every managed device must have a confirmed agent and active check-in.
- Establish and document performance baselines by device class; use them to spot drift, capacity trends, and pre-failure indicators.
- Respond to monitoring-triggered incidents; document RCA and remediation for all P1/P2 events.
- Produce monthly infrastructure health and coverage reports for IT leadership.
- Automation & Scripting
- Build and maintain PowerShell scripts for provisioning, patch reporting, compliance checking, DNS auditing, and account management.
- Maintain a version-controlled, documented script library and contribute to the IT automation roadmap.
- Support CI/CD pipeline infrastructure in coordination with Development (Azure DevOps) where provisioning intersects with pipeline needs.
- Security & Compliance
- Apply and maintain CIS benchmark hardening on all managed servers; support IT Security with vulnerability remediation.
- Manage server-level firewall rules, Windows Defender configuration, and local security policy in line with IT Security standards.
- Support audit and compliance requests — inventory, access reports, patch compliance, and log exports.
- Documentation & Technical Leadership
- Keep infrastructure documentation accurate and current: network/server diagrams, IP/DNS inventory, runbooks, change records, and SOPs.
- Mentor junior Infrastructure and Help Desk staff on server and systems topics.
- Lead infrastructure projects end-to-end: scoping, design, implementation planning, and post-implementation review.
- Participate in IT governance and change management under IT leadership.
Requirements
- 8+ years of progressively responsible Windows server and systems administration in enterprise environments.
- Demonstrated experience administering hybrid environments spanning on-premises Windows Server and Microsoft Azure IaaS.
- Strong hands-on expertise in Active Directory, DNS, DHCP, and Group Policy in multi-site environments.
- Proven IIS administration experience, including SSL/TLS certificate management and web application server configuration.
- Practical experience with enterprise backup platforms (Veeam strongly preferred) and documented DR processes including test restores.
- SQL Server infrastructure experience: installation, patching, Always On Availability Groups, and Failover Clustering.
- Proficiency in PowerShell scripting for administration and automation.
- Experience providing technical mentorship or informal leadership to junior team members.
Preferred Qualifications
- Microsoft certifications: AZ-800 (Hybrid Infrastructure), AZ-104 (Azure Administrator), MCSA/MCSE Windows Server, or equivalent.
- Experience with Azure DevOps in an infrastructure context (pipelines, infrastructure-as-code coordination).
- Familiarity with IT governance, change management, and ITIL-aligned service management.
- Experiential marketing or agency environment experience is a plus.
What Success Looks Like — First-Year OKRs
- Q1 Foundation & Assessment
- Establish a complete, accurate inventory of all managed server assets (on-prem and Azure) with documented configuration baselines.
- 100% of production servers documented in CMDB/asset system within 60 days.
- Server hardening audit completed against CIS benchmarks; remediation backlog created and prioritized.
- All backup jobs validated with documented test restores for Tier 1 workloads.
- Q2 Reliability & Automation
- Reduce manual administrative burden and improve platform consistency through automation.
- PowerShell automation deployed for patch compliance reporting, DNS auditing, and AD user account review.
- Server patch compliance rate ≥ 95%, reported monthly to IT leadership.
- IIS SSL certificate renewal automated or formally tracked with zero expiry events.
- Q3–Q4 DR Maturity & Hybrid Optimization
- Validate and mature disaster recovery posture across both sites.
- Full DR tabletop exercise completed for HQ and AA2 failover scenarios; gaps documented.
- Azure Site Recovery replication verified for all Tier 1 workloads with documented RTO/RPO targets.
- SQL Server Always On AG health verified and failover test executed with documented results.
Work Environment
Jackson Dawson is an experiential marketing agency operating in a fast-paced, project-driven environment. This role supports IT operations across multiple physical sites and involves managing competing priorities. On-site in Dearborn, MI. Occasional off-hours availability is required for