Senior Microsoft Systems Administrator
GDH · Montgomery, AL · 1 wk ago
Information Technology$110k–$130k/yrFull-time
About the Role
A Senior Microsoft Systems Administrator leads efforts to enhance the security posture of Windows servers and workstations through comprehensive implementation of NIST SP 800-53 security controls. This senior-level position is suited for candidates with extensive experience in Microsoft systems administration and security best practices.
Responsibilities
- Install, configure, harden, patch, and maintain Windows Server (2019/2022+) and Windows 10/11 workstations according to NIST SP 800-53 Rev. 5 controls.
- Implement and validate security controls across various families including Access Control, Configuration Management, Identification & Authentication, Audit & Accountability, and System & Communications Protection for endpoints and servers.
- Manage Group Policy Objects (GPOs), security baselines, and Intune/Microsoft Endpoint Manager policies to enforce NIST-aligned configurations such as password policies, account lockout, least privilege, firewall rules, AppLocker, and BitLocker.
- Perform system hardening tasks by enforcing deny-by-default policies, configuring host-based firewalls and intrusion detection/prevention systems, implementing multi-factor authentication, managing privileged accounts, and enabling cryptographic protections for data at rest and in transit.
- Remove unnecessary services, features, and default accounts to enhance security measures.
- Administer Microsoft security and compliance tools, including Active Directory, Microsoft Endpoint Configuration Manager (SCCM/MECM), Microsoft Intune, Azure AD/Entra ID, Defender for Endpoint, and Azure Policy for hybrid/cloud environments.
- Document security plans (SSP), control implementation procedures, Plan of Action & Milestones (POA&Ms), and maintain evidence for NIST 800-53 controls throughout project execution.
- Develop PowerShell scripts to automate compliance checks, security configurations, and reporting activities.
Requirements
- Minimum of 4 years of hands-on experience managing Windows servers and workstations within enterprise environments.
- Proven experience in implementing NIST SP 800-53 security controls on Microsoft platforms.
- Proficiency with Microsoft administration tools such as Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, and Defender for Endpoint.
- Strong understanding of NIST 800-53 control families, including Access Control, Audit & Accountability, Configuration Management, Identification & Authentication, and System & Communications Protection.
- Extensive experience with system hardening techniques, baseline configuration management, and least privilege security principles.
- Familiarity with vulnerability management and compliance tools such as Nessus/Tenable or similar solutions.
- Strong scripting skills, particularly with PowerShell, to automate compliance processes and security tasks.
- Eligibility for a U.S. Government security clearance; U.S. citizenship is required.
Pay
$110,000.00 – $130,000.00 annually.
Schedule
This position is based in the office and requires the employee to work on-site.