Senior Microsoft Systems Administrator
We are seeking a Senior Microsoft Systems Administrator to lead a project focused on hardening Windows servers and workstations in compliance with NIST SP 800-53 security controls. This role requires strong technical expertise in Microsoft technologies combined with practical knowledge of cybersecurity standards.
Responsibilities
- Install, configure, harden, patch, and maintain Windows Server (2019/2022+) and Windows 10/11 workstations in accordance with NIST SP 800-53 Rev. 5 controls.
- Implement and validate security controls across families including Access Control (AC), Configuration Management (CM), Identification & Authentication (IA), Audit & Accountability (AU), System & Communications Protection (SC), and others relevant to endpoint/server platforms.
- Manage Group Policy Objects (GPOs), security baselines, and Intune/Microsoft Endpoint Manager policies to enforce 800-53-aligned configurations (e.g., password policies, account lockout, least privilege, firewall rules, AppLocker, BitLocker).
- Perform hardening tasks including:
- Enforcing deny-by-default/allow-by-exception execution policies
- Configuring host-based firewalls and intrusion detection/prevention
- Implementing multi-factor authentication and privileged account management
- Enabling cryptographic protections for data at rest/transit
- Removing unnecessary services, features, and default accounts
- Administer Microsoft tools for compliance: Active Directory, Microsoft Endpoint Configuration Manager (SCCM/MECM), Microsoft Intune, Azure AD/Entra ID, Defender for Endpoint, and Azure Policy (where hybrid/cloud-integrated).
- Document system security plans (SSP), control implementation details, POA&Ms, and evidence for NIST 800-53 controls during the project.
- Develop PowerShell scripts for automation of compliance checks and reporting.
Requirements
- 4+ years of hands-on experience administering Windows servers and workstations in enterprise environments.
- Demonstrated experience implementing NIST SP 800-53 security controls on Microsoft platforms.
- Proficiency with Microsoft administration tools: Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, Defender suite.
- Understanding of key 800-53 control families as applied to endpoints/servers (AC, AU, CM, IA, SC, SI, etc.).
- Experience with hardening techniques, baseline configuration management, and least-privilege principles.
- Familiarity with compliance tools (Nessus/Tenable or similar).
- Strong scripting skills (PowerShell preferred) for automation and compliance checks.
- U.S. citizenship required.
Benefits
- Competitive pay
- Comprehensive health, dental, and vision coverage
- 401(k) retirement plans
Pay
$55/hr on W2
About the Company
At Seneca Resources, we are a trusted career partner providing opportunities that help professionals grow their careers while making an impact. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we match professionals with roles that align with their skills and career path. Our consultants and contractors enjoy the support of a dedicated team who advocates for them every step of the way.