> Markdown version of [/jobs/ext/1737226-it-systems-administrator-it006](https://www.wearedevelopers.com/jobs/ext/1737226-it-systems-administrator-it006). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Systems Administrator (IT006) - **Company:** Practical Energetics Research, Inc. - **Location:** Huntsville, AL, United States - **Salary:** $45,000.0 - $80,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Audit Trail, BitLocker Drive Encryption, CompTIA Security+, System Configuration, Domain Name System (DNS), Event Logging, File Server, Identity and Access Management, Information Security Management, Network Packet, Local Area Networks, Microsoft Office, Windows Servers, Peer-To-Peer (P2P), Windows PowerShell, Azure Active Directory, Cloud Services, Kusto Query Language, Security Content Automation Protocol, Microsoft SharePoint, Security Information and Event Management, Software Vulnerability Management, EndPointSecurity, Network Routers, Firewalls (Computer Science), Microsoft InTune, Information Technology, Nessus, Microsoft Sentinel, Hardware Infrastructure, CIS Benchmarks, User Administration, Vulnerability Analysis - **Published:** July 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=78b79ea13e6e6c80 ## About the Role · High Autonomy: Proven track record of operating as a sole or primary system administrator; capability to resolve complex technical blockers with minimal supervision. · Hybrid Systems Experience: Deep technical familiarity with both local Windows Server administration (Active Directory, GPOs, local file shares) and cloud tenant administration. · Sovereign Cloud Knowledge: Direct operational experience working within a Microsoft 365 GCC High or government-sovereign cloud environment. · Troubleshooting Proficiency: Demonstrated ability to read, interpret, and act upon Windows error messages and Event Logs, network packet captures, and security telemetry. · Ability to manage time and tasks. · Proficiency with Microsoft Office Suite · Clearance Eligibility: eligible to obtain a U.S. Secret security clearance. · Physical Demands: Ability to lift and move up to 25 lbs. Desired Qualifications · Compliance Framework Exposure: Direct familiarity with NIST SP 800-171, NIST SP 800-53, or CMMC Level 2 controls. · Active U.S. Secret security clearance · Professional Certifications: CompTIA Security+, CySA+, Network+, Microsoft Certified: Systems Administrator, or equivalent technical credentials. · Federal Toolsets: Exposure to the Risk Management Framework (RMF) lifecycle and eMASS portal operations. · Scripting & Automation: Proficiency with PowerShell for automating repetitive Active Directory tasks, bulk user management, or querying Entra ID/Intune telemetry. · Log Management & SIEM: Hands-on experience querying logs using KQL (Kusto Query Language) inside a Microsoft Sentinel repository. · Vulnerability Assessment Tools: Direct operational experience configuring and executing credentialed scans using toolsets like SCAP or Microsoft Defender Vulnerability Management. · Identity Management: Experience managing secure administrative practices such as Local Administrator Password Solution (LAPS) and enforcing baseline Just-In-Time (JIT) access. · Secure Provisioning: Experience using NIST SP 800-88 R1 guidelines for media sanitization, data wiping, and hardware decommissioning. ## Description PER is seeking a highly autonomous and self-reliant IT Systems Administrator / ISSO to assist with owning, managing, and keeping our corporate IT footprint secure. Reporting directly to the Information System Security Manager (ISSM), you will serve as an operational partner for our 30+ employee user base. This is not a basic helpdesk role or a heavily supervised position. The successful candidate must possess final tier-1 and tier-2 resolution authority, demonstrating the technical maturity to research, troubleshoot, and solve obscure systems errors independently. You will balance daily, hands-on workstation and infrastructure operations with strict technical security execution to enforce NIST SP 800-53, 800-88, and 800-171 controls. Primary Responsibilities (Operational & Security Governance) · Execute Configuration Changes: Act as the primary technical actor responsible for deploying, maintaining, and upgrading operating systems, applications, laptops, firewalls, and network assets in accordance with established security baselines. · Enforce Access Control Systems: Technically grant permissions and manage identities within Microsoft Entra ID and local Active Directory. Ensure all user modifications align with documented approvals from HR and Department Heads (Resource Owners). · Enforce Separation of Duties (SoD): Operate strictly within a "Request-Authorize-Execute" compliance workflow, ensuring you do not independently authorize your own changes or access rights. · Own the Technical Helpdesk: Drive full lifecycle resolution for all employee technical issues, leveraging independent research and event log analysis before escalating to the ISSM. · Manage Cryptographic Systems: Maintain the lifecycle of encryption keys, certificates, and secure BitLocker/LAPS escrow protocols. · Execute Compliance Monitoring: Conduct weekly audit log reviews, run automated vulnerability scans (e.g., SCAP/STIG, Nessus, OpenVAS, MDE), and provide initial technical support for incident response containment and forensic efforts. · Ensure Data & Media Integrity: Conduct routine, scheduled audits of system backups and execute formal media sanitization processes in compliance with NIST SP 800-53, 800-88, and 800-171 Daily and Monthly Responsibilities (Hybrid Architecture Management) · On-Premises Infrastructure Management: Maintain and optimize local network assets including our departmentally isolated file server, local Active Directory, DNS servers, PBX phone systems, switches, routers, and edge firewalls. · Cloud Ecosystem Administration: Administer our sovereign Microsoft 365 GCC High tenant, managing configurations across Microsoft Entra ID, Intune, SharePoint Online, and Defender for Endpoint. · Workstation Hardening: Enforce endpoint security profiles via Intune and local Group Policy Objects (GPOs), actively maintaining blocks on nonessential functions (e.g., peer-to-peer sharing, consumer-grade cloud resource sharing). · Log Preservation: Monitor, triage, and preserve event logs, tracking all system variations inside the corporate Change Management Log. · Availability: Provide on-call support during critical system upgrades, outages, or mandatory maintenance windows that may occasionally occur outside of regular business hours. ## Related Videos - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [From Zero to Hero: NextJS 13 and Tailwind CSS for Beginners](https://www.wearedevelopers.com/videos/766-from-zero-to-hero-nextjs-13-and-tailwind-css-for-beginners) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Building Better with Nuxt 3](https://www.wearedevelopers.com/videos/320-building-better-with-nuxt-3) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)