> Markdown version of [/jobs/ext/2269871-systems-administrator](https://www.wearedevelopers.com/jobs/ext/2269871-systems-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Administrator - **Company:** MIT Lincoln Laboratory - **Location:** Lexington, MA, United States (Remote available) - **Salary:** $95,700.0 - $126,700.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Data Analysis, Proxy Servers, User Authentication, Automation of Tests, BitLocker Drive Encryption, Business Software, Configuration Management, Software Documentation, Code Review, CompTIA Security+, Cyber Security, Continuous Integration, Dynamic Host Configuration Protocol, Domain Name System (DNS), Multi-Factor Authentication, Firmware, Systems Theories, Virtual Private Networks (VPN), Python (Programming Language), Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), System Center Configuration Manager, Multi-Purpose Internet Mail Extensions (MIME), Networking Basics, Operational Data Store, Public Key Infrastructure, Windows PowerShell, Zero Trust Network Access, Software Deployment, TCP/IP, Software Vulnerability Management, SSL Certificate Management, Hardware Testing, Git, Microsoft InTune, Azure Security Center, Build Management, Windows Security, Hardware Asset Management, 3-tier Architectures, Restful APIs, Software Version Control, Devsecops, Programming Languages - **Published:** August 27, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9121541/systems-administrator ## About the Role * Modern Windows Endpoint Engineering: Experience managing Windows OS as a product across provisioning, configuration, application delivery, patching, security, and lifecycle management. * Modern Endpoint Management: Hands-on experience with enterprise endpoint management platforms such as HCL BigFix or Microsoft Endpoint Configuration Manager. * Automation and Development: Strong PowerShell automation capability and experience with reusable modules, structured error handling, application programming interfaces, Git, code review, and continuous integration and delivery practices. Python or another development language is beneficial. * DevSecOps Practices: Strong understanding of secure engineering, vulnerability remediation, automated testing, source control, continuous integration and delivery, and configuration as code principles. * Security and Compliance: Ability to engineer and maintain endpoint security controls aligned with Laboratory cybersecurity requirements, NIST 800 171, vulnerability management, zero trust principles, and applicable Windows security baselines. * Endpoint Analytics and Reliability: Experience using telemetry, operational metrics, device health data, and service trends to identify reliability issues and drive automated remediation and continuous improvement. * Documentation and Communication: Experience maintaining technical documentation, operational procedures, troubleshooting guides, testing records, and change documentation. Strong presentation, writing, and interpersonal communication skills. * Problem Solving and Collaboration: Very strong problem solving skills and the ability to work autonomously while reporting status at the appropriate level. Ability to collaborate effectively across teams with varying technical responsibilities. * Networking Fundamentals: Solid understanding of endpoint connectivity and troubleshooting including DNS, DHCP, TCP/IP, HTTPS and TLS, VPN, proxies, Kerberos, LDAP, SMB, wireless authentication, and certificate based authentication. Preferred Skills * Advanced Endpoint Automation: Experience with Microsoft Graph, REST application programming interfaces, automated testing such as Pester, configuration as code, secrets handling, and automated compliance remediation. * Identity and Access Integration: Working knowledge of Microsoft Active Directory, authentication, certificates, and multi-factor authentication tokens. * Endpoint Security Controls: Experience with Microsoft Defender for Endpoint or equivalent endpoint detection and response tooling, BitLocker, attack surface reduction, Credential Guard, and application control technologies. * Endpoint Management Strategy: Experience designing co-management strategies between traditional enterprise endpoint management while enabling shadow IT delegative access to update research systems and applications. * Future Cloud Management : Working knowledge and/or experience with Microsoft inTune, Auto-pilot and Windows integration with EntraID. * Digital Employee Experience: Experience with endpoint experience monitoring, performance analytics, proactive remediation, service health measures, or digital employee experience platforms. * PKI Concepts: Knowledge of public key infrastructure concepts including certificate lifecycle management, device certificates, authentication certificates, and S/MIME. * Security Frameworks and Certifications: Familiarity with Security Plus, NIST 800 171, zero trust architecture, or related security frameworks and certifications. * Hardware Lifecycle Management: Experience with enterprise hardware standards, OEM integration, compatibility testing, firmware and driver management, refresh planning, secure wipe, and retirement. * IT Service Management: Familiarity with ITIL practices, service management, problem management, change management, and service catalog concepts., * Typically, a bachelor's degree plus a minimum of 4 years of relevant experience or equivalent education and experience. * Detailed hands-on knowledge of Windows 11 endpoint operational and security architecture in an enterprise environment. * Hands on experience with modern Windows provisioning and management using enterprise endpoint management capabilities such as HCL BigFix and Microsoft Endpoing Configuration Management. * Hands-on experience managing Windows endpoints with HCL BigFix, Microsoft Endpoint Configuration Manager, Active Directory Group Policy, or similar traditional management platforms and the ability to support transition between management models. * Strong PowerShell scripting and automation skills with the ability to develop reliable, reusable solutions for endpoint management and remediation. * Working knowledge of Git, application programming interfaces, structured testing, and continuous integration and delivery practices. * Working knowledge of endpoint security technologies, vulnerability remediation, encryption, certificate management, and Windows security configuration. * Strong knowledge of endpoint networking and troubleshooting including DNS, DHCP, TCP/IP, HTTPS and TLS, VPN, proxies, Kerberos, LDAP, SMB, wireless authentication, and certificate-based authentication. * Experience validating endpoint compatibility across enterprise hardware platforms, drivers, firmware, security agents, and business applications. ## Description Seeking an experienced Windows OS engineer to serve as part of the Modern Endpoint Workspace Team responsible for engineering, automating, securing, and continuously evolving the Laboratory's enterprise Windows endpoint platform. The position will focus on modern endpoint management, policy driven provisioning, application delivery, security compliance, lifecycle management, endpoint analytics, and employee experience. The role will utilize DevSecOps practices and systems management tools such as HCL BigFix, Microsoft Endpoint Configuration Manager, PowerShell, Git, and application programming interfaces to improve reliability, security, and operational efficiency. The position will collaborate closely with partnering teams of identity, cyber, network, service management, research IT, and the Laboratory's Service Center to provide a consistent and supportable endpoint experience across supported Dell and Microsoft devices. Participation in an on-call rotation and occasional off-hour support is required, as is on-site troubleshooting when necessary. This position reports to the End Point Management group within the Laboratory's Digital Solutions Department. Primary Duties Platform Engineering and Development * Design and maintain automated endpoint provisioning and configuration workflows using HCL BigFix, Microsoft Endpoint Configuration Manager and OEM provisioning capabilities. * Create reusable automation and engineering solutions using PowerShell, Python, REST application programming interfaces, Git, and continuous integration and delivery practices. * Apply configuration as code principles, automated testing, source control, peer review, and structured release practices to endpoint engineering changes. * Plan and execute staged compatibility testing and deployment of Windows quality updates, feature updates, drivers, firmware, and security changes using deployment rings and controlled rollout strategies. * Evaluate existing management workloads and identify opportunities for enhancement while maintaining support for environments with specialized requirements. Modern Endpoint Management and Experience * Utilize HCL BigFix for configuration settings, pushing OS and application updates and remediation fixlets. * Use endpoint telemetry, experience analytics, service desk trends, and operational data to identify reliability, performance, configuration, and employee experience issues. * Develop automated remediation for recurring endpoint health, configuration, performance, security, and application issues to reduce service desk demand and improve user experience. * Define and monitor endpoint service health measures including provisioning success, patch and configuration compliance, application reliability, device health, security posture, and remediation effectiveness. * Engineer the complete endpoint lifecycle from hardware standards and OEM integration through provisioning, configuration, operational management, refresh, secure wipe, and retirement. Service Engineering and Support * Provide Tier 3 engineering escalation and root cause analysis, including collaboration with IT peer groups in central and research IT, vendor management, knowledge creation, problem diagnosis, and resolution management. * Support project initiatives through requirements gathering, prototyping, systems design, testing, validation, deployment planning, and operational transition. * Develop, publish, and maintain system documentation including requirements, design and build documentation, test plans, operational procedures, troubleshooting guides, and standard operating procedures according to department standards. * Review endpoint security alerts, vulnerabilities, configuration drift, and compliance issues and work with the Laboratory's Cyber team to prioritize and implement remediation. * Collaborate with Microsoft, hardware manufacturers, software vendors, and service providers to plan for and remediate operational issues affecting the endpoint platform. * Partner with the Service Center and Workplace Experience teams to improve self-service, supportability, employee experience, and adoption of endpoint services., * Ability to obtain and maintain a security clearance is required for this position. * Position is hybrid where remote work is the norm but occasional on-site presence is required for system troubleshooting, hardware validation, and other operational needs. * Rely on experience and judgment to plan and accomplish goals with limited supervision. * Role requires flexibility, sound technical judgment, and creative problem solving to address evolving endpoint, security, and employee experience challenges. Administrative Duties * Develop, publish, and maintain system documentation including requirements, design and build documentation, testing records, operational procedures, and standard operating procedures according to department standards. * Develop and deliver training for peers and end users on service features, enhancements, new applications, and endpoint capabilities to increase effective adoption and supportability. * Participate in change management, problem management, service improvement, and technical review activities as required. * Participation in on-call rotation and occasional off-hour support is required. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)