Windows Systems Engineer
STN, inc.
Pleasanton, CA, United States
16 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$175,000.0 - $195,000.0
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Active Directory
Domain Controllers
Systems Engineering
JIRA
Microsoft Azure
CompTIA Security+
Data Stores
Dynamic Host Configuration Protocol
Software Debugging
Domain Name System (DNS)
Hyper-V
+26 more
Infrastructure as a Service (IaaS)
Identity and Access Management
Python (Programming Language)
Microsoft Office
System Center Configuration Manager
Windows Servers
Virtual Desktops
Public Key Infrastructure
Windows PowerShell
Ansible
Runbook
VMware VSphere
Software Vulnerability Management
Backup and Restore
SSL Certificate Management
Scripting
Microsoft InTune
Azure Security Center
Information Technology
Patch Management
Nessus
Veeam
Terraform
Qualys
Servicenow
Vulnerability Analysis
Job description
- Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services
- Plan and execute Active Directory work - domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes - from a documented plan
- Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation
- Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy
- Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines
- Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews
- Monitor backup and replication jobs, run and evidence test restores, and escalate failures against RPO and RTO commitments
- Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning
- Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows
- Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks
- Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation
- Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current
- Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines
Requirements
- 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration
- Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback
- Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate
- PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others - or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell
- Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it
- Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require
- Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access
- Backup and restore operations: job monitoring, test restores, and failure escalation - Cohesity or Veeam preferred, though the operational discipline matters more than the specific product
- Hands-on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management
- Clear written communication and documentation habits suited to a multi-customer environment
- Bachelor’s degree in information technology, computer science, or equivalent experience
Preferred
- Experience in an MSP, MSSP, or multi-tenant hosting environment supporting several customers concurrently
- Azure IaaS or Azure Virtual Desktop experience alongside on-premises virtualization
- Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto
- Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365
- Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow
- Hybrid identity experience including Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles
- Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting
- Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE
Benefits & conditions
- Health Coverage - Medical, Dental & Vision
- FSA Health and Dependent Care available
- 401(k) Plan
- Unlimited Paid Time Off (PTO)
- Observed Holidays Paid
- Cell Phone Allowance
- Collaborative, growth-driven culture
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
about 2 months ago
CS
Christina Schaireiter
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
4 months ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
8 months ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago
EM
Eli McGarvie
Highest Paying Tech Companies for Developers
over 3 years ago