Systems & Security Infrastructure Engineer

Highland Engineering, Inc.
Howell, United States of America
1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 70K

Job location

Howell, United States of America

Tech stack

Microsoft Windows
Microsoft Active Directory
Ubuntu (Operating System)
Computer Security
System Configuration
IT Management
Internet Protocol Security (IP SEC)
Internetworking
Virtual Private Networks (VPN)
Information Systems Security Architecture Professional
Windows Server
Network Segmentation
Open Shortest Path First
Open Source Technology
Public Key Infrastructure
Powershell
Remote Access Technology
Azure
Ansible
Virtual Router Redundancy Protocols
Virtualization Technology
EndPointSecurity
Scripting (Bash/Python/Go/Ruby)
Sonicwall
Firewalls (Computer Science)
GIT
Microsoft InTune
Docker
User Accounts

Job description

Job Summary: HEI is a defense manufacturer operating in a tightly regulated, security-sensitive environment. While our IT leadership defines and drives the security strategy, this role serves as the hands-on technical lead responsible for executing and sustaining that strategy. With core secure architecture and controls already in place, we are seeking a dedicated in-house expert to maintain, refine, and document these systems as our operations continue to evolve.

This role will directly maintain and evolve a state-of-the-art secure IT environment in a mission-critical defense manufacturing setting under the guidance of a security-savvy CIO., * Operate and harden Windows Server/Active Directory, virtualization, storage, and switching across a multi-building campus.

  • Administer Microsoft 365 GCC-High, Azure AD, Intune/Defender for Endpoint, and physical authentication devices.
  • Provide first-line support for Windows desktops, laptops, and user accounts; support end-users.
  • Maintain and extend our PKI infrastructure, certificate lifecycle, and secure remote access gateways.
  • Support privileged access workstations, enclave segmentation, and boundary controls.
  • Implement secure configuration baselines for engineering and ERP applications.
  • Maintain high-quality technical documentation (SOPs, change logs, configuration baselines) in a Git-based system.
  • Coordinate overflow or after-hours work with our external support partners; serve as the internal escalation point.
  • Provide periodic security control reviews and evidence updates to support ongoing audits and assessments.

What We Value:

  • Operate with ownership: We look for someone who will treat the environment like their own, proactively solving problems rather than waiting for direction, but understands the environment needs consistency and process, not hurried band-aides.
  • Process-minded: Comfortable following SOPs and recording actions in a structured way (tickets, process logs, change records, etc.).
  • Effective communicator: Comfortable explaining complex issues to non-technical leaders and documenting them clearly; can work with a variety of personalities.
  • Dependable and discreet: Understands the sensitivity of the environment and handles information responsibly.
  • Mission-driven: Understands the stakes of working in a DoD manufacturing environment and acts accordingly; sense of urgency, and stays available for the occasional after-hours emergency

Requirements

Do you have experience in Windows?, * 6+ years in Windows/Active Directory administration in a security-sensitive or regulated environment

  • Familiarity with Ubuntu and Docker system administration/configuration.
  • Broad experience with PKI, network segmentation, and secure remote access solutions.
  • Familiarity with NIST-aligned control frameworks (CMMC, 800-171, DFARS) and how they translate into technical operations.
  • Scripting/automation (PowerShell, Ansible, or similar) for repeatable configuration and evidence capture.
  • Ubuntu expertise
  • Strong documentation habits and ability to mentor less-experienced staff.
  • Strong customer service orientation and documentation skills.

Preferred Skills & Experience:

  • Experience with engineering/manufacturing applications and multi-building campus networks.
  • Familiarity with open-source and Git-based evidence or configuration systems.
  • Familiarity with SonicWall firewalls, Netgear switching, OSPF, VRRP, IPSec, VPN, and other internetworking technologies.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Flexible spending account, * 401(k)
  • Dental insurance
  • Employee assistance program
  • Flexible spending account
  • Health insurance
  • Life insurance
  • Paid time off
  • Tuition reimbursement
  • Vision insurance

About the company

Highland Engineering, Inc. (HEI) was founded in 1986 - and has become one of the leading small business suppliers of Ground Support Equipment to the DoD. Our emphasis has always been on solving the needs of our customers. Highland is an employee owned company and the average tenure of a Highland Employee is more than 10 years.

Apply for this position