Systems Administrator II (Microsoft 365 GCC & GCC High)
Role details
Job location
Tech stack
Job description
We are currently looking to hire a Systems Administrator II to serve as the hands-on operational administrator of our two Microsoft government cloud tenants: an enterprise Microsoft 365 GCC tenant supporting corporate operations, and a Microsoft 365 GCC High enclave where Controlled Unclassified Information (CUI) is processed under NIST SP 800-171 and DFARS requirements. This is a full-time, on-site position at SA-TECH's Oxnard, CA Operations office.
This Level II role reports directly to the Director of IT. You enter as the Tier 2 technical escalation point, with an expected progression to Tier 3 within your first 12-18 months while you master the environment, including mentoring junior IT staff. You will execute administrative work under a mature governance model: changes go through change control, privileged access is just-in-time and audited, and the work you do is captured as assessment-ready evidence. If you take pride in doing systems administration the right way - documented, least-privilege, repeatable - you will recognize this environment as one built for you.
What you'll do (other duties may be added as needed):
- Microsoft 365 tenant administration (GCC and GCC High)
- Administer core workloads across both tenants - Entra ID, Exchange Online, SharePoint Online, OneDrive, and Teams - including user and group lifecycle, licensing, and tenant configuration.
- Maintain the separation between the enterprise GCC tenant and the GCC High CUI enclave, following SA-TECH's adopted boundary model and data-handling rules.
- Support information-protection configurations (sensitivity labeling, DLP, sharing restrictions) in coordination with the Director of IT and the security operations function.
- Identity, access, and privileged administration
- Operate a just-in-time, least-privilege administrative model with modern, phishing-resistant authentication - privileged work is time-bound, justified, and audited.
- Administer identity and access management across both tenants: authentication policy, conditional access, and the credential lifecycle for users and administrators.
- Manage service and special-purpose accounts according to documented configuration baselines and procedures.
- Perform account provisioning, deprovisioning, and access changes tied to personnel actions, and support recurring account reconciliation reviews.
- Endpoint and device management
- Administer Microsoft Intune for company devices - enrollment, configuration baselines, update regimens, and device lifecycle workflows across desktop and mobile platforms.
- Follow SA-TECH's dedicated administrative workstation practices for privileged work, and help maintain the supporting configuration baselines.
- Coordinate with the security operations function on endpoint protection; monitoring and independent review remain separated from this role by design.
- Automation, evidence, and operational discipline
- Script and automate administrative work with PowerShell and Microsoft Graph, including against government cloud endpoints.
- Execute changes through SA-TECH's change-control process: submit and implement approved change requests, keep configuration baselines current, and document what was done.
- Capture and file evidence of administrative work (configuration exports, transcripts, screenshots) to support CMMC Level 2 assessment readiness - evidence capture is built into our procedures, not an afterthought.
- Follow, improve, and help author standard operating procedures; propose better ways of doing things through the governance process rather than around it.
- Team support
- Serve as the Tier 2 escalation point for junior IT staff and provide day-to-day mentoring, progressing to Tier 3 escalation authority.
- Support Azure Government services connected to the enclave as the environment evolves.
- Mentor more junior IT staff.
SA-TECH maintains deliberate separation of duties: governance and approvals, independent security oversight, and operational execution are distinct functions. This role owns execution - performing the administrative and configuration work in both tenants under that governance and oversight. You will have real responsibility and real authority to do the work - with clear limits, clear approvals, and an audit trail that protects you as much as the company., * SA-TECH offers flexible work schedules depending on the program, alongside generous PTO benefits.
- SA-TECH is an Equal Opportunity/Affirmative Action employer and evaluate all applicants regardless of race, color, religion, sex, sexual orientation, gender identity, pregnancy, national origin, disability, or protected Veteran status.
- We participate in the E-Verify system to verify work authorization in the U.S.
- Applicants are encouraged to apply within 5-15 days of posting for optimal consideration.
- We prioritize a supportive work environment, professional development, and a healthy work-life balance and our pay and benefits aim to enhance employee well-being. If this culture resonates with you, we invite you to apply. If you're uncertain about your fit, please explore other roles on SA-TECH Careers.
Requirements
- High School Diploma or equivalent.
- Three years or more (3+) of hands-on systems administration experience in a Microsoft 365 / Entra ID environment.
- Working proficiency with Entra ID (users, groups, roles, Conditional Access), Exchange Online, SharePoint Online/OneDrive, Teams, and Intune.
- PowerShell scripting experience, including Microsoft Graph PowerShell or equivalent administrative automation.
- Understanding of multi-factor authentication, least-privilege administration, and role-based access control concepts.
- Strong documentation habits and the discipline to work within change control and standard operating procedures.
- Clear written and verbal communication, including the ability to explain technical work to non-technical stakeholders and, when needed, to assessors.
- Must possess valid US Drivers' license; must be able to be insured through SA-TECH's vehicle insurance policy while driving work/government/rental vehicles during working hours, and for the duration of your work employment.
- No security clearance is required.
- All candidates will be required to pass background screening to include SSN, Driver Record, and Criminal Background Investigation., * Experience administering Microsoft 365 GCC High and/or GCC, including familiarity with U.S. government cloud endpoints and their differences from commercial M365 would be very beneficial.
- Familiarity with NIST SP 800-171, CMMC Level 2, and DFARS 252.204-7012 obligations in a defense-contractor setting is a plus.
- Experience implementing privileged-access management, phishing-resistant MFA, or dedicated administrative workstation patterns in Microsoft environments would be very helpful.
- Experience supporting compliance assessments or audits (evidence gathering, walkthroughs, interviews) would be beneficial.
- Relevant certifications such as CompTIA Security+, MD-102, MS-102, SC-300, or AZ-104 are preferred.
- Experience with Azure (Azure Government preferred), Microsoft Purview, or Defender-family security tooling is a big plus.
- Prior DoD or federal IT experience - hands-on IT or technical work performed for, or in direct support of, DoD or other federal components (uniformed service, government civilian, or contractor) is an added advantage.
- Formal education - an associate's or bachelor's degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience or military technical training is preferred.
- Clearance eligibility - the ability to obtain and maintain a U.S. security clearance should future contract requirements direct it; an active or previously held DoD security clearance is a plus.
Benefits & conditions
This position is based full-time, on-site at SA-TECH's Oxnard, CA Operations office. Privileged administration and CUI-related work are performed on-site on SA-TECH-managed equipment in accordance with our data-handling and dedicated administrative workstation practices.
The annual base salary range for this position is $95,000 - $120,000. Actual base pay within this range is determined by job-related factors including relevant experience, skills, certifications, education, and internal equity, consistent with California pay-transparency requirements. SA-TECH also offers a comprehensive benefits package.
Work Conditions:
- Work will be performed in climate-controlled enclosed buildings.
- Work will include sitting, standing, walking, lifting and reaching.
- The typical work schedule is Monday - Friday, 7am - 4pm, with occasional planned after-hours maintenance windows scheduled through change control.
- You will be working in front of computer screens for most of the day., As a highly regarded and long-established DoD employer, SA-TECH recognizes that our success is indicative of our team members' hard work and dedication towards a common goal… Supporting our Warfighters. Along with unparalleled stability, we have the ingredients for superior performance with a servant leadership mentality that provides an affirmation of purpose and value in a team-oriented positive work environment. As such, we provide a sense of family, competitive pay and employee benefits, along with a strong commitment to the professional development of our workforce and for providing broad career opportunities throughout the United States.
SA-TECH offers:
- Employee Recognition
- Above-Average Compensation
- Competitive Benefits
- Ongoing Training and Development
- Career Advancement Opportunities
Benefits Offered:
- Medical, Dental, Vision
- Life Insurance
- Long-Term Disability
- 401(k) match
- Flexible Spending Accounts
- EAP
- Education Assistance
- PTO and Holidays
- Vacation and Sick Leave, $95,000.00