Job Title: Senior Systems Engineer
Work Location: Remote or hybrid if near CO/VA offices
Labor Category: Exempt
Clearance Level: Secret
Travel: Up to 20%
Pay Rate: $111,000 - $142,000
About the Role This role works collaboratively with IT leadership, internal departments, cybersecurity personnel, vendors, and other technical resources, the Senior Systems Engineer provides advanced technical expertise, develops and maintains comprehensive system documentation, supports technology and cybersecurity initiatives, and contributes to the development of a secure, resilient, scalable, compliant, and highly available technology environment capable of supporting the organization's current and future business and federal contracting requirements.
What You'll Be DoingEnterprise Infrastructure & Cloud Administration- Administer, maintain, monitor, secure, and optimize enterprise servers, networks, storage, endpoints, cloud services, virtualization platforms, and other critical IT infrastructure to ensure availability, performance, resiliency, and security.
- Manage Microsoft 365 Commercial and GCC High, including Exchange Online, SharePoint Online, Teams, OneDrive, and related Microsoft cloud services.
- Administer Microsoft Azure and Microsoft Entra ID, including users and groups, enterprise applications, authentication, MFA, Conditional Access, RBAC, privileged access, Azure Policy, resource governance, and lifecycle management.
- Manage Windows Server and Active Directory environments, including Group Policy, DNS, DHCP, file services, certificates, and other core infrastructure services.
- Administer and support VMware and Microsoft Hyper-V environments, including hosts, virtual machines, storage, resource allocation, performance, patching, and lifecycle management.
- Support enterprise networking, including routers, switches, firewalls, wireless, VPNs, VLANs, WAN connectivity, network segmentation, DNS/DHCP, and network security technologies.
- Monitor infrastructure for availability, capacity, performance, security events, and operational issues and troubleshoot complex infrastructure, application, authentication, endpoint, network, and cybersecurity problems.
- Plan and execute infrastructure upgrades, system migrations, technology refreshes, cloud implementations, and modernization initiatives, including capacity and technology lifecycle planning.
- Manage technology services such as Microsoft licensing, cloud subscriptions, certificates, domains, warranties, support agreements, and vendor relationships.
Cybersecurity, CMMC & Infrastructure Security- Support implementation and ongoing compliance with NIST SP 800-171, CMMC, federal contractor cybersecurity requirements, and applicable organizational security standards.
- Implement, maintain, document, and validate technical controls protecting CUI, FCI, and other sensitive organizational information.
- Support the definition and maintenance of the organization's CMMC Assessment Scope, including identification and categorization of CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets.
- Maintain associated asset inventories, system boundaries, network and architecture diagrams, data flows, configurations, and technical documentation required to support cybersecurity assessments.
- Implement and maintain secure configurations using approved security baselines, DISA STIGs, CIS Benchmarks, Microsoft Security Baselines, hardening standards, and configuration requirements.
- Participate in cybersecurity assessments, control reviews, vulnerability assessments, POA&Ms, remediation activities, audits, and other compliance initiatives.
- Administer endpoint security and management technologies, including Microsoft Intune, Defender for Endpoint, Defender for Office 365, Defender for Identity, EDR, antivirus/anti-malware, encryption, application control, and device compliance.
- Manage operating system and application patching and vulnerability remediation, ensuring vulnerabilities are evaluated, prioritized, remediated, documented, and validated.
- Administer and support centralized logging and SIEM capabilities, including log collection, retention, correlation, alerting, monitoring, reporting, and integration across infrastructure, endpoints, networks, cloud, identity, and security platforms.
- Monitor security alerts and system events and participate in cybersecurity incident response, including identification, investigation, containment, remediation, recovery, documentation, and post-incident review.
Identity, Access & Data Protection- Manage user accounts, security groups, service accounts, administrative privileges, and access controls in accordance with least privilege and role-based access principles.
- Administer privileged identity capabilities, including Privileged Identity Management (PIM), privileged administrative accounts, emergency/break-glass accounts, service accounts, managed identities, service principals, and privileged-access recertification.
- Maintain identity lifecycle processes for onboarding, transfers, role changes, and terminations, including appropriate provisioning, modification, disabling, and removal of access.
- Implement and support MFA, SSO, Conditional Access, RBAC, privileged access, and other identity security technologies.
- Administer and support Microsoft security and compliance capabilities, including Microsoft Purview, sensitivity labels, Data Loss Prevention (DLP), retention, information protection, and device compliance controls.
- Review and secure Microsoft 365, SharePoint, OneDrive, Teams, Azure, and other data repositories to address excessive permissions, oversharing, inappropriate access, and potential exposure of sensitive information.
Backup, Recovery & Business Continuity- Administer enterprise backup, restoration, replication, and disaster recovery solutions to ensure the availability, integrity, and recoverability of organizational systems and data.
- Perform and document backup restoration testing and participate in disaster recovery and business continuity exercises, supporting established Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
- Maintain appropriate security controls for backup and recovery infrastructure to protect against unauthorized access, ransomware, data loss, and other threats.
AI, Automation & Emerging Technologies- Serve as a senior technical resource for the evaluation, implementation, integration, security, administration, governance, and support of AI, Generative AI, intelligent automation, machine learning, and other emerging technologies.
- Support the organization's enterprise AI strategy by identifying opportunities to use AI and automation to improve IT operations, cybersecurity, productivity, service delivery, analytics, knowledge management, reporting, and business processes.
- Evaluate, implement, administer, and support approved technologies such as Microsoft Copilot, Microsoft 365 Copilot, Azure AI services, AI-enabled security technologies, Power Automate, Microsoft Graph, PowerShell, and other authorized automation platforms.
- Establish and maintain appropriate AI governance, technical standards, security controls, guardrails, acceptable-use requirements, and risk-management practices in collaboration with IT, cybersecurity, compliance, legal, contracts, and business stakeholders.
- Ensure AI technologies and integrations comply with organizational policies and applicable requirements for CUI, FCI, PII, proprietary information, privacy, data classification, and other sensitive information, including preventing unauthorized use of public or consumer AI services.
- Conduct or support AI risk assessments addressing data leakage, unauthorized disclosure, identity and access, privacy, accuracy, intellectual property, supply-chain risk, model integrity, availability, security, and operational impact.
- Maintain an inventory of approved AI systems, applications, models, agents, integrations, APIs, data sources, owners, classifications, and authorized use cases.
- Implement appropriate authentication, authorization, least privilege, Conditional Access, privileged access, logging, monitoring, DLP, encryption, and other security controls for AI platforms and integrations.
- Review Microsoft 365, SharePoint, OneDrive, Teams, Exchange, Azure, and other repositories for oversharing and inappropriate access before enabling AI capabilities that access organizational data.
- Design, test, and support AI agents, copilots, workflows, integrations, and intelligent automation, ensuring appropriate human approval, validation, logging, auditing, rollback, and exception handling.
- Identify and evaluate opportunities to use AI in infrastructure monitoring, log analysis, incident triage, vulnerability management, threat intelligence, documentation, ticket classification, root-cause analysis, asset management, reporting, and administrative automation, while maintaining appropriate human oversight.
- Evaluate AI solutions and third-party AI providers for security, data handling, data residency, model-training practices, contractual protections, authentication, logging, encryption, integrations, certifications, and supply-chain risk.
- Support AI-related incident response involving unauthorized AI use, sensitive-data exposure, compromised accounts or integrations, misuse of AI agents, malicious prompts, or other AI-related security events.
- Maintain AI architecture, data-flow, configuration, security, risk, integration, operating, and administrative documentation and provide technical guidance and education on secure and responsible AI adoption.
- Monitor emerging AI technologies, security threats, vulnerabilities, federal guidance, and industry practices and recommend opportunities and safeguards to IT leadership.
Operations, Documentation & Continuous Improvement- Maintain accurate hardware, software, server, network, cloud, endpoint, application, and technology asset inventories and support technology lifecycle management.
- Develop and maintain technical documentation, including architecture and network diagrams, system inventories, configuration standards, SOPs, administrative guides, security documentation, and disaster recovery materials.
- Participate in IT change management to ensure infrastructure and system changes are appropriately assessed, tested, documented, approved, implemented, and validated.
- Support technology audits and assessments by gathering evidence, documenting configurations, producing reports, and responding to technical and cybersecurity requirements.
- Collaborate with cybersecurity, compliance, business leadership, vendors, managed service providers, telecommunications providers, and technology partners to resolve issues and implement secure technology solutions.
- Provide advanced technical support, escalation assistance, mentoring, and knowledge transfer to systems administrators, help desk personnel, and other IT staff.
- Identify opportunities to improve automation, standardization, security, efficiency, reliability, and operational performance through scripting, PowerShell, Microsoft technologies, AI, and other approved tools.
- Participate in scheduled maintenance, after-hours/on-call support, emergency response, cybersecurity incidents, outages, and planned infrastructure activities as required.
- Ensure technology services are operated with an emphasis on security, availability, confidentiality, integrity, resiliency, performance, and regulatory compliance.
- Perform other systems administration, infrastructure, cybersecurity, compliance, automation, AI, and technology-related duties as assigned in support of organizational and contractual objectives.
What We're Looking For- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related technical field, or an equivalent combination of education, technical training, professional certifications, and relevant experience.
- 10+ years of progressively responsible experience in systems administration, infrastructure engineering, network administration, cloud administration, or a related IT discipline, including 7+ years in a senior-level systems or infrastructure role supporting complex enterprise environments.
- Demonstrated expertise administering Windows Server, Active Directory, Group Policy, DNS, DHCP, file services, and other core enterprise infrastructure technologies.
- Strong experience supporting Microsoft 365 Commercial and/or GCC High, including Exchange Online, SharePoint Online, Teams, OneDrive, and related Microsoft cloud services.
- Hands-on experience administering Microsoft Azure and Microsoft Entra ID, including identity and access management, MFA, Conditional Access, enterprise applications, RBAC, privileged accounts, and related security controls.
- Hands-on experience administering VMware and/or Microsoft Hyper-V virtualization environments and supporting enterprise networking technologies, including TCP/IP, VLANs, routing, switching, VPNs, firewalls, wireless networks, DNS, DHCP, and network troubleshooting.
- Experience administering enterprise endpoint management and security technologies, including EDR, antivirus/anti-malware, device management, encryption, software depl