Systems Administrator

Kirkhill

$95K — $115K *
Brea, CA 92821In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of hands-on experience with Microsoft Azure and hybrid cloud solutions
  • Strong knowledge of networking protocols and architecture, including firewall and VLAN configuration
  • Active U.S. Secret security clearance is mandatory
  • Possess CompTIA Security+ certification (CE)
  • Proficient in PowerShell scripting for automation
  • Good communication skills for implementing and managing GenAI tools
  • Familiarity with cyber compliance standards like CMMC/NIST 800-171 is a plus

Responsibilities

  • Own and enhance the Azure cloud infrastructure, covering architecture, governance, and security
  • Lead migration efforts for on-premises systems to hybrid-cloud setups
  • Implement security measures and policies within the cloud environment
  • Configure Intune and manage endpoint security and deployment
  • Oversee network architecture improvements and maintain documentation
  • Manage access control and firewall settings as part of security hardening
  • Act as liaison for compliance and security in classified systems, coordinating audits and inspections

Benefits

  • Hands-on training for classified environment
  • Opportunities for professional development and certifications
  • Dynamic work environment with exposure to advanced technologies
  • Mentorship of junior IT staff
  • Supportive company culture that values communication and teamwork
Full Job Description
Systems Administrator - Cloud & Network Infrastructure

Position Summary

We are seeking a Systems Administrator with strong Azure and networking expertise.

Key Responsibilities

Cloud Infrastructure
  • Own and mature our Azure cloud environment: architecture, storage, identity (Entra ID), governance, cost management, and security posture
  • Lead cloud migration and hybrid-cloud integration efforts for on-prem workloads where appropriate
  • Implement and enforce cloud security configuration, CA policy, Defender security tooling, monitoring and logging
  • Intune configurations, package deployment, and endpoint management
  • Maintain monitoring, backup/DR, and patch/configuration management practices for cloud-hosted systems
  • Use AI, copilot, and PowerShell to automate repetitive administration and security tasks

Network Architecture
  • Design, document, and continuously improve network architecture, including segmentation between CUI-scoped enclaves and general business networks
  • Manage firewall, VLAN, and ACL configurations (including CUI subnet access control lists) and maintain accurate network documentation/diagrams
  • Lead network hardening initiatives and access control requirements (e.g., AC, SC control families)
  • Evaluate and implement zero-trust and micro-segmentation strategies

Classified Environment (training provided)
  • Maintain secure configurations, audits, and documentation for the classified workstations;
  • Maintain active Security+ certification
  • Maintain System Security Plans (SSPs), POA&Ms, and supporting documentation
  • Support periodic government inspections, self-inspections, vulnerability scans, and audit log reviews for the classified system
  • Serve as day-to-day POC for the classified environment, coordinating with the Facility Security Officer (FSO) and compliance team as needed

General Systems Administration
  • Administer Windows Server, Active Directory/Entra ID, endpoint management, and core virtual infrastructure services
  • Participate in security assessments, incident response testing, risk assessments, and 3rd party audits
  • Execute vulnerability scans, system patching, configuration deployments
  • Support configuration and software management controls (e.g., application allow-listing, nonessential functionality restrictions) in coordination with compliance staff
  • Participate in change management processes for IT systems affecting CUI/classified scope
  • Prioritize and resolve escalated technical issues and mentor junior IT staff, manage ticketing systems, and address chronic or persistent issues
  • Own and support all critical security incidents, interruptions/outages, and end-user issues with flexible evening/weekend work when required
  • Maintain system documentation, diagrams, project plans, asset inventory

Required Qualifications
  • Hands-on expertise in hybrid cloud migration, Microsoft Azure networking, cloud technologies, protocols, and authentication, and WAN network architecture
  • Experience administering Azure: identity (Entra ID), virtual machines, vnet, CA policy, Azure Foundry, Purview, Defender, Intune, etc.
  • Design and manage basic network architecture: routing, switching, segmentation, firewall/ACL configuration, VLANs, RADIUS, etc.
  • Excellent writing skills, conceptual thinking skills, and communication skills needed to learn/implement GenAI tools
  • Active Secret security clearance
  • U.S. citizenship required.
  • CompTIA Security+ (CE)

Preferred Qualifications
  • Cloud or Microsoft Azure Certifications
  • Experience with cybersecurity compliance frameworks similar to CMMC/NIST 800-171
  • Implementing simple AI solutions in Azure Foundry and/or Copilot
  • Strong PowerShell skills

Work Environment
  • On-site role
  • Some after-hours/on-call availability required to support maintenance windows and incident response

Similar Jobs

More Jobs at Kirkhill

More Information Technology Jobs

Find similar Systems Administrator jobs: