About this role
Eng Sr Prin II - Sys
Job Description: BAE Systems, a top-ten prime contractor to the U.S. Department of Defense, enables the U.S. government to transform data into intelligence and provides engineering, integration and sustainment support for critical military platforms and systems. Intelligence & Security provides services and products to the Department of Defense, the government, federal law enforcement officials, and troops deployed around the world.
At BAE Systems, we promote a strong, collaborative culture and provide our employees with the tools, skills and training they need to succeed. We are all about trust, camaraderie and a shared ambition to lead the world in defense technologies and national security services. We offer flexible work environment to support the balance in your life and keep you performing at your best. Be a part of a company that is part of the community; driven to improve our future and protect our freedom.
We are seeking an experienced Windows Automation & Patching Engineer to support multiple enterprise domains. This role is responsible for engineering, automating, and maintaining patching and configuration management solutions across a complex, heterogeneous IT environment spanning physical, virtual, and cloud-based systems.
The successful candidate will engineer automated solutions that simplify patch distribution, reduce manual effort, increase reliability, and support the organization’s transition toward cloud-enabled operations. This includes developing and maintaining scripts, workflows, and infrastructure-as-code to enhance system management at scale. Responsibilities:
• Manage and automate patch deployment and configuration management across multiple domains and enclaves.
• Develop automation solutions using PowerShell, Python, APIs, or orchestration frameworks to streamline system updates and administrative tasks.
• Support hybrid and cloud patching capabilities using tools such as Azure Update Management, AWS Systems Manager (SSM), and SCCM/ConfigMgr.
• Engineer improvements to the enterprise patching infrastructure and contribute to the design of a new automated update and hotfix distribution system.
• Perform automation-driven server configuration, baseline enforcement, compliance reporting, and STIG/vulnerability remediation.
• Provide Tier 3 troubleshooting and root-cause analysis for complex Windows systems.
• Migrate, refactor, and modernize traditional server workloads to support cloud compatibility and virtualization strategies.
• Monitor infrastructure performance, proactively identify issues, and implement automated remediation with minimal user impact.
• Translate customer requirements into hardware/software specifications and perform system integration, verification, and validation.
• Prepare technical documentation, diagrams, and patching process workflows for customer and team use.
• Work independently in a fast-paced environment while maintaining strong communication and problem-solving skills.
• Deliver strong customer service and collaborate effectively with technical teams.
ABC
Required Skills and Education: 11+ years of relevant experience with a Bachelor’s degree, 9+ years with a Master’s degree Required Skills, Experience, and Certifications Core System Engineering & Troubleshooting
• Tier 3 troubleshooting experience in enterprise Windows environments
• Hands-on experience with Windows Server OS 2016, 2019, and 2022
• Knowledge of Active Directory, DNS, DHCP
Patching, Automation & Configuration Management
• Advanced PowerShell scripting
• Experience with WSUS across multiple enclaves and in offline/air-gapped systems.
• Familiarity with cloud patching tools (Azure Update Management, AWS SSM)
• Familiarity with SCCM/ConfigMgr or similar enterprise patching tools
• Experience with vulnerability remediation automation and STIG compliance workflows
Virtualization & Infrastructure
• Experience with VMware (vSphere 4.x–6.x) and Microsoft Hyper-V (2016–2022)
• Experience with commercial cloud providers including Azure, Google Cloud (GCP), and Oracle Cloud (OCI)
Professional Skills
• Ability to prioritize and execute tasks effectively
• Ability to work independently or within a team
• Willingness and ability to learn new technologies quickly
• Strong customer service and communication skills
About BAE Systems Intelligence & Security: BAE Systems, Inc. is a defense, aerospace, and security company headquartered in Falls Church, Virginia, with more than 40,000 employees worldwide. We serve, supply, and protect those who protect us. As one of the most geographically diverse international defense companies, we deliver a full range of products and services spanning air, land, maritime, space, and cyber, including advanced electronics, intelligence solutions, and dedicated customer support.
Our culture is performance-driven and values-led, built on curiosity, creativity, and collaboration. Purpose isn't a tagline here. It's what drives us. We're developing breakthrough technologies that defend national security and make a lasting impact on our communities and our planet. When you join BAE Systems, you're not just building a career. You're contributing to a mission that truly matters.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
Preferred Skills and Education: • Cloud certifications (Azure/AWS) • Experience with automation/orchestration tools such as AWS Lambda • Experience with cloud-native monitoring tools (Azure Sentinel, CloudWatch) or Splunk automation • Experience creating enterprise-level documentation and architectural diagrams • Experience with DSC, CI/CD pipelines, GitHub/GitLab, Jenkins Pipeline • Experience with AWS services including VPC, EC2, ELB, S3, IAM, Security Groups, Fleet Manager, and EventBridge
Benefits Information: Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
Intern Benefits: Temporary employees generally are not eligible for BAE Systems benefits, but can elect to participate in the 401(k) savings plan. Temporary employees working 20+ hours per week are eligible for medical benefits, the employee assistance program, and business travel accident insurance.
Please note: Some benefits may be different for union employees that are governed by a collective bargaining agreement (CBA) or for positions covered by a wage law called the McNamara-O’Hara Service Contract Act (SCA).