Now hiring

Windows Systems Engineer @ Stninc

USOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers.

Key ResponsibilitiesAdminister Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services

Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan

Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation

Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy

Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines

Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews

Monitor backup and replication jobs, run and evidence test restores, and escalate failures against RPO and RTO commitments

Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning

Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows

Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks

Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation

Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current

Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines

Experience & QualificationsRequired

5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration

Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback

Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate

PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell

Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it

Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require

Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access

Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product

Hands-on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management

Clear written communication and documentation habits suited to a multi-customer environment

Bachelor's degree in information technology, computer science, or equivalent experience

Preferred

Experience in an MSP, MSSP, or multi-tenant hosting environment supporting several customers concurrently

Azure IaaS or Azure Virtual Desktop experience alongside on-premises virtualization

Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto

Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365

Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow

Hybrid identity experience including Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles

Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting

Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE

CompensationFull-Time, Exempt

$175,000-$195,000/year, DOE

BenefitsHealth Coverage – Medical, Dental & Vision

FSA Health and Dependent Care available

401(k) Plan

Unlimited Paid Time Off (PTO)

Observed Holidays Paid

Cell Phone Allowance

Collaborative, growth-driven culture

Skills

AI

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores