Job Position: Senior System Administrator
Location: El Segundo, CA
Duration: Full time
Overview:
Client is seeking a Senior Systems Administrator to own the systems that keep the company running day-to-day within Microsoft 365 GCC High. You'll own the tenant, build our identity and access automation from the ground up in an Entra-native environment with no on-prem Active Directory or Group Policy, and manage the endpoint, email security, and SaaS infrastructure the business runs on. You'll implement and evidence the technical controls behind our CMMC assessment as part of the normal job, not a detour. This is a high-ownership seat in an interdisciplinary environment, advancing milestones toward commercializing the first mass-produced nuclear reactor.
Responsibilities and Duties:
- Own Microsoft 365 GCC High: Exchange Online, SharePoint, Teams, and the tenant configuration underneath them; be the authority on what's possible in this cloud and what has to be built in-house.
- Own Entra end-to-end: conditional access, privileged access, app registrations, and single sign-on.
- Build the IAM automation layer, the centerpiece of the role: joiner/mover/leaver lifecycle, entitlements driven by HR data, provisioning through Graph and SCIM, and access reviews that run themselves.
- Own Windows and endpoint management through Intune, Autopilot, compliance policy, and update rings across the fleet, with no Group Policy underneath.
- Own email security and information protection: Defender for Office, mail flow and anti-phishing posture, and Purview for DLP, labeling, and retention in an environment handling CUI.
- Own SaaS administration and integration across the business application portfolio, including Box and Slack; some running today, some a project waiting for an owner.
- Own the workloads, services, and licensing infrastructure running in AWS, in constant contact with the IT DevOps engineer who owns the account layer.
- Take new platform projects from idea to deployed, integrated, and documented.
- Implement and evidence the technical controls in these areas for the CMMC assessment ahead, as normal work rather than a detour.
Required Qualifications and Skills:
- Bachelor's degree in Information Technology, Computer Engineering, Cybersecurity, or a similar field (4 years of work experience in lieu of a degree).
- 7+ years administering and engineering production systems.
- Deep, hands-on experience across the responsibilities above: GCC High tenant administration, Entra, self-built IAM automation, Intune without Group Policy, email security and Purview, and SaaS/AWS administration.
- Solid networking fundamentals: VLANs, routing, firewall policy, DNS/DHCP, VPN, wireless.
- Treats compliance control implementation and evidence collection as normal work.
- Service is the job; tier-1 handles day-to-day support, but nobody's too senior to help the person at their desk.
Desired Qualifications and Skills:
- Purview depth: DLP, sensitivity labeling, retention, or eDiscovery.
- CMMC or NIST 800-171 exposure; leading an assessment is not required.
- Stood up identity governance tooling: Entra ID Governance, SailPoint, Okta Workflows, or equivalent.
- Automation experience with PowerShell, Python, Microsoft Graph, and infrastructure as code (Terraform, Bicep, or similar).
- Written and maintained PowerShell modules other people use, not just scripts.
- Deployed Box, Slack, or comparable platforms into a regulated environment and handled the data boundary questions.