Windows Systems Engineer

STN

  • Pleasanton, California
  • 7 days ago

    Highlights

    The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers. PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell.

    Numbers & Facts

    LocationPleasanton, California
    Websitehttps://www.stninc.com/

    Description

    The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers.

    Key Responsibilities

    • Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services

    • Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan

    • Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation

    • Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy

    • Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines

    • Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews

    • Monitor backup and replication jobs, run and evidence test restores, and escalate failures against RPO and RTO commitments

    • Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning

    • Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows

    • Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks

    • Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation

    • Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current

    • Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines

    Experience & Qualifications

    Required

    • 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration

    • Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback

    • Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate

    • PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell

    • Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it

    • Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require

    • Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access

    • Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product

    • Hands-on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management

    • Clear written communication and documentation habits suited to a multi-customer environment

    • Bachelor's degree in information technology, computer science, or equivalent experience

    Preferred

    • Experience in an MSP, MSSP, or multi-tenant hosting environment supporting several customers concurrently

    • Azure IaaS or Azure Virtual Desktop experience alongside on-premises virtualization

    • Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto

    • Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365

    • Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow

    • Hybrid identity experience including Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles

    • Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting

    • Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE

    Compensation

    • Full-Time, Exempt

    • $175,000-$195,000/year, DOE

    Benefits

    • Health Coverage – Medical, Dental & Vision

    • FSA Health and Dependent Care available

    • 401(k) Plan

    • Unlimited Paid Time Off (PTO)

    • Observed Holidays Paid

    • Cell Phone Allowance

    • Collaborative, growth-driven culture

    Similar Jobs

    See more jobs