Role Overview
We are looking for a Senior Windows Administrator responsible for the design, administration, security, and day-to-day operation of enterprise Windows infrastructure and Microsoft-based platforms. The role has a strong focus on Windows Server, Active Directory, Microsoft Entra ID, endpoint management, Microsoft 365, server hosting, patching, backup, monitoring, and infrastructure operations, while also contributing to Azure, identity security, automation, and hybrid infrastructure initiatives. This is a hands-on senior infrastructure role requiring someone who can independently manage the organization’s server fleet and directory services, maintain secure and resilient infrastructure, troubleshoot complex issues, and contribute to infrastructure improvements and technology initiatives.
Key Responsibilities
Windows Server & Infrastructure Administration
- Administer, maintain, and support enterprise Windows Server environments across physical, virtualized, and hosted platforms.
- Manage the day-to-day operation, availability, performance, and reliability of Windows infrastructure.
- Perform server provisioning, configuration, hardening, patching, maintenance, and lifecycle activities.
- Maintain secure baseline configurations for Windows servers and endpoints.
- Manage server logging, monitoring, capacity, and performance.
- Troubleshoot complex Windows infrastructure issues and perform root-cause analysis.
- Support hosting and virtualization environments and associated infrastructure platforms.
- Contribute to disaster recovery and business continuity activities, including RPO/RTO planning and testing.
Active Directory & Microsoft Entra ID
- Administer and maintain Active Directory and Microsoft Entra ID environments.
- Support hybrid identity architecture and synchronization between on-premises and cloud environments.
- Manage users, groups, organizational structures, authentication, and access controls.
- Implement and maintain Conditional Access policies and identity security controls.
- Support enterprise Single Sign‑On (SSO) using protocols such as OAuth and SAML.
- Manage privileged access using PAM, PIM, and Just‑in‑Time (JIT) access models.
- Apply least-privilege and Zero Trust principles across identity and access management.
- Manage Microsoft Entra enterprise applications, app registrations, permissions, and consent.
Endpoint & Device Management
- Manage the enterprise Standard Operating Environment (SOE) for Windows devices.
- Administer endpoint configurations, local administrator access, and security baselines.
- Implement and maintain LAPS and secure endpoint administration practices.
- Manage device lifecycle and endpoint configuration using Microsoft Intune.
- Administer Windows Autopilot for device provisioning and deployment.
- Support endpoint compliance, configuration, patching, and security management.
- Troubleshoot endpoint and device management issues across the organization.
Microsoft 365 Administration
- Administer and support Microsoft 365 services and associated workloads.
- Support identity, access, security, configuration, and operational requirements across Microsoft 365.
- Troubleshoot Microsoft 365 service and user access issues.
- Support integration between Microsoft 365, Entra ID, endpoint management, and enterprise applications.
Azure Infrastructure & Platform Support
- Support Azure infrastructure and platform services within a hybrid enterprise environment.
- Work with Azure networking components including:
- Virtual Networks
- Hub-and-Spoke architectures
- Landing Zones
- Network Security Groups (NSGs)
- Application Security Groups (ASGs)
- User Defined Routes (UDRs)
- VNet peering
- Trust‑zone segmentation
- Support Azure Virtual Desktop (AVD) environments and associated access and security controls.
- Contribute to cloud infrastructure design, implementation, resilience, and cost optimization.
- Apply infrastructure standards and best practices to Azure environments.
Infrastructure Security
- Implement secure infrastructure configurations across servers, endpoints, identity, and cloud environments.
- Apply Zero Trust principles across identity, devices, networks, and applications.
- Support Microsoft security platforms including:
- Microsoft Defender
- Microsoft Sentinel
- Microsoft Purview
- Azure security services
- Support endpoint detection and response (EDR) operations and remediation activities.
- Implement and maintain information protection and DLP controls.
- Support security hardening based on recognized security standards and benchmarks.
- Assist with infrastructure and security incident response and remediation.
Core Infrastructure Services
- Administer and support core infrastructure services including:
- DNS
- NTP
- DHCP and related infrastructure services where applicable
- Server patching
- Logging
- Monitoring
- Support firewalls, cloud proxy, SASE/CASB, and related infrastructure security controls.
- Manage certificate lifecycle and PKI services for internal and external infrastructure.
- Troubleshoot connectivity, authentication, certificate, and infrastructure service issues.
Automation & Infrastructure as Code
- Identify repetitive infrastructure and operational activities that can be automated.
- Develop and maintain automation for server, endpoint, identity, and operational tasks.
- Support Infrastructure as Code (IaC) practices to standardize infrastructure deployment and configuration.
- Work with automation and scripting technologies appropriate to the Microsoft infrastructure environment.
- Support CI/CD and infrastructure automation using GitHub and/or Azure