Descrição do cargo
What You'll Be Doing
As a Senior Windows Systems Administrator, you'll play a key role in designing, maintaining, and securing enterprise Windows infrastructure while driving automation and operational excellence.
Identity & Active Directory
- Administer and maintain large-scale, multi-domain Active Directory environments, including Domain Controllers, Organizational Units, Group Policy Objects (GPOs), trusts, DNS integration, and security groups.
- Design and manage identity lifecycle processes, including automated Joiner, Mover, and Leaver (JML) workflows.
- Implement and maintain security best practices using LAPS, Group Policy, and Active Directory hardening.
Privileged Access & Security
- Administer Privileged Access Management (PAM) platforms, including privileged account onboarding, vault administration, credential lifecycle management, and secure authentication integration.
- Manage enterprise Public Key Infrastructure (PKI) and Windows Certificate Services, including certificate issuance, renewal, automation, and SSL/TLS lifecycle management.
- Implement Windows Server hardening aligned with recognized security standards such as:
- CIS Benchmarks
- NIST
- ANSSI
- Microsoft Security Baselines
- PingCastle recommendations
- Support vulnerability remediation and security compliance initiatives across enterprise infrastructure.
Infrastructure Automation
- Develop automation using PowerShell and Infrastructure as Code (IaC) tools to simplify administration, improve consistency, and reduce manual operations.
- Contribute to infrastructure provisioning and configuration management using tools such as Terraform and Ansible.
- Automate operational workflows, reporting, patching, and infrastructure maintenance.
Windows Infrastructure Operations
- Administer Windows Server 2019/2022 environments, including clustering, failover services, and enterprise server infrastructure.
- Manage operating system patching and software deployment using enterprise management platforms.
- Coordinate emergency patching activities while maintaining high service availability.
- Support secure remote administration through technologies such as Remote Desktop Services, Network Level Authentication (NLA), Just-In-Time (JIT) administration, and VPN integration.
Monitoring & Operational Excellence
- Monitor infrastructure health, capacity, availability, and performance using centralized monitoring and observability platforms.
- Perform proactive capacity planning and identify opportunities to improve reliability and operational efficiency.
- Support disaster recovery planning, backup validation, failover testing, and business continuity exercises.
- Produce and maintain high-quality technical documentation, operational procedures, and infrastructure standards.
Collaboration
- Work closely with Infrastructure, Security, Networking, Identity & Access Management, DevOps, and Operations teams to deliver secure and scalable infrastructure solutions.
- Participate in Change Advisory Boards (CAB), incident management, root cause analysis, and continuous service improvement initiatives.
- Contribute to architecture discussions, modernization projects, and cloud transformation initiatives.
What We're Looking For
Required Experience
- 5+ years of experience administering enterprise Windows Server environments.
- Extensive experience managing:
- Windows Server 2019/2022
- Active Directory
- Group Policy (GPO)
- Multi-domain environments
- DNS
- Windows Clustering
- Strong experience with enterprise security and identity management.
- Hands‑on experience with PowerShell automation.
- Experience implementing Infrastructure as Code using Terraform, Ansible, or similar automation tools.
- Strong knowledge of Windows security hardening, vulnerability management, and compliance.
- Experience with enterprise patch management and software deployment platforms.
- Good understanding of networking fundamentals, including:
- TCP/IP
- DNS
- VPN
- Active Directory Sites & Services
- Experience supporting production environments with structured incident, change, and problem management processes.
Technical Stack
Infrastructure
- Windows Server 2019 / 2022
- Active Directory
- Group Policy (GPO)
- LAPS
- DNS
- PKI
- Windows Certificate Services
- SSL/TLS
- Windows Clustering
Security
- Privileged Access Management (PAM)
- CyberArk
- Password Manager Plus
- CIS Benchmarks
- NIST
- ANSSI
- PingCastle
- Audit & Compliance
- Vulnerability Management
Automation
- PowerShell
- Terraform
- Ansible
- YAML
- Python (nice to have)
Infrastructure Management
- WSUS
- SCCM
- Patch Manager Plus
- Ivanti
- Remote Desktop Services
- NLA
- JIT Administration
Monitoring & Observability
- LogicMonitor
- WhatsUP Gold
- PagerDuty
- Coralogix
- Azure Log Analytics
Virtualization
- Citrix (Application Publishing & VDI)
Nice to Have
- Experience with Git version control.
- Familiarity with AI-assisted scripting tools such as Microsoft Copilot.
- Experience with enterprise Citrix environments.
- Experience working in highly regulated industries such as financial services, banking, healthcare, telecommunications, or critical infrastructure.
- Relevant certifications, including:
- Microsoft Certified: Windows Server Hybrid Administrator
- CompTIA Security+
- CyberArk Certified Implementation Specialist