Senior Microsoft Systems Administrator

Gdh Consulting, Inc.

Montgomery (AL)

On-site

USD 110,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401(k) plan
Wellbeats membership
Discount gym membership

Job summary

GDH, a premier staffing and talent solutions company, seeks a Senior Microsoft Systems Administrator in Montgomery, AL to lead security hardening of Windows Server environments in alignment with NIST SP 800-53 controls. The role emphasizes GPOs, Intune, SCCM/MECM, and Defender for Endpoint in hybrid/cloud settings.

You will implement access controls, configuration baselines, MFA, and privilege management while documenting SSPs and POA&Ms; strong PowerShell scripting is required to automate

Qualifications

  • Minimum of 4 years hands-on experience managing Windows servers and workstations within enterprise environments.
  • Proficiency with Microsoft administration tools such as Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, and Defender for Endpoint.
  • Strong scripting skills, particularly with PowerShell, to automate compliance processes and security tasks.

Responsibilities

  • Install, configure, harden, patch, and maintain Windows Server (2019/2022+) and Windows 10/11 workstations according to NIST SP 800-53 Rev. 5 controls.
  • Implement and validate security controls across various families including Access Control, Configuration Management, Identification & Authentication, Audit & Accountability, and System & Communications Protection for endpoints and servers.
  • Manage Group Policy Objects (GPOs), security baselines, and Intune/Microsoft Endpoint Manager policies to enforce NIST-aligned configurations such as password policies, account lockout, least privilege, firewall rules, AppLocker, and BitLocker.
  • Perform system hardening tasks by enforcing deny-by-default policies, configuring host-based firewalls and intrusion detection/prevention systems, implementing multi-factor authentication, managing privileged accounts, and enabling cryptographic protections for data at rest and in transit.
  • Remove unnecessary services, features, and default accounts to enhance security measures.
  • Administer Microsoft security and compliance tools, including Active Directory, Microsoft Endpoint Configuration Manager (SCCM/MECM), Microsoft Intune, Azure AD/Entra ID, Defender for Endpoint, and Azure Policy for hybrid/cloud environments.
  • Document security plans (SSP), control implementation procedures, Plan of Action & Milestones (POA&Ms), and maintain evidence for NIST 800-53 controls throughout project execution.
  • Develop PowerShell scripts to automate compliance checks, security configurations, and reporting activities.

Skills

Windows Server
PowerShell
Group Policy (GPOs)
Intune/MECM
Azure AD/Entra ID
Defender for Endpoint
SCCM/MECM
NIST SP 800-53 controls
Active Directory
Security hardening

Tools

SCCM/MECM
Intune
Azure Policy
Nessus/Tenable

Job description

Role Summary

A Senior Microsoft Systems Administrator is responsible for leading efforts to enhance the security posture of Windows servers and workstations through comprehensive implementation of NIST SP 800-53 security controls. This role involves configuring, hardening, and maintaining Microsoft environments in alignment with cybersecurity standards, ensuring ongoing compliance and security. It is a senior-level position suited for candidates with extensive experience in Microsoft systems administration and security best practices.

Responsibilities
  • Install, configure, harden, patch, and maintain Windows Server (2019/2022+) and Windows 10/11 workstations according to NIST SP 800-53 Rev. 5 controls.
  • Implement and validate security controls across various families including Access Control, Configuration Management, Identification & Authentication, Audit & Accountability, and System & Communications Protection for endpoints and servers.
  • Manage Group Policy Objects (GPOs), security baselines, and Intune/Microsoft Endpoint Manager policies to enforce NIST-aligned configurations such as password policies, account lockout, least privilege, firewall rules, AppLocker, and BitLocker.
  • Perform system hardening tasks by enforcing deny-by-default policies, configuring host-based firewalls and intrusion detection/prevention systems, implementing multi-factor authentication, managing privileged accounts, and enabling cryptographic protections for data at rest and in transit.
  • Remove unnecessary services, features, and default accounts to enhance security measures.
  • Administer Microsoft security and compliance tools, including Active Directory, Microsoft Endpoint Configuration Manager (SCCM/MECM), Microsoft Intune, Azure AD/Entra ID, Defender for Endpoint, and Azure Policy for hybrid/cloud environments.
  • Document security plans (SSP), control implementation procedures, Plan of Action & Milestones (POA&Ms), and maintain evidence for NIST 800-53 controls throughout project execution.
  • Develop PowerShell scripts to automate compliance checks, security configurations, and reporting activities.
Qualifications
  • Minimum of 4 years of hands‑on experience managing Windows servers and workstations within enterprise environments.
  • Proven experience in implementing NIST SP 800-53 security controls on Microsoft platforms.
  • Proficiency with Microsoft administration tools such as Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, and Defender for Endpoint.
  • Strong understanding of NIST 800-53 control families, including Access Control, Audit & Accountability, Configuration Management, Identification & Authentication, and System & Communications Protection.
  • Extensive experience with system hardening techniques, baseline configuration management, and least privilege security principles.
  • Familiarity with vulnerability management and compliance tools such as Nessus/Tenable or similar solutions.
  • Strong scripting skills, particularly with PowerShell, to automate compliance processes and security tasks.
  • This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required.
Pay Range

Publishing Pay Range: $110,000.00 - $130,000.00 Annually

Location

This position is based in the office and requires employee to work on‑site.

About GDH

At GDH, we believe in the power of people and the importance of caring. Our culture statement, "We care about people," isn't just a tagline - it's the core of everything we do. GDH is a premier staffing and talent solutions company dedicated to helping businesses find the best talent and assisting job seekers in finding their dream jobs. Who We Are: GDH, founded in 2001, has grown into a leader in providing staffing solutions across various industries. We specialize in IT across several sectors, connecting top talent with leading enterprises. As a Best of Staffing firm recognized for excellence in client, employee, talent, and women's services, we pride ourselves on our commitment to quality and service.

GDH Benefits
  • Our health benefits include three medical insurance options with access to KISx Card, Zero Card, and HealthJoy concierge services.
  • Other plan offerings include dental, vision, life, disability, supplemental insurance, and pet insurance plans.
  • Enjoy additional perks like holiday pay, 401(k) plan, direct deposit, an employee referral program, work‑life balance benefits, a Wellbeats membership, a discounted gym membership program, and more!
  • For more detailed information on benefits, please go to GDH's website under the tab for candidates.
Equal Employment Opportunity

GDH provides equal employment opportunities (EEO) to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, gender, sex (including pregnancy), sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, ancestry, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable federal, state, and local laws.

Disability Accommodation

Applicants with disabilities who require an accommodation or assistance in applying and/or for interviewing, please contact our HR Department.

Notice of Collection

Please visit our notice of collection for California applicants.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Services Manager
Network Services Manager

Gdh Consulting, Inc. • Washington

Hybrid
USD 83,000 - 90,000
Health benefits
401(k) plan
Wellness programs
Threat Implementation Engineer
Threat Implementation Engineer

Gdh Consulting, Inc. • Dallas (TX)

On-site
USD 62,000 - 65,000
Perimeter Implementation Engineer
Perimeter Implementation Engineer

Gdh Consulting, Inc. • Dallas (TX)

On-site
USD 62,000 - 65,000
Medical options
Dental & Vision
Wellbeats membership
+1
Microsoft Systems Administrator, Senior
Microsoft Systems Administrator, Senior

Gilder Search Group • Montgomery (AL)

On-site
USD 85,000 - 120,000
Health Insurance
401(k) Plan with Employer Match
Paid Time Off
DevOps Engineer
DevOps Engineer

Gdh Consulting, Inc. • Ellicott City (MD)

On-site
USD 69,000 - 76,000
Medical insurance options
401(k) plan
Wellbeats membership
+1
IAM Security Analyst
IAM Security Analyst

Gdh Consulting, Inc. • Little Rock (AR)

On-site
USD 41,000 - 45,000
Health benefits
401(k)
Remote work flexibility
Project Manager I - Engineering Operations
Project Manager I - Engineering Operations

Gdh Consulting, Inc. • Greenwood Village (CO)

Hybrid
USD 48,000 - 55,000
Health benefits
401(k)
Wellbeats membership
+1
Network Engineer
Network Engineer

Gdh Consulting, Inc. • Rancho Cordova (CA)

On-site
USD 171,924,000 - 197,713,000
Health insurance
Wellbeats membership
Gym membership discount
+2
Senior Enviromental Engineer
Senior Enviromental Engineer

Gdh Consulting, Inc. • Mont Belvieu (TX)

On-site
USD 130,000 - 132,000
Health insurance options
Three medical insurance options with K
KISx Card
+8
Network Engineer
Network Engineer

Gdh Consulting, Inc. • Overland Park (KS)

Hybrid
USD 94,000 - 104,000
Health insurance
401(k) plan
Wellbeats membership
+1