Sr. Windows Systems Administrator

Astrion

Columbia (MD)

On-site

USD 145,000 - 165,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Astrion is seeking a Senior Windows Systems Administrator in Columbia, MD to build, secure, and sustain the Windows Server estate and AD services across multiple classified networks. The role requires on-site work Monday through Friday and a TS/SCI clearance.

The candidate will manage Windows Server 2016–2022, Windows 11 workstations, and RMF-compliant configurations within air-gapped enclaves, coordinating with cyber, network, and mission stakeholders.

Qualifications

  • Active TS/SCI security clearance required.
  • Bachelor's degree in CS/IT or related field (or equivalent experience).
  • 8+ years of Windows systems and network administration in DoD/DoW or classified environments.
  • Deep Windows Server administration (2016–2022) and AD DS expertise.
  • Scripting and automation with PowerShell.

Responsibilities

  • Administer, patch, and sustain Windows Server and Windows 11 workstations across three or more isolated classified networks.
  • Provide end-user support for classified Windows Server and Windows 11 workstations; troubleshoot issues.
  • Administer Active Directory Domain Services per enclave: GPO, DNS, DHCP, DFS, ADCS, sites and replication.
  • Build, harden, baseline Windows systems to DoD STIGs; remediate findings and drift.
  • Manage workstation fleet with MECM, image deployment, app packaging, and GPO.

Skills

Windows Server Admin
Active Directory
PowerShell
RMF/STIG
Air-gap patching

Education

Bachelor's degree in CS/IT or related field

Tools

MECM
WSUS

Job description

Overview

Senior Windows Systems Administrator

LOCATION: Columbia, MD (Onsite)

JOB STATUS: Full-time

CLEARANCE: Active Top Secret / TS/SCI (Required)

TRAVEL: Less than 10%

SALARY RANGE: $145k - $165k

Astrion has an exciting opportunity for a highly experienced Senior Windows Administrator to build, secure, and sustain the Windows Server estate, the Windows 11 workstation fleet, and the Active Directory and Windows network services that run across three or more isolated classified networks supporting Department of Defense/Department of War (DoD/DoW) environments in Columbia, MD. The ideal candidate brings deep Windows Server and Active Directory expertise, extensive experience operating inside closed and air-gapped classified enclaves, and a proven record of building and maintaining systems in compliance with Risk Management Framework (RMF), DoD STIG, and Comply-to-Connect (C2C) requirements. This position requires Monday through Friday on-site work at our facility in Columbia, MD.

REQUIRED QUALIFICATIONS / SKILLS

  • Active TS/SCI security clearance (required)
  • Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience)
  • 8+ years of Windows systems and network administration experience within DoD/DoW or classified environments
  • Deep expertise in:
    • Windows Server administration (2016 through 2022): installation, patching, performance tuning, roles and features, storage, and networking
    • Active Directory Domain Services: Group Policy, DNS, DHCP, DFS, ADCS, sites and replication, and trusts
    • Scripting and automation (PowerShell and desired-state configuration)
    • Windows endpoint management (Microsoft Endpoint Configuration Manager, imaging, Group Policy)
    • End-user support on Classified Windows 11 and Windows Server supporting Operating System, supported applications, and hardware issues
  • Demonstrated experience implementing and maintaining DoD STIG compliance on Windows Server and workstations
  • Experience with offline and air-gapped patching (WSUS or MECM in an isolated enclave)
  • Strong understanding of:
    • RMF (Risk Management Framework)
    • DISA security requirements and accreditation processes
    • DCSA accreditation standards
  • Active DoD 8140 (formerly DoD 8570) compliant baseline certification (e.g., Security+ CE, CISSP)
  • Active DoD 8140 compliant computing environment certification (e.g., minimum Microsoft certification such as Windows Server Hybrid Administrator Associate or MCSA/MCSE equivalent)
  • Experience with:
    • ACAS or Nessus and SCAP scanning
    • SIEM integration and Windows event and log analysis
    • Continuous monitoring under RMF

KEY COMPETENCIES

  • Advanced Windows Server and Active Directory administration and troubleshooting
  • Security hardening and compliance enforcement
  • Automation and scripting (PowerShell)
  • Strong troubleshooting skills used in end-user support
  • Strong analytical and problem-solving abilities
  • Excellent communication and documentation skills
  • Ability to operate in high-security, mission-critical environments

PREFERRED QUALIFICATIONS / SKILLS

  • On-Premise deployment and administration of Microsoft SharePoint environments
  • Microsoft certifications such as Windows Server Hybrid Administrator Associate, Azure Administrator (AZ-104), or Identity and Access Administrator
  • Hyper-V and Windows Failover Clustering, and storage experience (NetApp or SAN)
  • PKI and Active Directory Certificate Services design and administration
  • PowerShell automation at scale (desired-state configuration, Git-based configuration management)
  • Zero Trust architectures and application allowlisting (AppLocker or WDAC) in classified environments
  • Prior experience supporting Cross Domain Solutions (CDS) programs
  • Experience with cloud-based DoD environments (e.g., Azure Government, Azure Secret)
  • Project management experience and experience briefing executive leadership

RESPONSIBILITIES

  • Administer, patch, and sustain Windows Server (2016 through 2022) and Windows 11 workstations across three or more isolated classified networks, each operated as its own authorization boundary
  • Provide end-user support for classified Windows Server and Windows 11 workstations to include troubleshooting supported applications, hardware, and operating system issues.
  • Administer Active Directory Domain Services across a separate forest per enclave: Group Policy, DNS, DHCP, DFS, Active Directory Certificate Services, sites and replication, and trust health
  • Build, harden, and baseline Windows systems to DoD Security Technical Implementation Guides (STIGs); remediate findings and control configuration drift
  • Manage the Windows workstation fleet with Microsoft Endpoint Configuration Manager (MECM), image build and deployment (MDT/WDS), application packaging, and Group Policy on closed networks
  • Perform patching and updates on air-gapped networks through approved offline processes (WSUS in an isolated enclave, MECM, or trusted media transfer), with a defined cadence and an emergency-patch path
  • Administer Windows network services: DNS, DHCP, name resolution, time synchronization, PKI and certificate services, and Windows Firewall with IPsec policy
  • Administer virtualization and clustering where present (Hyper-V, Windows Failover Clustering), including capacity planning and recovery testing
  • Automate provisioning, configuration, and remediation with PowerShell and desired-state configuration, including on disconnected systems
  • Administer host-based endpoint protection (Microsoft Defender for Endpoint or approved ESS) and integrate with the security tool stack
  • Implement and maintain C2C and 802.1x posture for Windows endpoints
  • Perform vulnerability remediation and continuous monitoring in accordance with RMF controls; run and interpret ACAS and SCAP scans and review Windows event and audit logs
  • Support the Authority to Operate (ATO) process, including STIG checklists, POA&Ms, and risk assessments
  • Maintain backup and recovery for Windows systems and Active Directory, including system state and authoritative and non-authoritative restore
  • Develop and maintain system documentation, diagrams, SOPs, and security artifacts
  • Troubleshoot complex issues across multi-network, multi-vendor environments
  • Collaborate with cybersecurity, network engineering, systems engineering, and mission stakeholders to ensure secure, reliable operations
  • Support audits, inspections, and compliance validation activities
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Linux Systems Administrator
Sr. Linux Systems Administrator

Astrion • Columbia (MD)

On-site
USD 145,000 - 165,000
Senior System Administrator
Senior System Administrator

Omniscius Consulting • Laurel (MD)

On-site
USD 100,000 - 130,000
Sr. Network Engineer
Sr. Network Engineer

Astrion • Columbia (MD)

On-site
USD 145,000 - 165,000
Lead Windows Systems Administrator - Active Top Secret
Lead Windows Systems Administrator - Active Top Secret

The One 23 Group • Herndon (VA)

On-site
USD 100,000 - 130,000
Systems Administrator [D.26.0139]
Systems Administrator [D.26.0139]

Dover Networks LLC • Maryland

On-site
USD 189,000 - 207,000
Senior Windows Systems Administrator — Classified Networks (TS/SCI)
Senior Windows Systems Administrator — Classified Networks (TS/SCI)

Astrion • Columbia (MD)

On-site
USD 145,000 - 165,000
System Engineer (TS/SCI)- Senior or Mid Level
System Engineer (TS/SCI)- Senior or Mid Level

Vexterra Group • Bethesda (MD)

On-site
USD 90,000 - 120,000
Windows Systems Administrator Team Lead
Windows Systems Administrator Team Lead

Integrated Computer Solutions, Inc. • Arlington (VA)

On-site
USD 110,000 - 130,000
Windows System Administrator, Mid-Level Washington, DC 8/27/2026
Windows System Administrator, Mid-Level Washington, DC 8/27/2026

HRB • Washington, Northern (KY)

Hybrid
USD 85,000 - 125,000
Medical, Dental, & Vision Plan
Short- and long-term disability
Accidental death & dismemberment
+5
Senior Windows Systems Administrator
Senior Windows Systems Administrator

Caelum Research Corporation • Aberdeen (MD)

On-site
USD 90,000 - 135,000
401(k)
Health insurance
Tuition reimbursement
+1