Windows Systems Engineer

STN Inc

Pleasanton (CA)

On-site

USD 175,000 - 195,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health Coverage – Medical, Dental &amp
Vision

Job summary

STN Inc. seeks a Systems Engineer to own day-to-day health, security, and lifecycle of Windows Server, Active Directory, and Microsoft 365 for managed-services customers.

You will administer servers, AD upgrades, and certificate lifecycle, author PowerShell automation, and manage 365/Entra ID including Exchange Online. Strong patching discipline and multi-customer communication are key.

Qualifications

  • 5+ years hands-on with Windows Server and Active Directory.
  • Experience with DNS, DHCP, and Group Policy administration.
  • Ability to script with PowerShell and automate tasks.
  • Experience with PKI, AD CS, or certificate lifecycle.
  • Knowledge of security, patching, MFA, and CA concepts.
  • Experience with PCI/HIPAA regulated environments.
  • Microsoft 365 and Entra ID administration including Exchange Online.
  • Virtualization experience with VMware vSphere or Hyper-V.

Responsibilities

  • Administer Windows Server environments across multiple customer sites.
  • Plan and execute Active Directory domain upgrades and topology changes.
  • Develop and maintain PowerShell scripts for provisioning and automation.
  • Manage Microsoft 365, Entra ID, and Exchange Online configurations.
  • Own patch cadence and endpoint protection, address vulnerabilities.
  • Support MFA/Conditional Access rollouts and identity hygiene.
  • Monitor backups and run test restores, ensure RPO/RTO targets.
  • Maintain runbooks and documentation for multi-customer environments.
  • Act as L3 escalation point for service desk and drive root-cause analysis.

Skills

Windows Server
Active Directory
DNS/DHCP
Group Policy
PowerShell
Security & patching
Microsoft 365
VMware/Hyper-V

Education

Bachelor's degree in IT

Tools

Cohesity
Veeam
Intune
SCCM/MECM
NinjaOne
Datto
Nessus
Qualys

Job description

The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers.
Key Responsibilities
  • Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services

  • Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan

  • Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation

  • Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy

  • Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines

  • Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews

  • Monitor backup and replication jobs, run and evidence test restores, and escalation failures against RPO and RTO commitments

  • Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning

  • Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows

  • Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks

  • Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation

  • Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current

  • Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines

Experience & Qualifications

Required

  • 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration

  • Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback

  • Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate

  • PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell

  • Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it

  • Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require

  • Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access

  • Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product

  • Hands‑on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management

  • Clear written communication and documentation habits suited to a multi-customer environment

  • Bachelor's degree in information technology, computer science, or equivalent experience

Preferred

  • Experience in an MSP, MSSP, or multi‑tenant hosting environment supporting several customers concurrently

  • Azure IaaS or Azure Virtual Desktop experience alongside on‑premises virtualization

  • Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto

  • Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365

  • Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow

  • Hybrid identity experience including Entra Connect, tenant‑to‑tenant migrations, and Windows Server 2022/2025 upgrade cycles

  • Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting

  • Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE

Compensation
  • Full-Time, Exempt

  • $175,000-$195,000/year, DOE

Benefits
  • Health Coverage – Medical, Dental & Vision

  • FSA Health and Dependent Care available

  • 401(k) Plan

  • Unlimited Paid Time Off (PTO)

  • Observed Holidays Paid

  • Cell Phone Allowance

  • Collaborative, growth-driven culture

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Windows Systems Engineer
Windows Systems Engineer

Socket.dev • Pleasanton (CA)

On-site
USD 175,000 - 195,000
Health Coverage
FSA Health and Dependent Care
401(k) Plan
+4
Windows Systems Engineer (MTS)
Windows Systems Engineer (MTS)

STN Incorporated • Pleasanton (CA)

On-site
USD 175,000 - 195,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
+3
Windows Systems Engineer (MTS)
Windows Systems Engineer (MTS)

STN, Inc. • Pleasanton (CA), Northern (KY)

Hybrid
USD 175,000 - 195,000
Health Coverage – Medical, Dental & V​
401(k) Plan
Unlimited Paid Time Off
+2
Senior Manager, Systems, Network, & MSP Service Desk Operations
Senior Manager, Systems, Network, & MSP Service Desk Operations

STN Inc • Pleasanton (CA)

On-site
USD 180,000 - 240,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
+3
Senior Manager, Systems, Network & MSP Service Desk Operations
Senior Manager, Systems, Network & MSP Service Desk Operations

STN, Inc. • Pleasanton (CA)

On-site
USD 180,000 - 240,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
Microsoft Systems Engineer
Microsoft Systems Engineer

CTC Technologies, Inc. • Ann Arbor (MI)

Hybrid
USD 85,000 - 110,000
Health, dental, and vision insurance
401K plan
Paid time off
Systems Administrator
Systems Administrator

Tecolote • Chantilly (VA)

On-site
USD 55,000 - 75,000
Health Insurance
Retirement Plan
Employee Stock Ownership Plan
+2
Systems Administrator
Systems Administrator

Tecolote • Arlington (VA)

On-site
USD 55,000 - 75,000
Major Medical Insurance
Dental Insurance
Vision Insurance
+6
Systems Engineer / System Administrator for Managed Service Provider
Systems Engineer / System Administrator for Managed Service Provider

Straightedgetech • Corpus Christi (TX)

On-site
USD 65,000 - 90,000
Competitive Pay
Company subsidized medical, dental and
vision insurance
Systems Engineer / System Administrator for Managed Service Provider
Systems Engineer / System Administrator for Managed Service Provider

Socket.dev • San Antonio (TX)

On-site
USD 70,000 - 110,000
Competitive Pay
Medical, dental, vision insurance
PTO
+3