Windows Systems Engineer

Socket.dev

Pleasanton (CA)

On-site

USD 175,000 - 195,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health Coverage
FSA Health and Dependent Care
401(k) Plan
Unlimited PTO
Holidays Paid
Cell Phone Allowance
Collaborative culture

Job summary

STN is seeking a Systems Engineer to own the day-to-day health, security, and lifecycle of Windows Server, Active Directory, and Microsoft 365 environments for managed-services customers. You will implement upgrades, manage DNS/DHCP, and maintain identity and access controls.

Responsibilities include writing PowerShell automation, patch cadence, backup validation, and supporting MFA/Conditional Access. Strong documentation and multi-customer communication are essential.

Qualifications

  • 5+ years hands-on with Windows Server and Active Directory, DNS, DHCP, and Group Policy.
  • Ability to run domain controller promotions or upgrades from a documented plan.
  • Certificate management experience: AD CS or PKI lifecycle and renewals.
  • PowerShell proficiency and automation depth (or Python/Ansible/Terraform).
  • Strong patch management and endpoint security experience including MFA/CA.
  • Experience with PCI and/or HIPAA regulated environments and change control.
  • Microsoft 365 and Entra ID administration including Exchange Online.
  • Backup/restore operations with Cohesity or Veeam understanding.

Responsibilities

  • Administer Windows Servers across multi-customer environments (DNS/DHCP/GP).
  • Plan and execute Active Directory upgrades from a documented plan.
  • Develop PowerShell scripts for provisioning, reporting, and remediation.
  • Manage Microsoft 365 and Entra ID including Exchange Online and CA policies.
  • Own patch cadence, endpoint protection, and vulnerability remediation.
  • Support MFA rollout, identity hygiene, and access reviews.

Skills

Windows Server
Active Directory
PowerShell
VMware vSphere/Hyper-V
Microsoft 365/Entra ID
Security & patch hygiene
Documentation

Education

Bachelor’s degree in IT/CS

Tools

PowerShell
Cohesity/Veeam
VMware vSphere
NinjaOne/Datto (RMM)

Job description

The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers.
Key Responsibilities
  • Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services

  • Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan

  • Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation

  • Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy

  • Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines

  • Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews

  • Monitor backup and replication jobs, run and evidence test restores, and escalation failures against RPO and RTO commitments

  • Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning

  • Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows

  • Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks

  • Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation

  • Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current

  • Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines

Experience & Qualifications

Required

  • 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration

  • Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback

  • Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate

  • PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell

  • Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it

  • Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require

  • Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access

  • Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product

  • Hands‑on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management

  • Clear written communication and documentation habits suited to a multi-customer environment

  • Bachelor's degree in information technology, computer science, or equivalent experience

Preferred

  • Experience in an MSP, MSSP, or multi‑tenant hosting environment supporting several customers concurrently

  • Azure IaaS or Azure Virtual Desktop experience alongside on‑premises virtualization

  • Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto

  • Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365

  • Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow

  • Hybrid identity experience including Entra Connect, tenant‑to‑tenant migrations, and Windows Server 2022/2025 upgrade cycles

  • Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting

  • Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE

Compensation
  • Full-Time, Exempt

  • $175,000-$195,000/year, DOE

Benefits
  • Health Coverage – Medical, Dental & Vision

  • FSA Health and Dependent Care available

  • 401(k) Plan

  • Unlimited Paid Time Off (PTO)

  • Observed Holidays Paid

  • Cell Phone Allowance

  • Collaborative, growth-driven culture

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Windows Systems Engineer
Windows Systems Engineer

STN Inc • Pleasanton (CA)

On-site
USD 175,000 - 195,000
Health Coverage – Medical, Dental &amp
Vision
Windows Systems Engineer (MTS)
Windows Systems Engineer (MTS)

STN Incorporated • Pleasanton (CA)

On-site
USD 175,000 - 195,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
+3
Windows Systems Engineer (MTS)
Windows Systems Engineer (MTS)

STN, Inc. • Pleasanton (CA), Northern (KY)

Hybrid
USD 175,000 - 195,000
Health Coverage – Medical, Dental & V​
401(k) Plan
Unlimited Paid Time Off
+2
Senior Manager, Systems, Network, & MSP Service Desk Operations
Senior Manager, Systems, Network, & MSP Service Desk Operations

STN Inc • Pleasanton (CA)

On-site
USD 180,000 - 240,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
+3
Senior Manager, Systems, Network & MSP Service Desk Operations
Senior Manager, Systems, Network & MSP Service Desk Operations

STN, Inc. • Pleasanton (CA)

On-site
USD 180,000 - 240,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
Microsoft Systems Engineer
Microsoft Systems Engineer

CTC Technologies, Inc. • Ann Arbor (MI)

Hybrid
USD 85,000 - 110,000
Health, dental, and vision insurance
401K plan
Paid time off
Systems Administrator
Systems Administrator

Tecolote • Chantilly (VA)

On-site
USD 55,000 - 75,000
Health Insurance
Retirement Plan
Employee Stock Ownership Plan
+2
Systems Administrator
Systems Administrator

Tecolote • Arlington (VA)

On-site
USD 55,000 - 75,000
Major Medical Insurance
Dental Insurance
Vision Insurance
+6
Systems Engineer / System Administrator for Managed Service Provider
Systems Engineer / System Administrator for Managed Service Provider

Straightedgetech • Corpus Christi (TX)

On-site
USD 65,000 - 90,000
Competitive Pay
Company subsidized medical, dental and
vision insurance
Managed Services Systems Lead
Managed Services Systems Lead

Carrieraccessit • Clive (IA)

On-site
USD 110,000 - 160,000
Medical, dental, and vision insurance
401(k) retirement plan with company 
匹
Professional development and training
+1