Windows Systems Engineer (MTS)

STN Incorporated

Pleasanton (CA)

Hybrid

USD 175,000 - 195,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
Observed Holidays Paid
Cell Phone Allowance
Collaborative culture

Job summary

STN Incorporated is hiring a Windows Systems Engineer (MTS) to maintain Windows Server, AD, and M365 environments for managed-service customers. The role emphasizes security, patching, and automation, with hybrid work in Pleasanton, CA.

You’ll collaborate with the Sr Manager – Service Desk, NOC/SOC, and multi-customer teams. The ideal candidate has 5+ years in Windows Server/AD, strong PowerShell skills, and experience with PCI/HIPAA environments.

Qualifications

  • 5+ years hands-on with Windows Server and Active Directory, DNS, DHCP, and GP administration.
  • PowerShell proficiency for automation and scripting; equivalent depth with Python/Ansible/Terraform considered.
  • Experience with PCI- and HIPAA-regulated environments and change control.

Responsibilities

  • Administer Windows Servers across multiple customer environments and services.
  • Execute AD work including domain controller upgrades from documented plans.
  • Write and maintain PowerShell scripts for provisioning and automation.
  • Administer Microsoft 365 and Entra ID; manage Exchange Online and mail flow.
  • Maintain patch cadence and endpoint protection; respond to vuln findings.
  • Support MFA and Conditional Access rollouts; manage identity hygiene.
  • Monitor backups and run restore tests; ensure RPO/RTO adherence.
  • Manage virtualization with VMware vSphere/Hyper-V and cloud IaaS.
  • Act as L3 escalation for service desk and drive root-cause analysis.

Skills

Windows Server
Active Directory
DNS
DHCP
Group Policy
PowerShell
MFA / Conditional Access
Microsoft 365
Entra ID
VMware vSphere / Hyper-V

Education

Bachelor's degree in IT / CS

Tools

Cohesity
Veeam
Intune
SCCM/MECM
NinjaOne
Datto

Job description

Windows Systems Engineer (MTS)

Location: Hybrid - Pleasanton, CA

Reporting to: Sr Manager – Service Desk, NOC/SOC, Systems & Network Administration

At STN, we don't just adapt to the digital future, we engineer it. Our mission is to help organizations thrive in a rapidly evolving technology landscape through strategic insight, cutting-edge solutions, and a security-first mindset. We provide end-to-end services spanning cloud consulting, AI infrastructure, and enterprise security, enabling secure, scalable, and future-ready transformation.

As trusted advisors, we align IT investments with business outcomes that drive performance and growth, starting with deep strategic engagement and delivering tailored solutions built for long-term impact.

Our approach is innovation-led and rooted in cybersecurity, with a focus on leveraging the right technologies to solve real-world challenges. We invest in our people and foster a culture of growth, inclusion, and purpose because we believe empowered teams build transformative technology.

The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers.
Key Responsibilities
  • Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services
  • Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan
  • Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation
  • Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy
  • Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines
  • Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews
  • Monitor backup and replication jobs, run and evidence test restores, and elevate failures against RPO and RTO commitments
  • Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning
  • Operate the VMware vSphere or Hyper‑V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows
  • Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks
  • Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation
  • Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current
  • Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines
Experience & Qualifications

Required

  • 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration
  • Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback
  • Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate
  • PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell
  • Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it
  • Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require
  • Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access
  • Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product
  • Hands‑on virtualization experience with VMware vSphere or Hyper‑V, including host and cluster operations, VM provisioning, snapshots, and resource management
  • Clear written communication and documentation habits suited to a multi-customer environment
  • Bachelor's degree in information technology, computer science, or equivalent experience

Preferred

  • Experience in an MSP, MSSP, or multi-tenant hosting environment supporting several customers concurrently
  • Azure IaaS or Azure Virtual Desktop experience alongside on‑premises virtualization
  • Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto
  • Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365
  • Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow
  • Hybrid identity experience including Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles
  • Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting
  • Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE
Compensation
  • Full-Time, Exempt
  • $175,000-$195,000/year, DOE
Benefits
  • Health Coverage – Medical, Dental & Vision
  • FSA Health and Dependent Care available
  • 401(k) Plan
  • Unlimited Paid Time Off (PTO)
  • Observed Holidays Paid
  • Cell Phone Allowance
  • Collaborative, growth-driven culture

Candidates must be U.S. Citizens or Permanent Residents. We are unable to provide sponsorship at this time.

Employment is contingent upon the successful completion of a background check and reference verification. All applicants must be authorized to work in the United States on a full-time basis.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Systems, Network & MSP Service Desk Operations
Senior Manager, Systems, Network & MSP Service Desk Operations

STN Incorporated • Pleasanton (CA)

On-site
USD 180,000 - 240,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
+2
Senior Manager, Systems, Network & MSP Service Desk Operations
Senior Manager, Systems, Network & MSP Service Desk Operations

STN, Inc. • Pleasanton (CA)

On-site
USD 180,000 - 240,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
Senior Manager, Systems, Network, & MSP Service Desk Operations
Senior Manager, Systems, Network, & MSP Service Desk Operations

STN Inc • Pleasanton (CA)

On-site
USD 180,000 - 240,000
Health Coverage – Medical, Dental &amp
401(k) Plan
Unlimited PTO
+3
Systems Engineer / System Administrator for Managed Service Provider
Systems Engineer / System Administrator for Managed Service Provider

Straightedgetech • San Antonio (TX)

On-site
USD 70,000 - 90,000
Competitive Pay
Company subsidized medical, dental and vision insurance
PTO
+3
Systems Engineer / System Administrator for Managed Service Provider
Systems Engineer / System Administrator for Managed Service Provider

Straight Edge Technology, Inc. • Corpus Christi (TX)

On-site
USD 55,000 - 85,000
Competitive Pay
Company subsidized medical, dental and
Vision insurance
+4
Microsoft Systems Engineer
Microsoft Systems Engineer

CTC Technologies, Inc. • Ann Arbor (MI)

Hybrid
USD 85,000 - 110,000
Health, dental, and vision insurance
401K plan
Paid time off
Systems Engineer / System Administrator for Managed Service Provider
Systems Engineer / System Administrator for Managed Service Provider

Straightedgetech • Corpus Christi (TX)

On-site
USD 65,000 - 90,000
Competitive Pay
Company subsidized medical, dental and
vision insurance
Managed Services Systems Lead
Managed Services Systems Lead

Carrier Access IT • Clive (IA)

On-site
USD 120,000 - 160,000
Medical, dental, and vision insurance
401(k) with company match
Professional development opportunities
+1
Managed Services Systems Lead
Managed Services Systems Lead

Carrieraccessit • Clive (IA)

On-site
USD 110,000 - 140,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
+4
Senior Server Windows Engineer
Senior Server Windows Engineer

Saic • Washington

On-site
USD 80,000 - 120,000