Job Description
Job DescriptionPosition: Junior Microsoft Systems Administrator Location: Montgomery, AL – 36106Duration: 12 months from projected start date
Job Summary:
We are seeking a Junior Microsoft Systems Administrator to harden Windows servers and workstations in compliance with NIST SP 800-53 security controls. This role focuses on implementing configuration baselines, enforcing access controls, and continuous monitoring. This position requires strong technical expertise in Microsoft technologies combined with practical knowledge of cybersecurity standards.
Key Responsibilities
- Install, configure, harden, patch, and maintain Windows Server (2019/2022+) and Windows 10/11 workstations in accordance with NIST SP 800-53 Rev. 5 controls.
- Implement and validate security controls across families including Access Control (AC), Configuration Management (CM), Identification & Authentication (IA), Audit & Accountability (AU), System & Communications Protection (SC), and others relevant to endpoint/server platforms.
- Manage Group Policy Objects (GPOs), security baselines, and Intune/Microsoft Endpoint Manager policies to enforce 800-53-aligned configurations (e.g., password policies, account lockout, least privilege, firewall rules, AppLocker, BitLocker).
- Perform hardening tasks including, but not limited to:
- Enforcing deny-by-default/allow-by-exception execution policies
- Configuring host-based firewalls and intrusion detection/prevention
- Implementing multi-factor authentication and privileged account management
- Enabling cryptographic protections for data at rest/transit
- Removing unnecessary services, features, and default accounts
- Administer Microsoft tools for compliance: Active Directory, Microsoft Intune, Azure AD/Entra ID, Defender for Endpoint, and Azure Policy (where hybrid/cloud-integrated).
- Conduct regular compliance scans, vulnerability assessments, and remediation of findings to maintain continuous ATO posture.
- Document system security plans (SSP), control implementation details, POA&Ms, and evidence for NIST 800-53 controls during audits or assessments.
Required Qualifications
- 2+ years of hands-on experience administering Windows servers and workstations in enterprise environments.
- Proficiency with Microsoft administration tools: Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, Defender suite.
- Understanding of key 800-53 control families as applied to endpoints/servers (AC, AU, CM, IA, SC, SI, etc.).
- Experience with hardening techniques, baseline configuration management, and least-privilege principles.
- Familiarity with compliance tools (Nessus/Tenable or similar).
- Familiar with PowerShell for automation and compliance checks.
Relevant certifications:
- Microsoft: Microsoft Certified: Windows Server Hybrid Administrator Associate, Endpoint Administrator, or equivalent.
- Security/Compliance: CompTIA Security+
- Hands-on work with Azure AD/Entra ID, Microsoft Defender for Endpoint compliance policies, or Azure Policy for NIST mappings.
Education
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, related field, (or equivalent experience).
vTech Solution Inc. is a Managed IT Services firm headquartered in Washington, DC. They specialize in a range of services including cloud computing, managed network security, and cybersecurity. Their primary focus is on providing human-centered IT solutions for government and business sectors, including federal, state, local, and education (SLED) groups, as well as commercial organizations.
vTech Solution offers services such as:
- Managed Security Services: Implementing zero-trust security frameworks to prevent cyber threats in real-time.
- Multi-cloud Management Services: Helping businesses digitally transform with smart cloud technologies.
- Infrastructure Managed Services: Creating resilient and secure infrastructure management.
- Professional Services: Providing expertise for mission-critical programs.
- Productivity and Communications: Ensuring secure and confident business connectivity from anywhere
