Location: Hybrid - Pleasanton, CA
Reporting to: Sr Manager – Service Desk, NOC/SOC, Systems & Network Administration
At STN, we don't just adapt to the digital future, we engineer it. Our mission is to help organizations thrive in a rapidly evolving technology landscape through strategic insight, cutting-edge solutions, and a security-first mindset. We provide end-to-end services spanning cloud consulting, AI infrastructure, and enterprise security, enabling secure, scalable, and future-ready transformation.
As trusted advisors, we align IT investments with business outcomes that drive performance and growth, starting with deep strategic engagement and delivering tailored solutions built for long-term impact.
Our approach is innovation-led and rooted in cybersecurity, with a focus on leveraging the right technologies to solve real-world challenges. We invest in our people and foster a culture of growth, inclusion, and purpose because we believe empowered teams build transformative technology.
Overview
The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers.Â
Key Responsibilities
- Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services
- Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan
- Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation
- Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy
- Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines
- Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews
- Monitor backup and replication jobs, run and evidence test restores, and escalate failures against RPO and RTO commitments
- Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning
- Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows
- Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks
- Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation
- Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current
- Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines
Experience & Qualifications
Required- 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration
- Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback
- Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate
- PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell
- Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it
- Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require
- Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access
- Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product
- Hands-on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management
- Clear written communication and documentation habits suited to a multi-customer environment
- Bachelor's degree in information technology, computer science, or equivalent experience
- Experience in an MSP, MSSP, or multi-tenant hosting environment supporting several customers concurrently
- Azure IaaS or Azure Virtual Desktop experience alongside on-premises virtualization
- Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto
- Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365
- Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow
- Hybrid identity experience including Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles
- Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting
- Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE
Compensation
- Full-Time, Exempt
- $175,000-$195,000/year, DOE
Benefits
- Health Coverage – Medical, Dental & Vision
- FSA Health and Dependent Care available
- 401(k) Plan
- Unlimited Paid Time Off (PTO)
- Observed Holidays Paid
- Cell Phone Allowance
- Collaborative, growth-driven culture
Candidates must be U.S. Citizens or Permanent Residents. We are unable to provide sponsorship at this time.
Employment is contingent upon the successful completion of a background check and reference verification. All applicants must be authorized to work in the United States on a full-time basis.
Learn more about this Employer on their Career Site
