SonicJobs Logo
Left arrow iconBack to search

Windows Systems Engineer (MTS)

STN Incorporated
Posted 2 days ago, valid for 21 days
Location

Pleasanton, CA, US

Salary

$175,000 - $195,000 per year

Contract type

Full Time

Paid Time Off
Flexible Spending Account

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Windows Systems Engineer (MTS)
Location: Hybrid - Pleasanton, CA
Reporting to: Sr Manager – Service Desk, NOC/SOC, Systems & Network Administration

At STN, we don't just adapt to the digital future, we engineer it. Our mission is to help organizations thrive in a rapidly evolving technology landscape through strategic insight, cutting-edge solutions, and a security-first mindset. We provide end-to-end services spanning cloud consulting, AI infrastructure, and enterprise security, enabling secure, scalable, and future-ready transformation.

As trusted advisors, we align IT investments with business outcomes that drive performance and growth, starting with deep strategic engagement and delivering tailored solutions built for long-term impact.

Our approach is innovation-led and rooted in cybersecurity, with a focus on leveraging the right technologies to solve real-world challenges. We invest in our people and foster a culture of growth, inclusion, and purpose because we believe empowered teams build transformative technology.

Overview

The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers. 

Key Responsibilities

  • Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services
  • Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan
  • Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation
  • Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy
  • Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines
  • Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews
  • Monitor backup and replication jobs, run and evidence test restores, and escalate failures against RPO and RTO commitments
  • Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning
  • Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows
  • Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks
  • Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation
  • Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current
  • Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines

Experience & Qualifications

Required
  • 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration
  • Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback
  • Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate
  • PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell
  • Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it
  • Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require
  • Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access
  • Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product
  • Hands-on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management
  • Clear written communication and documentation habits suited to a multi-customer environment
  • Bachelor's degree in information technology, computer science, or equivalent experience
Preferred
  • Experience in an MSP, MSSP, or multi-tenant hosting environment supporting several customers concurrently
  • Azure IaaS or Azure Virtual Desktop experience alongside on-premises virtualization
  • Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto
  • Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365
  • Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow
  • Hybrid identity experience including Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles
  • Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting
  • Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE

Compensation

  • Full-Time, Exempt
  • $175,000-$195,000/year, DOE

Benefits

  • Health Coverage – Medical, Dental & Vision
  • FSA Health and Dependent Care available
  • 401(k) Plan
  • Unlimited Paid Time Off (PTO)
  • Observed Holidays Paid
  • Cell Phone Allowance
  • Collaborative, growth-driven culture

Candidates must be U.S. Citizens or Permanent Residents. We are unable to provide sponsorship at this time.

Employment is contingent upon the successful completion of a background check and reference verification. All applicants must be authorized to work in the United States on a full-time basis.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.