You will lead the hardening of Windows servers and workstations to comply with NIST SP 800-53 security controls.
This role is on-site.
Responsibilities
Install, configure, patch, and maintain Windows Server (2019/2022+) and Windows 10/11 endpoints.
Implement and validate security controls across NIST families including Access Control (AC), Configuration Management (CM), and Audit & Accountability (AU).
Manage Group Policy Objects (GPOs), security baselines, and Intune policies to enforce least privilege, firewall rules, and cryptographic protections.
Administer Active Directory, SCCM/MECM, Microsoft Intune, Azure AD/Entra ID, and Defender for Endpoint.
Develop PowerShell scripts for automation of compliance checks and generate system security plans and evidence documentation.
Required Skills
10+ years of hands-on experience administering Windows servers and workstations in enterprise environments.
Proven experience implementing NIST SP 800-53 security controls on Microsoft platforms.
Proficiency with Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, and the Defender suite.
Deep understanding of hardening techniques, baseline configuration management, and least-privilege principles.
Experience with compliance tools such as Nessus/Tenable.
Strong scripting skills in PowerShell for automation and reporting.
Ability to document System Security Plans (SSP) and POA&Ms.
Preferred Skills
Certifications such as Microsoft Certified: Windows Server Hybrid Administrator Associate, Endpoint Administrator, CompTIA Security+, CISM, or CAP.
Hands-on experience with Azure AD/Entra ID, Microsoft Defender for Endpoint compliance policies, or Azure Policy for NIST mappings.