Systems Administrator; L3 - Concord, CA
Listed on 2026-04-30
-
Engineering
Systems Engineer, Cybersecurity
MSP4, LLC | Full-Time | Onsite | Up to 10% Regional Travel
About the RoleThis is a hands‑on operational role. You own the day‑to‑day administration of client infrastructure:
Windows Server, virtualization clusters, SAN and HCI storage, backup, Microsoft 365 and Azure tenants, and defined‑scope network change work. You implement, operate, and maintain inside the framework set by the Principal Solutions Architect and the Senior Engineering team. Your role is to turn an approved design into a running, monitored, documented environment that passes audit. Design authority sits above your tier.
At the L3 tier, you sit between the L2 Field Support Technicians and Senior Infrastructure and Network Security Engineering. L2 escalations land with you. Design questions and architecturally novel changes escalate up from you. You own the outcome at the server and platform layer at your assigned locations, and you touch the client environment every day.
This is a full onsite role at a client facility in your posted location, with regional coverage for nearby MSP4 clients where it applies. Context switching across clients and priorities throughout the day is part of the job. Compliance weight is real: CMMC L2, NIST 800‑171, and SOC 2 are active requirements in this client base.
What You Will Do- Administer Windows Server environments:
Active Directory, DNS, DHCP, Group Policy, file and print services, certificate services at an operational level - Operate VMware vSphere or Microsoft Hyper‑V clusters day to day: VM lifecycle, capacity monitoring, host patching, vMotion or Live Migration, HA and DRS behavior, snapshot hygiene
- SAN and HCI storage operations (Net App, Pure Storage, Nutanix, VMware vSAN): provisioning, volume and LUN changes, capacity monitoring, health checks. Storage architecture sits with Senior Infrastructure Engineering.
- Veeam Backup and Replication operations: job management, backup verification, restore execution, immutable repository and tape operations where applicable, backup gap remediation
- Network change execution at a defined scope: firewall rule adds and modifications against approved standards, VLAN configuration on managed switches, switch port and access layer work. Routing, firewall architecture, and policy design sit with Senior Network Security Engineering.
- Microsoft 365 and Azure tenant administration: identity, licensing, Intune policy application, Conditional Access within established standards, basic tenant hygiene
- Operational SQL Server work in support of client ERP and line‑of‑business applications: installation, patching, version upgrades, backup coordination with Veeam, baseline instance administration. DBA‑level query tuning, indexing, and application‑side schema sit with client DBAs or application vendors.
- L2 escalation ownership: take the tickets that pass the endpoint and site layer, resolve within scope, or escalate cleanly to Senior Engineering
- STIG application and NIST 800‑171 control execution at the server layer in support of CMMC L2 and SOC 2
- Client communication on infrastructure work, change windows, and incident response. You talk directly to client technical contacts and to non‑technical stakeholders.
- Documentation: change records, operational runbooks, and audit‑ready configuration records. Written so another engineer can operate the environment without asking you questions.
- 4 to 6 years of systems administration experience in a multi‑client service delivery environment
- US person status and US‑based work location. You must be based in the United States and qualify as a US person (US citizen, US national, lawful permanent resident, or protected individual under US law). This role's access to Controlled Unclassified Information (CUI) and export‑controlled systems is restricted under CMMC L2 and US export control regulations.
- Windows Server operational depth:
Active Directory, DNS, DHCP, Group Policy, PKI basics, file and print services. Operational depth, not surface familiarity. - Production virtualization experience on VMware vSphere or Microsoft Hyper‑V: host and cluster administration, VM lifecycle, patching, snapshot management, HA and DRS behavior at an…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).