Windows Systems Engineer; MTS
Listed on 2026-09-20
-
IT/Tech
Windows Server, Cybersecurity, Systems Engineer
Windows Systems Engineer (MTS)
Location: Hybrid - Pleasanton, CA
Reporting to: Sr Manager – Service Desk, NOC/SOC, Systems & Network Administration
At STN
, we don't just adapt to the digital future, we engineer it. Our mission is to help organizations thrive in a rapidly evolving technology landscape through strategic insight, cutting-edge solutions, and a security-first mindset. We provide end-to-end services spanning cloud consulting, AI infrastructure, and enterprise security, enabling secure, scalable, and future-ready transformation.
As trusted advisors, we align IT investments with business outcomes that drive performance and growth, starting with deep strategic engagement and delivering tailored solutions built for long-term impact.
Our approach is innovation-led and rooted in cybersecurity, with a focus on leveraging the right technologies to solve real-world challenges. We invest in our people and foster a culture of growth, inclusion, and purpose because we believe empowered teams build transformative technology.
Overview
The Systems Engineer owns the day-to-day health, security, and lifecycle of the Windows Server, Active Directory, and Microsoft 365 environments that STN operates for its managed-services customers.
Key Responsibilities
- Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services
- Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan
- Write, debug, and maintain Power Shell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation
- Administer Microsoft 365 and Entra Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy
- Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines
- Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews
- Monitor backup and replication jobs, run and evidence test restores, and escalate failures against RPO and RTO commitments
- Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning
- Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows
- Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks
- Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation
- Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current
- Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines
Required
- 5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration
- Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback
- Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).