About Elveo
Elveo is what happens when two pioneers in direct-to-device (D2D) communications join forces. Elveo brings together a combined 20 years of expertise to close the coverage gap for more than 50 mobile network operators (MNOs) and major distribution partners operating in 60+ countries worldwide.
That heritage and our technology powers what we call ‘elevated intelligence’ — a new approach that processes and adapts on orbit, delivering voice and data services straight to mobile users, IoT devices and machines across enterprise, government and humanitarian sectors worldwide.
As a team, we’re on a mission to deliver powerful compute and connectivity directly to individuals and objects everywhere on Earth.
Join us, and become part of a globally inclusive company that is transforming satellite communications from a niche service to an essential global infrastructure, and democratizing connectivity for billions worldwide.
Ready to take the next step? Join us.
The IT Infrastructure & Systems Administrator will support and maintain Elveo's core IT infrastructure, with a particular focus on Microsoft identity, endpoint management, device security, and compliance across our Chevy Chase, MD and Chantilly, VA locations. This role will administer Microsoft Entra ID, Intune, Defender, Microsoft 365, and MDM tooling; monitor endpoint compliance and configuration drift; and help ensure systems remain aligned with Elveo's security and CMMC requirements.
The role will also support general systems and network administration, including firewalls, VPNs, DNS/DHCP, wireless infrastructure, and other corporate IT systems. While this is not primarily an end-user support position, the administrator will serve as an escalation point for technical issues and assist with device provisioning, onboarding/offboarding, and other hands-on IT needs when required.
Duties & ResponsibilitiesAdminister and harden core infrastructure: Microsoft Entra ID (Azure AD), Conditional Access, DNS/DHCP, Office 365, and endpoint security (ESET, Microsoft Defender) at the systems-administration level
Manage endpoint and device compliance through Microsoft Intune and MDM platforms (e.g., NinjaOne), including policy design, patch management, and fleet-wide enforcement
Implement and maintain infrastructure security controls (firewalls, MFA, network segmentation, endpoint protection) in line with ITAR and export-control obligations
Support Lynk's CMMC Level 2 compliance program — maintain endpoint compliance (patching, configuration baselines, encryption, access control) across the device fleet and evidence controls for audits
Monitor and remediate endpoint compliance drift via Intune/NinjaOne and Microsoft Defender to keep the environment aligned with NIST SP 800-171 control requirements
Design, deploy, and maintain LAN/WAN, wireless, VPN, and firewall infrastructure across Lynk office and lab locations
Own network architecture decisions — segmentation, routing, VLANs, redundancy, and capacity planning as the company scales
Deploy, monitor, and maintain security posture via Microsoft Defender (Endpoint/365) — threat detection, alerting, and remediation
Manage server infrastructure (physical and virtual), including provisioning, patching, backup, and lifecycle management
Monitor network and infrastructure health; lead incident response and root-cause analysis for outages and performance issues
Partner with security/compliance stakeholders on System Security Plans (SSPs), POA&Ms, and audit readiness for CMMC assessments
Document network topology, infrastructure architecture, and disaster recovery/business continuity procedures
Serve as a secondary/escalation point of contact for basic end-user technical issues (hardware, software, connectivity, account access)
Provision and configure end-user hardware (laptops, peripherals) in line with security and compliance baselines
Troubleshoot common Windows/macOS and Office 365 issues for staff as needed
Support onboarding/offboarding from an infrastructure and access-management perspective (accounts, device enrollment, permissions)
4+ years of experience in network engineering, systems administration, or infrastructure management
Hands-on experience designing and maintaining LAN/WAN, VPN, firewall, and wireless network infrastructure
Strong Windows Server and macOS environment administration experience
Experience managing Microsoft Entra ID (Azure AD), Conditional Access, and Office 365 at an administrative/architectural level
Hands-on experience with Microsoft Intune for device/endpoint management and compliance policy
Experience with MDM platforms such as NinjaOne, ManageEngine, or similar
Experience deploying and managing Microsoft Defender (Endpoint/365) or comparable endpoint security/EDR tooling
Understanding of network security fundamentals: firewalls, segmentation, and endpoint protection
Familiarity with CMMC Level 2 / NIST SP 800-171 control requirements and experience maintaining endpoint compliance in a regulated environment
Comfortable providing basic end-user technical support alongside infrastructure duties
Strong documentation, troubleshooting, and incident-response skills
Relevant certification preferred (e.g., CompTIA Network+/Security+, CCNA, Microsoft Certified: Intune/Endpoint Manager, or equivalent experience)
Experience with PowerShell or other scripting/automation tools
Direct experience preparing for or supporting a CMMC Level 2 assessment (SSP/POA&M development, C3PAO audit support)
Experience supporting infrastructure in a regulated or export-controlled (ITAR) environment
Previous startup experience is a strong plus
To comply with U.S. Government export control regulations (ITAR), applicants must be one of the following: (i) a U.S. citizen or national, (ii) a lawful permanent resident (green card holder), (iii) a refugee under 8 U.S.C. § 1157, or (iv) an asylee under 8 U.S.C. § 1158. Individuals who do not meet these criteria must be eligible to obtain the necessary authorizations from the U.S. Department of State.
Learn about ITAR here: https://www.pmddtc.state.gov
Job LocationChevy Chase, MD — Hybrid (2–3 days onsite/week), with periodic travel to Chantilly, VA
Skills Required
- 4+ years of experience in network engineering, systems administration, or infrastructure management
- Hands-on experience designing and maintaining LAN/WAN, VPN, firewall, and wireless network infrastructure
- Strong Windows Server and macOS environment administration experience
- Experience managing Microsoft Entra ID or Azure AD, Conditional Access, and Office 365 at an administrative or architectural level
- Hands-on experience with Microsoft Intune for device and endpoint management and compliance policy
- Experience with MDM platforms such as NinjaOne, ManageEngine, or similar
- Experience deploying and managing Microsoft Defender Endpoint, Microsoft Defender 365, or comparable endpoint security or EDR tooling
- Understanding of network security fundamentals, including firewalls, segmentation, and endpoint protection
- Familiarity with CMMC Level 2 and NIST SP 800-171 control requirements and endpoint compliance in a regulated environment
- Ability to provide basic end-user technical support alongside infrastructure duties
- Strong documentation, troubleshooting, and incident-response skills
- Relevant certification such as CompTIA Network+, CompTIA Security+, CCNA, or Microsoft Certified Intune/Endpoint Manager
- PowerShell or other scripting and automation experience
- Direct experience supporting a CMMC Level 2 assessment, including SSP, POA&M, or C3PAO audit support
- Experience supporting infrastructure in a regulated or export-controlled ITAR environment
- Previous startup experience
- Must meet ITAR eligibility requirements or be eligible to obtain required U.S. Department of State authorizations
What We Do
Lynk is a patented, proven, and commercially licensed satellite-direct-to-standard-mobile-phone system. Today, Lynk allows commercial subscribers to send and receive text messages to and from space, via standard unmodified mobile devices. Lynk’s service has been demonstrated in over 25 countries and is currently being deployed commercially, based on 36 MNO commercial service contracts covering approximately 50 countries. Lynk is currently providing cell broadcast (emergency) alerts and two-way SMS messaging and plans to launch voice and mobile broadband services in the future. By partnering with Lynk via a simple roaming agreement, a mobile network operator opens the door to new revenue in untapped markets, gives subscribers peace of mind with ubiquitous connectivity, and provides a potential pathway to economic prosperity for billions. For more information, visit www.lynk.world.







