Administer Windows Servers across multiple customer environments, including DNS, DHCP, Group Policy, file and print services, and certificate services
Plan and execute Active Directory work — domain controller upgrades, promotion and demotion, OS and functional-level upgrades, replication troubleshooting, and site and topology changes — from a documented plan
Write, debug, and maintain PowerShell for provisioning, reporting, bulk changes, and remediation, converting repeat manual work into reusable, reviewed automation
Administer Microsoft 365 and Entra ID: Exchange Online, mail flow and transport rules, licensing, mailbox moves and migrations, group and identity management, and Conditional Access policy
Own patch cadence across servers and endpoints, maintain endpoint protection coverage, and remediate vulnerability scan findings against agreed timelines
Support MFA and Conditional Access rollouts and maintain identity hygiene, including privileged account control, stale object cleanup, and access reviews
Monitor backup and replication jobs, run and evidence test restores, and escalate failures against RPO and RTO commitments
Build, standardize, and retire Windows servers across virtualization and cloud IaaS, including image standards and capacity planning
Operate the VMware vSphere or Hyper-V estate: host and cluster health, VM lifecycle and sizing, snapshots, datastore capacity, and hypervisor patching within approved maintenance windows
Act as the L3 escalation point for the service desk, drive root-cause analysis on recurring incidents, and feed fixes back into runbooks
Follow change management for all infrastructure work: risk assessment, maintenance windows, rollback plans, and post-change validation
Maintain runbooks, architecture and identity documentation, and configuration records, keeping customer-specific detail current
Produce and maintain evidence for PCI and HIPAA reviews, including patch reports, restore tests, access reviews, and configuration baselines
Required
5+ years hands-on with Windows Server and Active Directory, covering DNS, DHCP, and Group Policy administration
Demonstrated ability to run a domain controller promotion or upgrade independently from a documented plan, including pre-checks, replication validation, and rollback
Certificate management experience: AD CS or another internal PKI, public SSL/TLS certificate lifecycle, and the renewal and expiry discipline that keeps customer services from failing on an expired certificate
PowerShell proficiency at the level of writing and debugging scripts, not only running scripts written by others — or equivalent automation depth in another tool (Python, Ansible, or Terraform) alongside working PowerShell
Working command of security and patch hygiene: patch cadence, endpoint protection, MFA and Conditional Access concepts, and the ability to read a vulnerability scan and act on it
Experience supporting PCI- and/or HIPAA-regulated customer environments and the change control and evidence discipline they require
Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access
Backup and restore operations: job monitoring, test restores, and failure escalation — Cohesity or Veeam preferred, though the operational discipline matters more than the specific product
Hands-on virtualization experience with VMware vSphere or Hyper-V, including host and cluster operations, VM provisioning, snapshots, and resource management
Clear written communication and documentation habits suited to a multi-customer environment
Bachelor's degree in information technology, computer science, or equivalent experience
Preferred
Experience in an MSP, MSSP, or multi-tenant hosting environment supporting several customers concurrently
Azure IaaS or Azure Virtual Desktop experience alongside on-premises virtualization
Endpoint and patch management platforms such as Intune, SCCM/MECM, or an RMM such as NinjaOne or Datto
Vulnerability management tooling (Nessus, Qualys, or Rapid7) and Microsoft Defender for Endpoint or Defender for Office 365
Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow
Hybrid identity experience including Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles
Familiarity or working knowledge of using AI coding tools such as Claude or OpenAI to accelerate scripting and troubleshooting
Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, or MCSA/MCSE
Full-Time, Exempt
$175,000-$195,000/year, DOE
Health Coverage – Medical, Dental & Vision
FSA Health and Dependent Care available
401(k) Plan
Unlimited Paid Time Off (PTO)
Observed Holidays Paid
Cell Phone Allowance
Collaborative, growth-driven culture
Skills Required
- 5+ years of hands-on Windows Server and Active Directory experience, including DNS, DHCP, and Group Policy administration
- Ability to independently perform domain controller promotions or upgrades using documented plans, pre-checks, replication validation, and rollback procedures
- Certificate management experience with AD CS or internal PKI, public SSL/TLS certificates, renewals, and expiration management
- PowerShell scripting and debugging proficiency, or equivalent automation experience with Python, Ansible, or Terraform alongside working PowerShell knowledge
- Experience with patch cadence, endpoint protection, MFA, Conditional Access, and vulnerability scan remediation
- Experience supporting PCI- and/or HIPAA-regulated customer environments, including change control and compliance evidence
- Microsoft 365 and Entra ID administration, including Exchange Online, mail flow, licensing, mailbox moves, and Conditional Access
- Backup and restore operations, including job monitoring, test restores, and failure escalation; Cohesity or Veeam preferred
- Hands-on VMware vSphere or Hyper-V experience, including host and cluster operations, VM provisioning, snapshots, and resource management
- Clear written communication and documentation skills for multi-customer environments
- Bachelor's degree in information technology, computer science, or equivalent experience
- Experience in an MSP, MSSP, or multi-tenant hosting environment
- Azure IaaS or Azure Virtual Desktop experience
- Experience with Intune, SCCM/MECM, NinjaOne, or Datto
- Experience with Nessus, Qualys, Rapid7, Microsoft Defender for Endpoint, or Defender for Office 365
- Experience with RMM, PSA, or ITSM platforms such as NinjaOne, ConnectWise, HaloPSA, Jira Service Management, or ServiceNow
- Hybrid identity experience with Entra Connect, tenant-to-tenant migrations, and Windows Server 2022/2025 upgrade cycles
- Familiarity with AI coding tools such as Claude or OpenAI for scripting and troubleshooting
- Certifications such as AZ-104, MS-102, SC-300, AZ-800/801, CompTIA Security+, MCSA, or MCSE
What We Do
STN, Inc. is a managed technology and infrastructure provider serving enterprise, regulated, and AI-driven organizations. It designs, operates, and supports secure, scalable systems, including managed IT, cloud and platform services, cybersecurity, data management, compliance engineering, enterprise hardware and software, and GPU One, its GPU-as-a-Service platform for AI training, tuning, inference, and other high-performance workloads. STN emphasizes reliability, audit readiness, and ongoing human support.







