What are the responsibilities and job description for the IT Engineer position at MAPP TECHNOLOGIES, LLC?
Infrastructure and Systems Administration
- Administer, maintain, and troubleshoot company IT infrastructure, including Windows servers, Active Directory, Group Policy, DNS, DHCP, file services, print services, and related infrastructure services.
- Support hybrid identity services, including on-premises Active Directory, Microsoft Entra ID, Microsoft 365, user synchronization, group-based access, and account lifecycle management.
- Support Microsoft 365 GCC High services, including Exchange Online, SharePoint, OneDrive, Teams, and related administrative functions.
- Support Azure Government infrastructure and services, including virtual networks, virtual machines, storage, monitoring, secure access, and related cloud resources.
- Support remote access and virtual desktop technologies, including VPN, Remote Desktop Services, Azure Virtual Desktop, and other approved remote access methods.
- Assist with server, workstation, and application upgrades, migrations, configuration changes, and lifecycle replacement projects.
- Maintain system documentation, network diagrams, configuration records, asset records, administrative procedures, and support runbooks.
Network and Security Infrastructure
- Administer and troubleshoot network infrastructure, including Fortinet firewalls, VPNs, VLANs, switches, wireless networks, routing, DNS, DHCP, and network segmentation.
- Support secure connectivity between on-premises systems, Azure Government resources, remote users, vendors, and approved cloud services.
- Monitor and troubleshoot firewall policies, VPN connectivity, site-to-site connectivity, remote access issues, and network performance.
- Assist with the implementation and maintenance of security baselines, secure configurations, firewall rules, access restrictions, endpoint controls, and network monitoring.
Endpoint, Patch, and Device Management
- Administer endpoint management tools such as ManageEngine Endpoint Central for patching, software deployment, remote support, inventory, configuration enforcement, and endpoint reporting.
- Support workstation, laptop, shared device, thin client, printer, mobile device, and production-floor technology needs.
- Assist with Microsoft Intune, MDM, and device compliance initiatives where applicable.
- Support endpoint security controls, including device encryption, antivirus/EDR, application control, removable media controls, and secure configuration policies.
- Ensure endpoints are patched, inventoried, monitored, and maintained in accordance with company policy.
Service Desk and User Support
- Provide advanced second-level and third-level support for complex user, endpoint, application, network, identity, and infrastructure issues.
- Escalate, coordinate, and resolve incidents using the company helpdesk system, including ManageEngine ServiceDesk Plus.
- Assist the IT Manager with escalations, root cause analysis, repeat-issue remediation, and knowledge base development.
- Support onboarding, offboarding, role changes, access changes, MFA/passwordless authentication, hardware provisioning, and account access requests.
- Train users on approved systems, cybersecurity practices, remote access procedures, and secure handling of company information.
Cybersecurity, Monitoring, and Incident Response
- Support cybersecurity monitoring and alert triage using tools such as Microsoft Defender, Microsoft Sentinel, Proofpoint, Fortinet logs, Endpoint Central, and other approved platforms.
- Investigate suspicious activity, phishing reports, endpoint alerts, failed access attempts, unusual network behavior, and other security events.
- Assist with vulnerability management, patch remediation, risk tracking, configuration review, and security exception documentation.
- Support the enforcement of least privilege, MFA, Conditional Access, privileged account controls, secure remote access, and administrative access restrictions.
- Participate in incident response activities, including containment, documentation, remediation, evidence preservation, and post-incident improvement actions.
NIST SP 800-171 / CMMC Level 2 Compliance Support
- Support the implementation, maintenance, and documentation of technical security controls aligned with NIST SP 800-171 and CMMC Level 2.
- Assist with collection, organization, and maintenance of compliance evidence, including screenshots, exports, logs, configuration records, access reviews, audit logs, vulnerability reports, patch records, and system documentation.
- Support periodic access reviews, privileged account reviews, asset reviews, configuration reviews, vulnerability remediation reviews, and security monitoring activities.
- Maintain or assist with documentation related to system boundaries, CUI data flows, approved software, authorized users, administrative access, remote access, mobile code, removable media, encryption, logging, monitoring, and incident response.
- Ensure IT changes, system configurations, and access permissions are implemented in accordance with company policy, change management procedures, and compliance requirements.
- Work with IT leadership, auditors, assessors, vendors, and service providers to support internal reviews, external assessments, and remediation activities.
Projects, Vendors, and Continuous Improvement
- Lead or assist with infrastructure, cloud, security, compliance, endpoint, and network improvement projects.
- Coordinate with vendors, managed service providers, software providers, cloud service providers, and support partners to resolve technical issues and complete approved projects.
- Research, evaluate, and recommend new technologies that improve reliability, security, compliance, efficiency, or business operations.
- Identify recurring technical issues and implement long-term corrective actions.
- Create and maintain technical documentation, procedures, diagrams, implementation notes, and user-facing instructions.