What are the responsibilities and job description for the Senior microsoft system administrator position at Seneca Resources?
Job Summary
We are seeking a Senior Microsoft Systems Administrator to lead a project to harden Windows servers and workstations in compliance with NIST SP 800-53 security controls. This role focuses on implementing configuration baselines, enforcing access controls, and continuous monitoring. This position requires strong technical expertise in Microsoft technologies combined with practical knowledge of cybersecurity standards.
Key Responsibilities
- Install, configure, harden, patch, and maintain Windows Server (2019/2022 ) and Windows 10/11 workstations in accordance with NIST SP 800-53 Rev. 5 controls.
- Implement and validate security controls across families including Access Control (AC), Configuration Management (CM), Identification & Authentication (IA), Audit & Accountability (AU), System & Communications Protection (SC), and others relevant to endpoint/server platforms.
- Manage Group Policy Objects (GPOs), security baselines, and Intune/Microsoft Endpoint Manager policies to enforce 800-53-aligned configurations (e.g., password policies, account lockout, least privilege, firewall rules, AppLocker, BitLocker).
- Perform hardening tasks including:
- Enforcing deny-by-default/allow-by-exception execution policies
- Configuring host-based firewalls and intrusion detection/prevention
- Implementing multi-factor authentication and privileged account management
- Enabling cryptographic protections for data at rest/transit
- Removing unnecessary services, features, and default accounts
- Administer Microsoft tools for compliance: Active Directory, Microsoft Endpoint Configuration Manager (SCCM/MECM), Microsoft Intune, Azure AD/Entra ID, Defender for Endpoint, and Azure Policy (where hybrid/cloud-integrated).
- Document system security plans (SSP), control implementation details, POA&Ms, and evidence for NIST 800-53 controls during the project.
- Develop PowerShell scripts for automation of compliance checks and reporting.
Required Qualifications
4 years of hands-on experience administering Windows servers and workstations in enterprise environments.
- Demonstrated experience implementing NIST SP 800-53 security controls on Microsoft platforms.
- Proficiency with Microsoft administration tools: Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, Defender suite.
- Understanding of key 800-53 control families as applied to endpoints/servers (AC, AU, CM, IA, SC, SI, etc.).
- Experience with hardening techniques, baseline configuration management, and least-privilege principles.
- Familiarity with compliance tools (Nessus/Tenable or similar).
- Strong scripting skills (PowerShell preferred) for automation and compliance checks.
- U.S. citizenship required