Job Description

Please find below the new requirement.

Employment Type: Contract
Duration: 09/01/2026 : 1 Years from projected start date
Remote Job: No
Country: United States
State: Alabama
City: Montgomery, AL, 36105
Zip Code: 36105
Required Hours Week: 40
Primary Skills: Powershell, Cybersecurity, Information Technology, Group Policy, Intune, SCCM/MECM, Defender suite. Understanding of key 800-53 control families as applied to endpoints/servers (AC, AU, CM, IA, SC, SI, etc.). Experience with hardening techniques, baseline configuration management, and least-privilege principles. Familiarity with compliance tools (Nessus/Tenable or similar). Bachelor’s degree in Computer Science, or related field (or equivalent experience). Strong scripting skills (PowerShell preferred) for automation and compliance checks., 4+ years of hands-on experience administering Windows servers and workstations in enterprise environments. Demonstrated experience implementing NIST SP 800-53 security controls on Microsoft platforms. Proficiency with Microsoft administration tools:

Description Of Job

Job Title:
Senior Microsoft Systems Administrator
Job Summary
We are seeking a Senior Microsoft Systems Administrator to lead a project to harden Windows servers and workstations in compliance with NIST SP 800-53 security controls. This role focuses on implementing configuration baselines, enforcing access controls, and continuous monitoring. This position requires strong technical expertise in Microsoft technologies combined with practical knowledge of cybersecurity standards.

Key Responsibilities
Install, configure, harden, patch, and maintain Windows Server (2019/2022+) and Windows 10/11 workstations in accordance with NIST SP 800-53 Rev. 5 controls.
Implement and validate security controls across families including Access Control (AC), Configuration Management (CM), Identification & Authentication (IA), Audit & Accountability (AU), System & Communications Protection (SC), and others relevant to endpoint/server platforms.
Manage Group Policy Objects (GPOs), security baselines, and Intune/Microsoft Endpoint Manager policies to enforce 800-53-aligned configurations (e.g., password policies, account lockout, least privilege, firewall rules, AppLocker, BitLocker).

Perform hardening tasks including:
Enforcing deny-by-default/allow-by-exception execution policies
Configuring host-based firewalls and intrusion detection/prevention
Implementing multi-factor authentication and privileged account management
Enabling cryptographic protections for data at rest/transit
Removing unnecessary services, features, and default accounts
Administer Microsoft tools for compliance: Active Directory, Microsoft Endpoint Configuration Manager (SCCM/MECM), Microsoft Intune, Azure AD/Entra ID, Defender for Endpoint, and Azure Policy (where hybrid/cloud-integrated).
Document system security plans (SSP), control implementation details, POA&Ms, and evidence for NIST 800-53 controls during the project.
Develop PowerShell scripts for automation of compliance checks and reporting.

Required Qualifications
4+ years of hands-on experience administering Windows servers and workstations in enterprise environments.
Demonstrated experience implementing NIST SP 800-53 security controls on Microsoft platforms.
Proficiency with Microsoft administration tools: Active Directory, Group Policy, PowerShell, SCCM/MECM, Intune, Defender suite.
Understanding of key 800-53 control families as applied to endpoints/servers (AC, AU, CM, IA, SC, SI, etc.).
Experience with hardening techniques, baseline configuration management, and least-privilege principles.
Familiarity with compliance tools (Nessus/Tenable or similar).
Strong scripting skills (PowerShell preferred) for automation and compliance checks.
U.S. citizenship required

Preferred Qualifications
Relevant certifications:
Microsoft: Microsoft Certified: Windows Server Hybrid Administrator Associate, Endpoint Administrator, or equivalent.
Security/Compliance: CompTIA Security+, CISM, or CAP.
Hands-on work with Azure AD/Entra ID, Microsoft Defender for Endpoint compliance policies, or Azure Policy for NIST mappings.
Knowledge of related standards (NIST 800-171, CMMC, FISMA).

Education
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience).