{"schemaVersion":"jobsearcher.job.v1","id":"a69f3a9056c8a2bd74135c38","url":"https://jobsearcher.com/jobs/a69f3a9056c8a2bd74135c38","canonicalUrl":"https://jobsearcher.com/jobs/a69f3a9056c8a2bd74135c38","title":"Windows Infrastructure Engineer/Architect","description":"Job Title: Windows Infrastructure Engineer/Architect\nLocation: Primarily REMOTE (Possible onsite work in DC as needed), must be located in the greater DC area\nRole Type: 6 + months Contract\nClearance: Must be able to obtain a Public Trust\n\nSystem One has a Windows Infrastructure Engineer/Architect position will have experience in securing, scaling, and supporting core enterprise identity and access management platforms. In this role, the candidate will serve as the subject matter expert and highest-tier escalation point for our Active Directory (AD) environment and Azure Active Directory /Microsoft Entra ID cloud integrations. They will be responsible for architecting robust identity solutions, managing our Enterprise Public Key Infrastructure (PKI), and providing high-level tier -3 architectural support to ensure optimal security, compliance, and system availability across our hybrid environment. This technical resource will support and engage with the infrastructure team on the various tasks being supported by the team at a higher technical level. The position will set standards the rest of the team builds to and serve as an escalation point when an issue exceeds Tier 1 and Tier 2 support. They may also provide hands-on support in program operations, configuration, deployment, maintenance, monitoring, maintenance and trouble-shooting activities.\n\nSkills:\nIdentify Architecture\nSecurity & PKI Management\nCloud Design\nAzure Engineering, Administration, and Optimization\nTier 3 Engineering Support\nAccess Governance\nAutomation and Optimization\nDisaster Recovery\nContinuous Improvement\nDocumentation Compliance\n\nRequired Qualifications\n\nBachelor’s degree in computer science, information systems, engineering, or a related technical field, and eight (8) or more years of progressive Windows Infrastructure Engineer/Architect experience OR Master’s degree in a related field and at least 6 years of relevant experience in above areas. Equivalent additional experience may substitute for the degree.\nA minimum of six (6) years of experience in cloud operations, engineering, or related field.\nA minimum of three (3) years performing at a senior and lead level with design and architecture ownership for an enterprise Windows environment.\nFamiliarity with federal compliance (NIST, FISMA, FedRAMP) and CIS 4.0 controls.\nSignificant experience designing, operating and maintaining Microsoft Azure environments to include Zero Trust, hybrid cloud, and cross-domain architectures in mission environments.\nExperience with the configuration, deployment, and management of Microsoft Entra ID / Azure AD for centralized identity, single sign-on (SSO), and role-based access control (RBAC) across Azure tenants and subscriptions.\nDemonstrated experience with the integration of federated identity solutions with AWS Identity Center, Entra, or on-premises Active Directory.\nDevelop and enforce Azure governance frameworks, including Azure Policy, Management Groups, and Blueprints, ensuring alignment with DoD Zero Trust and least-privilege principles.\nExperience with Azure Monitor and cost optimization strategies.\nDeep expertise in Microsoft Azure architecture, Microsoft Entra ID and on-prem interoperability.\nFamiliarity with orchestration tools like Ansible, Chef, or Puppet for configuration management and ability to implement Continuous Integration/Continuous Deployment (CI/CD) pipelines for cloud infrastructure provisioning and deployment automation.?\nAbility to script in one more of the following computer languages Python, Bash, Visual Basic or PowerShell.?\nStrong understanding of federated identity, modern authentication protocols (SAML, OIDC, OAuth 2.0), and cross-cloud authentication mechanisms.\nDeep expertise in Microsoft Azure architecture, Microsoft Entra ID and on-prem interoperability.\nHands on experience with and knowledge of networking concepts (DNS, VPNs, load balancers, etc.) and cloud-based networking configurations.\nConfigure, maintain and upgrade 2019, 2022, & 2025 servers operating systems by performing system administration tasks related to:\nMicrosoft Application installation and maintenance\n3rd Party software installation and maintenance\nConfigure, maintain and upgrade physical and virtual server installations in FTC datacenters, to include:\nOS installation and configuration\nOut of Band management configuration (iLO, etc.)\nHardware installation/maintenance (network adapter, memory, hard drives, etc.)\nRAID Configuration\nNetwork adapter configuration\nSCSI and Fiber Channel configuration\nExperience and ability to immediately contribute to Automation Tasks and Infrastructure-as-Code tools and templates.\nProvide experience designing, deploying, and maintaining Active Directory Certificate Services (AD CS) ?/ PKI environments.\nApplied knowledge of system security engineering, including CIS and STIG hardening, vulnerability management, and federal compliance frameworks (FISMA, NIST SP 800-53).\nExtensive experience with Visio or other networking diagram tools and solid understanding of Networking principles.\nExcellent troubleshooting skills with the ability to resolve complex technical issues in a timely manner.\nStrong problem-solving skills and ability to conduct root cause analysis.\nActively participate in the process of reviewing and improving operational processes, procedures, technology, and documentation. Support the program team in efforts to improve service delivery to the FTC. Adopt program directed procedural changes, process changes, and tool changes as required for the role.\nPerform work activities in accordance with program processes, procedures, and service level agreements.\nSupport other anticipated requirements that will emerge and are reasonably aligned to the role supporting server elements of the infrastructure.\nDemonstrated ability to complete technical projects independently, with strong organizational skills and attention to detail.\nCreate, monitor and drive to resolution change requests and trouble tickets for service level changes that affect Windows Servers and applications installed on Windows servers.\nExcellent written and verbal communication skills. This includes drafting SOPs and technical documentation as well as communication with senior program and customer leadership.\nMust be able to present designs, plans, courses of action, and analyses of alternatives to technical leadership personnel and boards for approvals.\nITIL4 experience.\nServiceNow experience and review incoming ServiceNow tickets and work to resolve any incident tickets and service requests as assigned for:\nServer builds\nServer configuration changes\nWindows Permissions changes\nFile Server ACL changes\nApplication maintenance for:\nSymantec Endpoint Protection (Servers)\nCarbon Black Protection (Servers)\nDNS/DHCP Updates\nActive Directory (including Group Policy Objects)\nMaintain status of assigned tickets in accordance with program standards and program SLAs, including quality of status and timeliness of updates.\nBe comfortable in preparation of data and presentations then active participation and presenting in Leidos and customer meetings as required.\n\nRequired Certifications\nMicrosoft Certified Azure Administrator Associate certification (AZ-104).\nCurrent DoD 8570/8140 baseline certification appropriate for Intermediate System Administrator roles (e.g., Security+, GSEC, SSCP, or equivalent).\n\nPreferred Certifications\nAny other certifications in support of the stated work scope requirements.\n\nSystem One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.\n\nSystem One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.\n\n#M-2\n#LI-CB5\nRef: #851-Rockville-S1","company":"Systemone","rawCompany":"systemone","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-09-27T12:12:26.503Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1241.00","title":"Computer Network Architects","slug":"computer-network-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Windows Infrastructure Engineer/Architect","description":"Job Title: Windows Infrastructure Engineer/Architect\nLocation: Primarily REMOTE (Possible onsite work in DC as needed), must be located in the greater DC area\nRole Type: 6 + months Contract\nClearance: Must be able to obtain a Public Trust\n\nSystem One has a Windows Infrastructure Engineer/Architect position will have experience in securing, scaling, and supporting core enterprise identity and access management platforms. In this role, the candidate will serve as the subject matter expert and highest-tier escalation point for our Active Directory (AD) environment and Azure Active Directory /Microsoft Entra ID cloud integrations. They will be responsible for architecting robust identity solutions, managing our Enterprise Public Key Infrastructure (PKI), and providing high-level tier -3 architectural support to ensure optimal security, compliance, and system availability across our hybrid environment. This technical resource will support and engage with the infrastructure team on the various tasks being supported by the team at a higher technical level. The position will set standards the rest of the team builds to and serve as an escalation point when an issue exceeds Tier 1 and Tier 2 support. They may also provide hands-on support in program operations, configuration, deployment, maintenance, monitoring, maintenance and trouble-shooting activities.\n\nSkills:\nIdentify Architecture\nSecurity & PKI Management\nCloud Design\nAzure Engineering, Administration, and Optimization\nTier 3 Engineering Support\nAccess Governance\nAutomation and Optimization\nDisaster Recovery\nContinuous Improvement\nDocumentation Compliance\n\nRequired Qualifications\n\nBachelor’s degree in computer science, information systems, engineering, or a related technical field, and eight (8) or more years of progressive Windows Infrastructure Engineer/Architect experience OR Master’s degree in a related field and at least 6 years of relevant experience in above areas. Equivalent additional experience may substitute for the degree.\nA minimum of six (6) years of experience in cloud operations, engineering, or related field.\nA minimum of three (3) years performing at a senior and lead level with design and architecture ownership for an enterprise Windows environment.\nFamiliarity with federal compliance (NIST, FISMA, FedRAMP) and CIS 4.0 controls.\nSignificant experience designing, operating and maintaining Microsoft Azure environments to include Zero Trust, hybrid cloud, and cross-domain architectures in mission environments.\nExperience with the configuration, deployment, and management of Microsoft Entra ID / Azure AD for centralized identity, single sign-on (SSO), and role-based access control (RBAC) across Azure tenants and subscriptions.\nDemonstrated experience with the integration of federated identity solutions with AWS Identity Center, Entra, or on-premises Active Directory.\nDevelop and enforce Azure governance frameworks, including Azure Policy, Management Groups, and Blueprints, ensuring alignment with DoD Zero Trust and least-privilege principles.\nExperience with Azure Monitor and cost optimization strategies.\nDeep expertise in Microsoft Azure architecture, Microsoft Entra ID and on-prem interoperability.\nFamiliarity with orchestration tools like Ansible, Chef, or Puppet for configuration management and ability to implement Continuous Integration/Continuous Deployment (CI/CD) pipelines for cloud infrastructure provisioning and deployment automation.?\nAbility to script in one more of the following computer languages Python, Bash, Visual Basic or PowerShell.?\nStrong understanding of federated identity, modern authentication protocols (SAML, OIDC, OAuth 2.0), and cross-cloud authentication mechanisms.\nDeep expertise in Microsoft Azure architecture, Microsoft Entra ID and on-prem interoperability.\nHands on experience with and knowledge of networking concepts (DNS, VPNs, load balancers, etc.) and cloud-based networking configurations.\nConfigure, maintain and upgrade 2019, 2022, & 2025 servers operating systems by performing system administration tasks related to:\nMicrosoft Application installation and maintenance\n3rd Party software installation and maintenance\nConfigure, maintain and upgrade physical and virtual server installations in FTC datacenters, to include:\nOS installation and configuration\nOut of Band management configuration (iLO, etc.)\nHardware installation/maintenance (network adapter, memory, hard drives, etc.)\nRAID Configuration\nNetwork adapter configuration\nSCSI and Fiber Channel configuration\nExperience and ability to immediately contribute to Automation Tasks and Infrastructure-as-Code tools and templates.\nProvide experience designing, deploying, and maintaining Active Directory Certificate Services (AD CS) ?/ PKI environments.\nApplied knowledge of system security engineering, including CIS and STIG hardening, vulnerability management, and federal compliance frameworks (FISMA, NIST SP 800-53).\nExtensive experience with Visio or other networking diagram tools and solid understanding of Networking principles.\nExcellent troubleshooting skills with the ability to resolve complex technical issues in a timely manner.\nStrong problem-solving skills and ability to conduct root cause analysis.\nActively participate in the process of reviewing and improving operational processes, procedures, technology, and documentation. Support the program team in efforts to improve service delivery to the FTC. Adopt program directed procedural changes, process changes, and tool changes as required for the role.\nPerform work activities in accordance with program processes, procedures, and service level agreements.\nSupport other anticipated requirements that will emerge and are reasonably aligned to the role supporting server elements of the infrastructure.\nDemonstrated ability to complete technical projects independently, with strong organizational skills and attention to detail.\nCreate, monitor and drive to resolution change requests and trouble tickets for service level changes that affect Windows Servers and applications installed on Windows servers.\nExcellent written and verbal communication skills. This includes drafting SOPs and technical documentation as well as communication with senior program and customer leadership.\nMust be able to present designs, plans, courses of action, and analyses of alternatives to technical leadership personnel and boards for approvals.\nITIL4 experience.\nServiceNow experience and review incoming ServiceNow tickets and work to resolve any incident tickets and service requests as assigned for:\nServer builds\nServer configuration changes\nWindows Permissions changes\nFile Server ACL changes\nApplication maintenance for:\nSymantec Endpoint Protection (Servers)\nCarbon Black Protection (Servers)\nDNS/DHCP Updates\nActive Directory (including Group Policy Objects)\nMaintain status of assigned tickets in accordance with program standards and program SLAs, including quality of status and timeliness of updates.\nBe comfortable in preparation of data and presentations then active participation and presenting in Leidos and customer meetings as required.\n\nRequired Certifications\nMicrosoft Certified Azure Administrator Associate certification (AZ-104).\nCurrent DoD 8570/8140 baseline certification appropriate for Intermediate System Administrator roles (e.g., Security+, GSEC, SSCP, or equivalent).\n\nPreferred Certifications\nAny other certifications in support of the stated work scope requirements.\n\nSystem One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.\n\nSystem One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.\n\n#M-2\n#LI-CB5\nRef: #851-Rockville-S1","datePosted":"2026-09-27T12:12:26.503Z","dateModified":"2026-09-27T12:12:26.503Z","hiringOrganization":{"@type":"Organization","name":"Systemone","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a69f3a9056c8a2bd74135c38"},"url":"https://jobsearcher.com/jobs/a69f3a9056c8a2bd74135c38"}}