Network System Administrator
Job description
About the role
You will architect and sustain the network and systems backbone that connects our distributed teams and technology. This role owns the configuration and resilience of our core infrastructure spanning both our Chevy Chase, MD and Chantilly, VA sites. You will ensure that our critical systems remain secure, performant, and aligned with strict regulatory requirements. Your work will directly uphold the integrity of our global communications platform. You will play a key role in maintaining our endpoint compliance posture and security frameworks. This position provides a direct opportunity to safeguard the infrastructure that powers our mission. You will collaborate closely with security and compliance teams to uphold our standards. Your contributions will ensure continuity for our hybrid operational model.
Key facts
What you'll do
Configure, deploy, and maintain LAN/WAN, wireless, VPN, and firewall infrastructure across Lynk office and lab locations.
Administer network segmentation, routing, and VLANs, and support capacity planning as the company scales.
Administer and harden core infrastructure: Microsoft Entra ID (Azure AD), Conditional Access, DNS/DHCP, Office 365, and endpoint security (ESET, Microsoft Defender) at the systems-administration level.
Manage endpoint and device compliance through Microsoft Intune and MDM platforms (e.g., NinjaOne), including policy design, patch management, and fleet-wide enforcement.
Deploy, monitor, and maintain security posture via Microsoft Defender (Endpoint/365) - threat detection, alerting, and remediation.
Manage server infrastructure (physical and virtual), including provisioning, patching, backup, and lifecycle management.
Monitor network and infrastructure health; lead incident response and root-cause analysis for outages and performance issues.
Implement and maintain infrastructure security controls (firewalls, VPN, MFA, network segmentation, endpoint protection) in line with ITAR and export-control obligations.
Support Lynk's CMMC Level 2 compliance program - maintain endpoint compliance (patching, configuration baselines, encryption, access control) across the device fleet and evidence controls for audits.
Monitor and remediate endpoint compliance drift via Intune/NinjaOne and Microsoft Defender to keep the environment aligned with NIST SP 800-171 control requirements.
Partner with security/compliance stakeholders on System Security Plans (SSPs), POA&Ms, and audit readiness for CMMC assessments.
Document network topology, infrastructure configuration, and disaster recovery/business continuity procedures.
Provide basic end-user IT support as a secondary/escalation point for standard technical issues.
Provision and configure end-user hardware such as laptops and peripherals in accordance with security and compliance baselines.
Troubleshoot common Windows/macOS and Office 365 issues for staff as needed.
Support user onboarding and offboarding processes, including account management, device enrollment, and permissions handling.
Requirements
4+ years of experience in network engineering, systems administration, or infrastructure management.
Hands-on experience administering and maintaining LAN/WAN, VPN, firewall, and wireless network infrastructure.
Strong Windows Server and macOS environment administration experience.
Experience managing Microsoft Entra ID (Azure AD), Conditional Access, and Office 365 at an administrative or architectural level.
Hands-on experience with Microsoft Intune for device and endpoint management and compliance policy enforcement.
Experience with MDM platforms such as NinjaOne, ManageEngine, or similar tools.
Experience deploying and managing Microsoft Defender (Endpoint/365) or comparable endpoint security and EDR tooling.
Understanding of network security fundamentals, including firewalls, segmentation, VPN, and endpoint protection mechanisms.
Familiarity with CMMC Level 2 and NIST SP 800-171 control requirements and audit readiness practices.
Ability to work within a regulated environment that requires strict adherence to compliance frameworks.
Capacity to manage infrastructure documentation and support audit evidence collection.
Commitment to maintaining security and availability for a globally distributed, mission-critical operation.
Capability to perform routine server and endpoint patching while minimizing user impact.
Willingness to partner with internal stakeholders to align technical operations with business and regulatory objectives.
Nice to have
Experience supporting hybrid environments that include satellite-enabled connectivity scenarios.
Knowledge of direct-to-device satellite communication concepts and operational constraints.
Practical notes
Hybrid (2-3 days onsite/week), with periodic travel to Chantilly, VA.