AYN

Senior Systems Engineer

Tlingit Haida Tribal Business Corporation · Falls Church, Virginia, United States · remote

At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description—it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one.

For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska.

Together We Grow – One Mission, One Team – With a Commitment to Serve

Job Title: Senior Systems Engineer

Work Location: Remote or hybrid if near CO/VA offices

Labor Category: Exempt

Clearance Level: Secret

Travel: Up to 20%

Pay Rate: $111,000 - $142,000

About the Role

This role works collaboratively with IT leadership, internal departments, cybersecurity personnel, vendors, and other technical resources, the Senior Systems Engineer provides advanced technical expertise, develops and maintains comprehensive system documentation, supports technology and cybersecurity initiatives, and contributes to the development of a secure, resilient, scalable, compliant, and highly available technology environment capable of supporting the organization’s current and future business and federal contracting requirements.

What You'll Be Doing

Enterprise Infrastructure & Cloud Administration

- Administer, maintain, monitor, secure, and optimize enterprise servers, networks, storage, endpoints, cloud services, virtualization platforms, and other critical IT infrastructure to ensure availability, performance, resiliency, and security.

- Manage Microsoft 365 Commercial and GCC High, including Exchange Online, SharePoint Online, Teams, OneDrive, and related Microsoft cloud services.

- Administer Microsoft Azure and Microsoft Entra ID, including users and groups, enterprise applications, authentication, MFA, Conditional Access, RBAC, privileged access, Azure Policy, resource governance, and lifecycle management.

- Manage Windows Server and Active Directory environments, including Group Policy, DNS, DHCP, file services, certificates, and other core infrastructure services.

- Administer and support VMware and Microsoft Hyper-V environments, including hosts, virtual machines, storage, resource allocation, performance, patching, and lifecycle management.

- Support enterprise networking, including routers, switches, firewalls, wireless, VPNs, VLANs, WAN connectivity, network segmentation, DNS/DHCP, and network security technologies.

- Monitor infrastructure for availability, capacity, performance, security events, and operational issues and troubleshoot complex infrastructure, application, authentication, endpoint, network, and cybersecurity problems.

- Plan and execute infrastructure upgrades, system migrations, technology refreshes, cloud implementations, and modernization initiatives, including capacity and technology lifecycle planning.

- Manage technology services such as Microsoft licensing, cloud subscriptions, certificates, domains, warranties, support agreements, and vendor relationships.

Cybersecurity, CMMC & Infrastructure Security

- Support implementation and ongoing compliance with NIST SP 800-171, CMMC, federal contractor cybersecurity requirements, and applicable organizational security standards.

- Implement, maintain, document, and validate technical controls protecting CUI, FCI, and other sensitive organizational information.

- Support the definition and maintenance of the organization's CMMC Assessment Scope, including identification and categorization of CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets.

- Maintain associated asset inventories, system boundaries, network and architecture diagrams, data flows, configurations, and technical documentation required to support cybersecurity assessments.

- Implement and maintain secure configurations using approved security baselines, DISA STIGs, CIS Benchmarks, Microsoft Security Baselines, hardening standards, and configuration requirements.

- Participate in cybersecurity assessments, control reviews, vulnerability assessments, POA&Ms, remediation activities, audits, and other compliance initiatives.

- Administer endpoint security and management technologies, including Microsoft Intune, Defender for Endpoint, Defender for Office 365, Defender for Identity, EDR, antivirus/anti-malware, encryption, application control, and device compliance.

- Manage operating system and application patching and vulnerability remediation, ensuring vulnerabilities are evaluated, prioritized, remediated, documented, and validated.

- Administer and support centralized logging and SIEM capabilities, including log collection, retention, correlation, alerting, monitoring, reporting, and integration across infrastructure, endpoints, networks, cloud, identity, and security platforms.

- Monitor security alerts and system events and participate in cybersecurity incident response, including identification, investigation, containment, remediation, recovery, documentation, and post-incident review.

Identity, Access & Data Protection

- Manage user accounts, security groups, service accounts, administrative privileges, and access controls in accordance with least privilege and role-based access principles.

- Administer privileged identity capabilities, including Privileged Identity Management (PIM), privileged administrative accounts, emergency/break-glass accounts, service accounts, managed identities, service principals, and privileged-access recertification.

- Maintain identity lifecycle processes for onboarding, transfers, role changes, and terminations, including appropriate provisioning, modification, disabling, and removal of access.

- Implement and support MFA, SSO, Conditional Access, RBAC, privileged access, and other identity security technologies.

- Administer and support Microsoft security and compliance capabilities, including Microsoft Purview, sensitivity labels, Data Loss Prevention (DLP), retention, information protection, and device compliance controls.

- Review and secure Microsoft 365, SharePoint, OneDrive, Teams, Azure, and other data repositories to address excessive permissions, oversharing, inappropriate access, and potential exposure of sensitive information.

Backup, Recovery & Business Continuity

- Administer enterprise backup, restoration, replication, and disaster recovery solutions to ensure the availability, integrity, and recoverability of organizational systems and data.

- Perform and document backup restoration testing and participate in disaster recovery and business continuity exercises, supporting established Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

- Maintain appropriate security controls for backup and recovery infrastructure to protect against unauthorized access, ransomware, data loss, and other threats.

AI, Automation & Emerging Technologies

- Serve as a senior technical resource for the evaluation, implementation, integration, security, administration, governance, and support of AI, Generative AI, intelligent automation, machine learning, and other emerging technologies.

- Support the organization's enterprise AI strategy by identifying opportunities to use AI and automation to improve IT operations, cybersecurity, productivity, service delivery, analytics, knowledge management, reporting, and business processes.

- Evaluate, implement, administer, and support approved technologies such as Microsoft Copilot, Microsoft 365 Copilot, Azure AI services, AI-enabled security technologies, Power Automate, Microsoft Graph, PowerSh

Apply on the employer’s site