System Administrator (Endpoint) - Baltimore, MD(Onsite) - Onsite interview mandatory
Position Overview
We are seeking an experienced Systems Administrator Endpoint & Server Infrastructure to support enterprise endpoint and server environments. This position is ideal for a hands-on systems administrator with strong experience managing Windows environments, enterprise patching, system upgrades, vulnerability remediation, and endpoint management technologies.
The Systems Administrator will be responsible for the ongoing administration, maintenance, patching, upgrading, and lifecycle management of enterprise laptops, workstations, and server infrastructure.
The successful candidate will help ensure systems remain secure, stable, compliant, and current by managing operating system and security updates, testing and deploying patches, troubleshooting deployment failures, coordinating maintenance activities, and maintaining accurate infrastructure documentation.
This role requires experience supporting large enterprise environments and the ability to perform production maintenance while minimizing disruption to business operations.
Key Responsibilities
Endpoint & Patch Management
- Manage enterprise patching and update activities across Windows and macOS endpoints and Windows/Linux server environments.
- Schedule, test, deploy, and monitor operating system patches, security updates, hotfixes, and feature updates.
- Configure and maintain centralized endpoint and patch management solutions such as Microsoft Intune, Microsoft SCCM/Configuration Manager, and Microsoft Azure Update Manager.
- Develop and maintain automated patching policies and deployment schedules.
- Monitor patch compliance and identify systems that have failed or missed required updates.
- Troubleshoot deployment failures and remediate problematic endpoints and servers.
- Support firmware, driver, and BIOS updates across enterprise endpoint devices.
Security & Vulnerability Remediation
- Monitor security and vulnerability management platforms, including Microsoft Defender, for vulnerabilities, critical CVEs, missing patches, and required remediation activities.
- Prioritize and coordinate remediation of critical and high-risk vulnerabilities.
- Work with security and infrastructure teams to ensure systems meet organizational security and patch compliance requirements.
- Validate successful remediation and maintain appropriate evidence and documentation.
Server Administration & Maintenance
- Administer and maintain enterprise Windows Server environments, including Windows Server 2016 2022/2025.
- Support patching, upgrades, configuration changes, and routine maintenance of server infrastructure.
- Coordinate maintenance windows and perform production upgrades during approved off-hours when required.
- Monitor server health and investigate system issues related to patches, upgrades, configuration changes, and operating system performance.
- Develop and execute rollback and recovery procedures when upgrades or patches cause system instability.
Testing & Change Management
- Establish and maintain controlled testing and staging processes for patches and system upgrades.
- Validate operating system, application, and infrastructure compatibility before production deployment.
- Conduct post-deployment validation to confirm system stability and successful installation.
- Document deployment plans, test results, identified issues, rollback procedures, and production outcomes.
- Coordinate planned changes with technical teams and business stakeholders to minimize operational disruption.
Infrastructure Lifecycle Management
- Support the complete lifecycle of enterprise laptops, workstations, and servers.
- Maintain accurate hardware and software inventory information.
- Track operating system versions, firmware levels, patch status, and infrastructure configurations.
- Identify systems approaching end-of-support or end-of-life and assist with upgrade or replacement planning.
- Maintain configuration, inventory, maintenance, and patch schedule documentation.
Required Qualifications
Preferred Qualifications
- Experience with one or more of the following is highly desirable:
- Microsoft Azure Update Manager
- Microsoft Defender
- Windows Autopilot
- Microsoft Entra ID / Azure Active Directory
- PowerShell scripting and automation
- Windows Server administration
- Linux server patching and administration
- Enterprise vulnerability management
- Endpoint security and compliance management
Preferred Certifications
- One or more of the following certifications is preferred but not required:
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Relevant Microsoft Windows Server / Azure certification
- CompTIA Security+
- CompTIA Server+
- Other relevant Microsoft, cloud, infrastructure, or cybersecurity certifications
Key Competencies
- The ideal candidate will demonstrate:
- Strong hands-on troubleshooting and root-cause analysis skills
- Ability to manage large-scale patching and upgrade activities
- Attention to detail in security-sensitive production environments
- Strong ownership and follow-through
- Ability to prioritize critical vulnerabilities and operational issues
- Effective communication with infrastructure, security, application, and business teams
- Ability to document technical work clearly and maintain accurate operational records
- Ability to work independently while collaborating effectively within a technical team
What Success Looks Like
- Success in this role means maintaining a secure, reliable, and well-managed endpoint and server environment with:
- High patch and update compliance
- Timely remediation of critical vulnerabilities
- Minimal disruption from production upgrades
- Effective testing and rollback procedures
- Accurate infrastructure and lifecycle documentation
- Rapid identification and resolution of failed deployments
- Proactive management of systems approaching end-of-life or requiring upgrades