We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Systems Administrator

MIT Lincoln Laboratory
tuition reimbursement, 401(k), remote work
United States, Massachusetts, Lexington
244 Wood Street (Show on map)
Aug 27, 2026


Select how often (in days) to receive an alert:

JOIN OUR TALENT NETWORK
Systems Administrator
Apply now

Date: Aug 26, 2026


Location:
Lexington, MA, US


Company:
MIT Lincoln Laboratory


Position Description

Seeking an experienced Windows OS engineer to serve as part of the Modern Endpoint Workspace Team responsible for engineering, automating, securing, and continuously evolving the Laboratory's enterprise Windows endpoint platform. The position will focus on modern endpoint management, policy driven provisioning, application delivery, security compliance, lifecycle management, endpoint analytics, and employee experience. The role will utilize DevSecOps practices and systems management tools such as HCL BigFix, Microsoft Endpoint Configuration Manager, PowerShell, Git, and application programming interfaces to improve reliability, security, and operational efficiency. The position will collaborate closely with partnering teams of identity, cyber, network, service management, research IT, and the Laboratory's Service Center to provide a consistent and supportable endpoint experience across supported Dell and Microsoft devices. Participation in an on-call rotation and occasional off-hour support is required, as is on-site troubleshooting when necessary. This position reports to the End Point Management group within the Laboratory's Digital Solutions Department.


Primary Duties
Platform Engineering and Development

  • Design and maintain automated endpoint provisioning and configuration workflows using HCL BigFix, Microsoft Endpoint Configuration Manager and OEM provisioning capabilities.
  • Create reusable automation and engineering solutions using PowerShell, Python, REST application programming interfaces, Git, and continuous integration and delivery practices.
  • Apply configuration as code principles, automated testing, source control, peer review, and structured release practices to endpoint engineering changes.
  • Plan and execute staged compatibility testing and deployment of Windows quality updates, feature updates, drivers, firmware, and security changes using deployment rings and controlled rollout strategies.
  • Evaluate existing management workloads and identify opportunities for enhancement while maintaining support for environments with specialized requirements.


Modern Endpoint Management and Experience

  • Utilize HCL BigFix for configuration settings, pushing OS and application updates and remediation fixlets.
  • Use endpoint telemetry, experience analytics, service desk trends, and operational data to identify reliability, performance, configuration, and employee experience issues.
  • Develop automated remediation for recurring endpoint health, configuration, performance, security, and application issues to reduce service desk demand and improve user experience.
  • Define and monitor endpoint service health measures including provisioning success, patch and configuration compliance, application reliability, device health, security posture, and remediation effectiveness.
  • Engineer the complete endpoint lifecycle from hardware standards and OEM integration through provisioning, configuration, operational management, refresh, secure wipe, and retirement.


Service Engineering and Support

  • Provide Tier 3 engineering escalation and root cause analysis, including collaboration with IT peer groups in central and research IT, vendor management, knowledge creation, problem diagnosis, and resolution management.
  • Support project initiatives through requirements gathering, prototyping, systems design, testing, validation, deployment planning, and operational transition.
  • Develop, publish, and maintain system documentation including requirements, design and build documentation, test plans, operational procedures, troubleshooting guides, and standard operating procedures according to department standards.
  • Review endpoint security alerts, vulnerabilities, configuration drift, and compliance issues and work with the Laboratory's Cyber team to prioritize and implement remediation.
  • Collaborate with Microsoft, hardware manufacturers, software vendors, and service providers to plan for and remediate operational issues affecting the endpoint platform.
  • Partner with the Service Center and Workplace Experience teams to improve self-service, supportability, employee experience, and adoption of endpoint services.


Required Skills

  • Modern Windows Endpoint Engineering: Experience managing Windows OS as a product across provisioning, configuration, application delivery, patching, security, and lifecycle management.
  • Modern Endpoint Management: Hands-on experience with enterprise endpoint management platforms such as HCL BigFix or Microsoft Endpoint Configuration Manager.
  • Automation and Development: Strong PowerShell automation capability and experience with reusable modules, structured error handling, application programming interfaces, Git, code review, and continuous integration and delivery practices. Python or another development language is beneficial.
  • DevSecOps Practices: Strong understanding of secure engineering, vulnerability remediation, automated testing, source control, continuous integration and delivery, and configuration as code principles.
  • Security and Compliance: Ability to engineer and maintain endpoint security controls aligned with Laboratory cybersecurity requirements, NIST 800 171, vulnerability management, zero trust principles, and applicable Windows security baselines.
  • Endpoint Analytics and Reliability: Experience using telemetry, operational metrics, device health data, and service trends to identify reliability issues and drive automated remediation and continuous improvement.
  • Documentation and Communication: Experience maintaining technical documentation, operational procedures, troubleshooting guides, testing records, and change documentation. Strong presentation, writing, and interpersonal communication skills.
  • Problem Solving and Collaboration: Very strong problem solving skills and the ability to work autonomously while reporting status at the appropriate level. Ability to collaborate effectively across teams with varying technical responsibilities.
  • Networking Fundamentals: Solid understanding of endpoint connectivity and troubleshooting including DNS, DHCP, TCP/IP, HTTPS and TLS, VPN, proxies, Kerberos, LDAP, SMB, wireless authentication, and certificate based authentication.


Preferred Skills

  • Advanced Endpoint Automation: Experience with Microsoft Graph, REST application programming interfaces, automated testing such as Pester, configuration as code, secrets handling, and automated compliance remediation.
  • Identity and Access Integration: Working knowledge of Microsoft Active Directory, authentication, certificates, and multi-factor authentication tokens.
  • Endpoint Security Controls: Experience with Microsoft Defender for Endpoint or equivalent endpoint detection and response tooling, BitLocker, attack surface reduction, Credential Guard, and application control technologies.
  • Endpoint Management Strategy: Experience designing co-management strategies between traditional enterprise endpoint management while enabling shadow IT delegative access to update research systems and applications.
  • Future Cloud Management : Working knowledge and/or experience with Microsoft inTune, Auto-pilot and Windows integration with EntraID.
  • Digital Employee Experience: Experience with endpoint experience monitoring, performance analytics, proactive remediation, service health measures, or digital employee experience platforms.
  • PKI Concepts: Knowledge of public key infrastructure concepts including certificate lifecycle management, device certificates, authentication certificates, and S/MIME.
  • Security Frameworks and Certifications: Familiarity with Security Plus, NIST 800 171, zero trust architecture, or related security frameworks and certifications.
  • Hardware Lifecycle Management: Experience with enterprise hardware standards, OEM integration, compatibility testing, firmware and driver management, refresh planning, secure wipe, and retirement.
  • IT Service Management: Familiarity with ITIL practices, service management, problem management, change management, and service catalog concepts.


Other Qualifications

  • Ability to obtain and maintain a security clearance is required for this position.
  • Position is hybrid where remote work is the norm but occasional on-site presence is required for system troubleshooting, hardware validation, and other operational needs.
  • Rely on experience and judgment to plan and accomplish goals with limited supervision.
  • Role requires flexibility, sound technical judgment, and creative problem solving to address evolving endpoint, security, and employee experience challenges.


Administrative Duties

  • Develop, publish, and maintain system documentation including requirements, design and build documentation, testing records, operational procedures, and standard operating procedures according to department standards.
  • Develop and deliver training for peers and end users on service features, enhancements, new applications, and endpoint capabilities to increase effective adoption and supportability.
  • Participate in change management, problem management, service improvement, and technical review activities as required.
  • Participation in on-call rotation and occasional off-hour support is required.


Minimum Qualifications

  • Typically, a bachelor's degree plus a minimum of 4 years of relevant experience or equivalent education and experience.
  • Detailed hands-on knowledge of Windows 11 endpoint operational and security architecture in an enterprise environment.
  • Hands on experience with modern Windows provisioning and management using enterprise endpoint management capabilities such as HCL BigFix and Microsoft Endpoing Configuration Management.
  • Hands-on experience managing Windows endpoints with HCL BigFix, Microsoft Endpoint Configuration Manager, Active Directory Group Policy, or similar traditional management platforms and the ability to support transition between management models.
  • Strong PowerShell scripting and automation skills with the ability to develop reliable, reusable solutions for endpoint management and remediation.
  • Working knowledge of Git, application programming interfaces, structured testing, and continuous integration and delivery practices.
  • Working knowledge of endpoint security technologies, vulnerability remediation, encryption, certificate management, and Windows security configuration.
  • Strong knowledge of endpoint networking and troubleshooting including DNS, DHCP, TCP/IP, HTTPS and TLS, VPN, proxies, Kerberos, LDAP, SMB, wireless authentication, and certificate-based authentication.
  • Experience validating endpoint compatibility across enterprise hardware platforms, drivers, firmware, security agents, and business applications.



THIS POSITION CAN BE REMOTE BUT THE CANDIDATE NEEDS TO BE WITHIN 100 MILES OF THE LAB AND COME IN AS NEEDED.


Hiring Range:$95,700-$126,700

Disclaimer: MIT Lincoln Laboratory provides a typical hiring range as a good faith estimate of what we reasonably expect to offer for this position at the time of posting. The final salary offered to a selected candidate will depend on various factors, including-but not limited to-the scope and responsibilities of the role, the candidate's experience, skills and education/training, internal equity considerations and applicable legal requirements. This range reflects base salary only and does not include additional forms of compensation or benefits.

At MIT Lincoln Laboratory, our exceptional career opportunities include many outstanding benefits to help you stay healthy, feel supported, and enjoy a fulfilling work-life balance. Benefits offered to employees include:




  • Comprehensive health, dental, and vision plans
  • MIT-funded pension
  • Matching 401K
  • Paid leave (including vacation, sick, parental, military, etc.)
  • Tuition reimbursement and continuing education programs
  • Mentorship programs
  • A range of work-life balance options
  • ... and much more!



Please visit our Benefits page for more information. As an employee of MIT, you can also take advantage ofother voluntary benefits, discounts and perks.

Selected candidate will be subject to a pre-employment background investigation and must be able to obtain and maintain a Secret level DoD security clearance.

MIT Lincoln Laboratory is an Equal Employment Opportunity (EEO) employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, or genetic information; U.S. citizenship is required.

Requisition ID: 43270





Nearest Major Market: Boston



Job Segment:
Testing, Laboratory, Firmware, System Administrator, Cloud, Technology, Science


Apply now



Find similar jobs:

Applied = 0

(web-77cf7d65c7-4vs2h)