Systems Administrator II (Microsoft 365 GCC & GCC High)
Summary
Administers Microsoft 365 GCC/GCC High tenants for a DoD contractor, managing user/device lifecycle, identity/access controls, and compliance workflows (NIST 800-171/DFARS) with PowerShell/Graph API. Focuses on governance, automation, and evidence capture for CMMC Level 2 readiness.
Position Type: Full-Time, Exempt
Work Location: Oxnard, CA
Pay Info: $95,000 - $120,000 (DOE)
Systems Application & Technologies, Inc. (SA-TECH) is a progressive and well-established Department of Defense (DoD) contractor specializing in Range operations and maintenance (O&M); weapons testing; facilities management; aerial, ground and seaborne targets O&M; technical, logistics and other engineering support; systems integration; electronics and communications maintenance services; and a growing cybersecurity business. We are highly focused and, among other efforts, currently operate a dozen active test and/or training ranges for the Army, Air Force and Navy. Our 36-year heritage is founded on supporting complex and diverse DoD programs and we’ve developed a standout reputation for providing the highest quality services, superior workmanship and cost-effective results while achieving complete customer satisfaction.
As a U.S. defense contractor providing operations & maintenance, engineering, IT, and logistics services to DoD customers, we operate a modern, cloud-first Microsoft environment built on Microsoft 365 GCC and GCC High, backed by an established, well-documented cybersecurity program aligned to NIST SP 800-171 and CMMC Level 2.
We are currently looking to hire a Systems Administrator II to serve as the hands-on operational administrator of our two Microsoft government cloud tenants: an enterprise Microsoft 365 GCC tenant supporting corporate operations, and a Microsoft 365 GCC High enclave where Controlled Unclassified Information (CUI) is processed under NIST SP 800-171 and DFARS requirements. This is a full-time, on-site position at SA-TECH’s Oxnard, CA Operations office.
This Level II role reports directly to the Director of IT. You enter as the Tier 2 technical escalation point, with an expected progression to Tier 3 within your first 12-18 months while you master the environment, including mentoring junior IT staff. You will execute administrative work under a mature governance model: changes go through change control, privileged access is just-in-time and audited, and the work you do is captured as assessment-ready evidence. If you take pride in doing systems administration the right way — documented, least-privilege, repeatable — you will recognize this environment as one built for you.
What you'll do (other duties may be added as needed):
- Microsoft 365 tenant administration (GCC and GCC High)
- Administer core workloads across both tenants — Entra ID, Exchange Online, SharePoint Online, OneDrive, and Teams — including user and group lifecycle, licensing, and tenant configuration.
- Maintain the separation between the enterprise GCC tenant and the GCC High CUI enclave, following SA-TECH's adopted boundary model and data-handling rules.
- Support information-protection configurations (sensitivity labeling, DLP, sharing restrictions) in coordination with the Director of IT and the security operations function.
- Identity, access, and privileged administration
- Operate a just-in-time, least-privilege administrative model with modern, phishing-resistant authentication — privileged work is time-bound, justified, and audited.
- Administer identity and access management across both tenants: authentication policy, conditional access, and the credential lifecycle for users and administrators.
- Manage service and special-purpose accounts according to documented configuration baselines and procedures.
- Perform account provisioning, deprovisioning, and access changes tied to personnel actions, and support recurring account reconciliation reviews.
- Endpoint and device management
- Administer Microsoft Intune for company devices — enrollment, configuration baselines, update regimens, and device lifecycle workflows across desktop and mobile platforms.
- Follow SA-TECH's dedicated administrative workstation practices for privileged work, and help maintain the supporting configuration baselines.
- Coordinate with the security operations function on endpoint protection; monitoring and independent review remain separated from this role by design.
- Automation, evidence, and operational discipline
- Script and automate administrative work with PowerShell and Microsoft Graph, including against government cloud endpoints.
- Execute changes through SA-TECH's change-control process: submit and implement approved change requests, keep configuration baselines current, and document what was done.
- Capture and file evidence of administrative work (configuration exports, transcripts, screenshots) to support CMMC Level 2 assessment readiness — evidence capture is built into our procedures, not an afterthought.
- Follow, improve, and help author standard operating procedures; propose better ways of doing things through the governance process rather than around it.
- Team support
- Serve as the Tier 2 escalation point for junior IT staff and provide day-to-day mentoring, progressing to Tier 3 escalation authority.
- Support Azure Government services connected to the enclave as the environment evolves.
- Mentor more junior IT staff.
SA-TECH maintains deliberate separation of duties: governance and approvals, independent security oversight, and operational execution are distinct functions. This role owns execution — performing the administrative and configuration work in both tenants under that governance and oversight. You will have real responsibility and real authority to do the work — with clear limits, clear approvals, and an audit trail that protects you as much as the company.
This position is based full-time, on-site at SA-TECH’s Oxnard, CA Operations office. Privileged administration and CUI-related work are performed on-site on SA-TECH-managed equipment in accordance with our data-handling and dedicated administrative workstation practices.
The annual base salary range for this position is $95,000 – $120,000. Actual base pay within this range is determined by job-related factors including relevant experience, skills, certifications, education, and internal equity, consistent with California pay-transparency requirements. SA-TECH also offers a comprehensive benefits package.
Work Conditions:
- Work will be performed in climate-controlled enclosed buildings.
- Work will include sitting, standing, walking, lifting and reaching.
- The typical work schedule is Monday - Friday, 7am - 4pm, with occasional planned after-hours maintenance windows scheduled through change control.
- You will be working in front of computer screens for most of the day.