Mount Indie is seeking a Windows OS Security & STIG Administrator to secure, administer, and maintain Windows environments across on-premises infrastructure and Oracle Cloud Infrastructure (OCI). This role will focus on Windows administration, DISA STIG implementation, cybersecurity compliance, vulnerability remediation, and secure configuration management. The environment is transitioning toward OCI, and this position will support both current on-premises operations and OCI-based workloads. The successful candidate will collaborate with the Ansible automation lead to integrate Windows security requirements into automated hardening and compliance processes. Git will be used for version control, peer review, documentation, and change management.
Key Responsibilities
- Administer and secure Windows Server environments across on-premises and OCI infrastructure.
- Implement, assess, and remediate DISA STIG requirements for Windows operating systems.
- Analyze and remediate CAT I, CAT II, and CAT III findings.
- Support consistent Windows security baselines across on-premises and OCI environments.
- Provide Windows-specific requirements, testing, and troubleshooting support for Ansible playbooks and roles.
- Execute and troubleshoot Ansible-based hardening, compliance validation, and remediation activities. Use Git for branching, pull requests, peer review, issue tracking, and controlled change management.
- Develop and maintain PowerShell scripts, configuration checks, and validation utilities. Support Group Policy, Active Directory, auditing, least privilege, patching, and vulnerability management. Support OCI services and security controls, including Compute, VCNs, IAM, compartments, security lists, network security groups, logging, and monitoring.
- Evaluate the impact of STIG controls on OCI agents, monitoring tools, management services, and system connectivity. Maintain compliance evidence, remediation records, exception documentation, POA&M inputs, and technical procedures. Collaborate with Windows, cloud, cybersecurity, automation, and infrastructure teams.
Required Qualifications
- 5 or more years of Windows Server administration experience.
- 3 or more years of hands-on Windows STIG implementation, assessment, or remediation experience. Strong knowledge of Windows security baselines, Group Policy, Active Directory, auditing, least privilege, patching, and vulnerability remediation.
- Experience with Ansible for Windows configuration management, security hardening, or compliance activities.
- Experience with Git, including branching, pull requests, peer review, and change tracking. Strong PowerShell skills and a software engineering mindset, including testing, documentation, reusable code, and controlled releases. Experience securing Windows environments across on-premises and cloud infrastructure.
- Experience with OCI or a comparable cloud platform.
-
Minimum Secret security clearance required.
-
DoD 8570 IAT Level II certification, such as CompTIA Security+, or another customer-approved equivalent aligned with applicable DoD 8140 requirements.
- Strong technical documentation, troubleshooting, and communication skills.
Preferred Qualifications
- Experience with Windows Server 2016, 2019, 2022, or later.
- Experience with WinRM over HTTPS and Windows Ansible modules.
- Experience with STIG Viewer, SCAP Compliance Checker, Evaluate-STIG, or comparable tools.
- Experience supporting Windows workload migration to OCI. Familiarity with CI/CD, infrastructure as code, DevSecOps, or automated testing. Python or another scripting language.
-
OCI certification or equivalent hands-on experience.
- Experience in federal, defense, regulated, or compliance-driven environments.