IT Admin

SkyetonFayetteville, NC
Onsite

About The Position

The IT Administrator owns day-to-day information technology, network and cloud infrastructure, business-systems support and development, and cybersecurity across Skyeton Inc.'s U.S. locations. This hands-on role supports employees and operational systems; administers endpoints, identity, networks, servers, collaboration platforms, source control, and cloud services; and maintains reliable, secure access to the technology the business depends on. The position also specifies, reviews, tests, and deploys changes to internal business systems and integrations, including AI-assisted development completed under human engineering review and established software-governance controls. The IT Administrator is responsible for security hardening, monitoring, incident response, access control, documentation, and technical compliance evidence supporting ITAR/EAR, Controlled Unclassified Information, NIST SP 800-171, DFARS 252.204-7012, CMMC, and customer requirements. The role is an individual contributor initially and may grow into leadership of a small IT and security team.

Requirements

  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a closely related technical discipline. Equivalent demonstrated experience will be considered, but this role is engineering work and the bar is set there.
  • 4+ years combining hands-on IT administration with real software development. We are looking for someone who has genuinely done both, not someone who has done one and read about the other.
  • Scripting and software development you can show us — Python strongly preferred. You have written and shipped something a business depended on, and you can talk about how it was reviewed, tested, and released.
  • Code review as a first-class skill. You can read code you did not write, understand what it is actually doing, and say clearly why it is wrong. Much of this role is judgement applied to someone else's — or something else's — output.
  • Git and modern source-control discipline — branches, merge requests, code review, CI/CD pipelines. You have worked somewhere that took review and release process seriously, and you did not find it an obstacle.
  • Willingness to develop with AI coding agents, and to be accountable for what they produce. Prior experience with Claude Code, Copilot, Cursor, or similar in a real codebase is a strong plus; the non-negotiable part is the temperament — you neither refuse the tool nor trust it.
  • REST API integration experience — you have made two systems talk to each other in production, and you have dealt with what happens when one of them is down.
  • Demonstrated experience administering Windows endpoints and a cloud identity and productivity suite (Microsoft 365 / Entra ID, Google Workspace, or equivalent): identity lifecycle, MFA, conditional access, groups, and permissions.
  • Linux server administration — you are comfortable on a shell, with systemd, logs, packages, and services.
  • Networking you can defend in an interview: TCP/IP, DNS, DHCP, routing, VLANs, managed switching, firewall rule design, VPN, and wireless. You can read a packet capture and explain what you are looking at.
  • Cybersecurity fundamentals in practice, not just in theory: least privilege, secure baseline configuration, network segmentation, vulnerability management, logging and detection, incident response, and data protection.
  • Working familiarity with at least one compliance framework — NIST SP 800-171, NIST SP 800-53, CMMC, ISO 27001, or similar — including what evidence actually satisfies a control.
  • Clear technical writing. Our plans, runbooks, and security documents are read by people who are not you.
  • Ability to prioritise ruthlessly across three lanes of work and communicate honestly about what is and is not getting done.
  • High integrity and discretion. This role sees payroll systems, financial systems, export-controlled technical data, and every credential in the company.
  • US citizen, able to obtain and maintain a US security clearance, and able to work under ITAR / EAR controls.

Nice To Haves

  • CompTIA Security+ (DoD 8140 / 8570 IAT Level II baseline). If you do not hold it, we expect you to earn it within twelve months and we will pay for it.
  • Additional certifications, held or in progress: CompTIA Network+, CySA+, or CASP+; Cisco CCNA or CCNP Security; Microsoft SC-200 / SC-300 / AZ-104; GIAC (GSEC, GCIH, GCIA); CISSP or CISM for a more senior candidate.
  • Hands-on experience implementing NIST SP 800-171 and preparing for a CMMC assessment — the system security plan, the POA&M, and the evidence behind them.
  • FIPS 140-3 validated cryptography experience, and a working understanding of where FIPS validation is required versus where strong encryption alone is enough.
  • Public-cloud experience, AWS preferred — compute, VPC and subnet design, identity and access management, secrets and parameter storage, object storage, monitoring, backup and snapshot strategy, and cost management. Experience in a cloud region operating under a US government compliance boundary is a significant plus, as is any cloud certification (AWS Cloud Practitioner, Solutions Architect Associate, SysOps Administrator, or Security Specialty, or the Azure equivalents).
  • Infrastructure as code — Terraform, Ansible, or CloudFormation — and a genuine dislike of hand-built servers.
  • Substantial experience developing with AI coding agents in a production codebase, including what you changed about your own review habits once you started.
  • ERP development or extension experience on any major platform — SAP, NetSuite, Odoo, Dynamics, or an open-source ERP — including custom objects, workflows, permissions, and API integration.
  • Administration of a self-hosted source-control and CI platform (GitLab, Gitea, Bitbucket Server, or similar), runner management, and pipeline authoring.
  • Zero-trust or overlay-network experience and access-policy design for a mesh or software-defined perimeter.
  • API integration work against commercial accounting, expense, HR, or similar business platforms.
  • Experience supporting aerospace, defense, or another regulated manufacturing environment; familiarity with production-floor systems, CAD, PDM, or MES.
  • Experience in a startup, greenfield, or rapidly scaling organisation — you have been the whole IT department before and it did not break you.
  • Active or recently held US security clearance.
  • US military veteran or DoD program experience; familiarity with the NC / Sandhills / Fort Bragg labor market.

Responsibilities

  • Own the full endpoint lifecycle for every Skyeton Inc. US employee: procure, image, configure, deploy, patch, encrypt, support, recover, and retire laptops, desktops, mobile devices, and peripherals against a documented standard build.
  • Provide responsive Tier 1 and Tier 2 support across all sites for endpoints, business applications, printing, conference-room technology, and shop-floor systems.
  • Administer the corporate email, collaboration, file-sharing, and cloud identity platform: directory and group management, multifactor authentication, conditional access, licensing, and permissions.
  • Run onboarding and offboarding end to end with HR: account provisioning, group and role assignment, equipment issue, and access removal on departure.
  • Maintain an accurate asset, license, warranty, and configuration inventory. Track spend and lifecycle so equipment refresh is planned, not reactive.
  • Own the wired and wireless networks at every Skyeton Inc. site: switching, VLAN segmentation, firewalls, wireless, structured cabling, internet and carrier services, and the remote-access layer.
  • Segment the production floor from the office. Network-connected manufacturing equipment — CNC, cure-room controls, test stands, booths, inspection gear — belongs on its own segment, with deliberate and documented rules about what may cross.
  • Stand up the network and IT infrastructure for new sites and facility build-outs, from the cabling drawing to the day the first person plugs in.
  • Administer Linux and Windows servers and the company's cloud footprint, in coordination with the existing infrastructure-as-code and following it.
  • Own the remote-access and zero-trust network layer: device enrolment, group membership, access policy, and the identity checks behind it.
  • Own backup, restore, business continuity, and disaster recovery. Test the restores and document the results.
  • Monitor availability, capacity, storage, and alerting; investigate and resolve before users report the problem.
  • Specify, direct, review, and ship changes to Skyeton Inc.'s business systems: the ERP (Python / JavaScript) and its custom document types and extensions; the leadership dashboards; the accounting, card-spend, and HR integrations; other internal API integrations; and the supporting infrastructure-as-code.
  • Develop with AI coding agents — and own what they produce.
  • Improve the harness itself: the project rules, the prompts, the tests, and the CI gates that make agent output reliable.
  • Work the governance pipeline as follows: A work item first. Nothing gets built before there is a work item defining it. A plan document, not a comment. The plan states the problem, the source of truth for every value, the design, the companion merge requests, verification, rollout, rollback, what "done" looks like, and the open questions. It is agreed before code is written. A merge request with a green pipeline. Fast-forward-only, rebased, squashed. A gate that cannot fail does not exist — no advisory checks, and nothing merges through a known-red pipeline. Rehearse on staging before production, same tool and same flags, from a fresh production restore. First-time code paths never execute on production first. Production deploys are deliberate and human-run — a prepared release script that a human reads and runs, never a CI button and never because a merge request landed. Every ERP extension is registered in the extensions register in the same commit, so the next person can trace every departure from stock. Done means finished. A change that needs something outside itself is not mergeable, and work does not end with a list of loose follow-ups.
  • Respect the source-of-truth doctrine. Data lives only in its system of record and is pulled from there. Nothing copies, caches, or re-keys data as a workflow.
  • Support and administer the systems you build: ERP user and role provisioning, workflow and approval configuration, print formats, scheduled jobs, integrations, upgrades, and the unglamorous reliability work behind all of it.
  • Protect separation of duties in ERP. A single-role individual must never be able to raise and approve the same document. Re-audit after every role grant — particularly the superuser roles, which bypass workflow controls entirely.
  • Own the source-control server, the build runners, and the health of the pipelines. Infrastructure or pipeline changes freeze feature merges until proven — the gates cannot vouch for anything while they are moving.
  • Own Skyeton Inc.'s technical security posture: secure baseline configurations, hardening standards, patch and vulnerability management, endpoint detection and response, logging and monitoring, and least-privilege access across every system.
  • Hold the line on defense in depth. Every sensitive surface gets two independent checks, never one, and access is granted per group rather than per network.
  • Own secrets handling: secrets live in the approved secrets manager, never in a repository, never on a command line, never echoed to a log. Rotate immediately on any suspected exposure, and build the tooling so the safe path is the easy path.
  • Own the technical controls and the evidence behind NIST SP 800-171, DFARS 252.204-7012, CMMC, ITAR / EAR, and customer-specific cybersecurity flow-downs. Maintain the system security plan, the POA&M, and the artefacts an assessor will ask for — before they ask.
  • Identify and mark Controlled Unclassified Information, enforce its handling rules, and implement FIPS 140-3 validated cryptography where CUI requires it.
  • Run incident response: detection, triage, containment, investigation, notification, and corrective action. Every incident becomes a check — a test, a gate, or a control, so the same thing cannot happen twice.
  • Run phishing simulation, security awareness training, and periodic access reviews with business owners.
  • Support export-control compliance on the technical side: access segregation for controlled technical data, foreign-national access controls, and the audit trail behind both.
  • Author and maintain the security management-system documents under Skyeton Inc.'s document standard, and keep the revision history in git.
  • Manage managed service providers, carriers, software vendors, and equipment suppliers; drive service issues to resolution rather than merely tracking them.
  • Evaluate technology needs, obtain quotes, recommend practical solutions, and support IT purchasing, lifecycle planning, and budget tracking.
  • Report on system availability, security posture, open vulnerabilities, and business-systems delivery to the VP of Engineering and Manufacturing.
  • Participate in after-hours maintenance windows and urgent incident response when the business needs it.
  • All other duties as assigned by Skyeton leadership.

Benefits

  • Paid Time Off (PTO)
  • 401(k) plan with company match
  • Medical insurance: company-paid employee coverage
  • Dental and vision insurance
  • Competitive salary commensurate with experience
  • Sign-on and relocation assistance may be negotiable
  • Equity eligibility in accordance with Skyeton compensation policy
  • Company-funded training and role-relevant professional certifications
  • Bonus opportunity tied to company milestones and ongoing performance
  • Career growth opportunities within a rapidly expanding aerospace organization
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service