Systems Administrator II (Microsoft 365 GCC & GCC High)

Systems Application & Technologies IncOxnard, CA
$95,000 - $120,000Onsite

About The Position

Systems Application & Technologies, Inc. (SA-TECH) is seeking a Systems Administrator II to manage two Microsoft government cloud tenants: an enterprise Microsoft 365 GCC tenant for corporate operations and a Microsoft 365 GCC High enclave for Controlled Unclassified Information (CUI). This is a full-time, on-site position in Oxnard, CA. The role serves as a Tier 2 technical escalation point, with a progression to Tier 3 within 12-18 months, including mentoring junior staff. The position operates under a mature governance model with change control, just-in-time privileged access, and audited work, focusing on documented, least-privilege, and repeatable systems administration. The role involves hands-on operational administration, ensuring the separation between tenants, supporting information protection, managing identity and access, administering endpoints via Intune, scripting for automation, executing changes through change control, capturing evidence for CMMC Level 2 readiness, and improving standard operating procedures. The position also involves serving as a Tier 2 escalation point, mentoring junior staff, and supporting Azure Government services as the environment evolves. Privileged administration and CUI-related work are performed on-site using SA-TECH-managed equipment.

Requirements

  • High School Diploma or equivalent.
  • Three years or more (3+) of hands-on systems administration experience in a Microsoft 365 / Entra ID environment.
  • Working proficiency with Entra ID (users, groups, roles, Conditional Access), Exchange Online, SharePoint Online/OneDrive, Teams, and Intune.
  • PowerShell scripting experience, including Microsoft Graph PowerShell or equivalent administrative automation.
  • Understanding of multi-factor authentication, least-privilege administration, and role-based access control concepts.
  • Strong documentation habits and the discipline to work within change control and standard operating procedures.
  • Clear written and verbal communication, including the ability to explain technical work to non-technical stakeholders and, when needed, to assessors.
  • Must possess valid US Drivers’ license; must be able to be insured through SA-TECH's vehicle insurance policy while driving work/government/rental vehicles during working hours, and for the duration of your work employment.
  • U.S. Citizenship required and you must be able to obtain a U.S. DoD Secret Security Clearance prior to start date and maintain a Secret clearance throughout employment.
  • All candidates will be required to pass background screening to include SSN, Driver Record, and Criminal Background Investigation.

Nice To Haves

  • Experience administering Microsoft 365 GCC High and/or GCC, including familiarity with U.S. government cloud endpoints and their differences from commercial M365 would be very beneficial.
  • Familiarity with NIST SP 800-171, CMMC Level 2, and DFARS 252.204-7012 obligations in a defense-contractor setting is a plus.
  • Experience implementing privileged-access management, phishing-resistant MFA, or dedicated administrative workstation patterns in Microsoft environments would be very helpful.
  • Experience supporting compliance assessments or audits (evidence gathering, walkthroughs, interviews) would be beneficial.
  • Relevant certifications such as CompTIA Security+, MD-102, MS-102, SC-300, or AZ-104 are preferred.
  • Experience with Azure (Azure Government preferred), Microsoft Purview, or Defender-family security tooling is a big plus.
  • Prior DoD or federal IT experience — hands-on IT or technical work performed for, or in direct support of, DoD or other federal components (uniformed service, government civilian, or contractor) is an added advantage.
  • Formal education — an associate's or bachelor's degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience or military technical training is preferred.
  • Clearance eligibility — the ability to obtain and maintain a U.S. security clearance should future contract requirements direct it; an active or previously held DoD security clearance is a plus.

Responsibilities

  • Microsoft 365 tenant administration (GCC and GCC High)
  • Administer core workloads across both tenants — Entra ID, Exchange Online, SharePoint Online, OneDrive, and Teams — including user and group lifecycle, licensing, and tenant configuration.
  • Maintain the separation between the enterprise GCC tenant and the GCC High CUI enclave, following SA-TECH's adopted boundary model and data-handling rules.
  • Support information-protection configurations (sensitivity labeling, DLP, sharing restrictions) in coordination with the Director of IT and the security operations function.
  • Operate a just-in-time, least-privilege administrative model with modern, phishing-resistant authentication — privileged work is time-bound, justified, and audited.
  • Administer identity and access management across both tenants: authentication policy, conditional access, and the credential lifecycle for users and administrators.
  • Manage service and special-purpose accounts according to documented configuration baselines and procedures.
  • Perform account provisioning, deprovisioning, and access changes tied to personnel actions, and support recurring account reconciliation reviews.
  • Administer Microsoft Intune for company devices — enrollment, configuration baselines, update regimens, and device lifecycle workflows across desktop and mobile platforms.
  • Follow SA-TECH's dedicated administrative workstation practices for privileged work, and help maintain the supporting configuration baselines.
  • Coordinate with the security operations function on endpoint protection; monitoring and independent review remain separated from this role by design.
  • Script and automate administrative work with PowerShell and Microsoft Graph, including against government cloud endpoints.
  • Execute changes through SA-TECH's change-control process: submit and implement approved change requests, keep configuration baselines current, and document what was done.
  • Capture and file evidence of administrative work (configuration exports, transcripts, screenshots) to support CMMC Level 2 assessment readiness — evidence capture is built into our procedures, not an afterthought.
  • Follow, improve, and help author standard operating procedures; propose better ways of doing things through the governance process rather than around it.
  • Serve as the Tier 2 escalation point for junior IT staff and provide day-to-day mentoring, progressing to Tier 3 escalation authority.
  • Support Azure Government services connected to the enclave as the environment evolves.
  • Mentor more junior IT staff.

Benefits

  • Medical, Dental, Vision
  • Life Insurance
  • Long-Term Disability
  • 401(k) match
  • Flexible Spending Accounts
  • EAP
  • Education Assistance
  • PTO and Holidays
  • Vacation and Sick Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service