Windows Systems Automation Engineer

Booz Allen HamiltonMcLean, VA
$86,800 - $198,000

About The Position

Secure cyber training environments need Windows systems that can be deployed, configured, tested, and removed consistently through automation. This role involves engineering Windows Server and workstation capabilities for isolated, cloud-based cyber ranges. The engineer will automate Active Directory, DNS, Group Policy, domain joins, security hardening, software installation, patching, and endpoint configuration using PowerShell and infrastructure as code. Responsibilities include developing reusable deployment components, bootstrap scripts, and automated machine-image pipelines, as well as integrating Windows systems with cloud services for identity, secrets management, logging, monitoring, and remote administration. The work ensures environments can be securely deployed and completely removed without manual configuration. Collaboration with platform engineers, network engineers, cybersecurity SMEs, and range operators is expected for troubleshooting. Applying STIGs, remediating vulnerabilities, documenting system designs, and continuously improving deployment reliability are also key aspects of the role.

Requirements

  • 6+ years of experience administering or engineering Windows Server environments
  • 2+ years of experience supporting a U.S. Government or federal environment
  • Experience with Active Directory, DNS, Group Policy, and automated domain provisioning
  • Experience developing PowerShell automation for infrastructure deployment, configuration, and security auditing
  • Experience with infrastructure-as-code tools such as AWS CDK, CloudFormation, or Terraform
  • Experience using Git and CI/CD pipelines to manage and deploy infrastructure changes
  • Experience with automated patching, compliance tracking, and endpoint management
  • Knowledge of STIGs, NIST SP 800-53 controls, and Windows security-hardening practices
  • Experience troubleshooting complex system, identity, network, and application issues
  • HS diploma or GED
  • DoD 8570/8140 IAT Level II-compliant certification, such as Security+, CySA+, or GSEC
  • Ability to obtain an IAT Level III-compliant certification, such as SecurityX, CISSP, or CCNP Security, within 6 months of start date

Nice To Haves

  • Experience administering Windows workloads in AWS
  • Experience with AWS Systems Manager, Secrets Manager, IAM, S3, or CloudWatch
  • Experience with AWS EC2 Image Builder, Packer, or another automated image-building platform
  • Experience with AWS CDK and TypeScript
  • Experience with PowerShell Desired State Configuration or Pester
  • Experience automating Microsoft Office and enterprise application deployment
  • Experience with SCCM, MECM, Chocolatey, or similar software-management tools
  • Experience administering Linux systems in a hybrid environment
  • Experience with SQL Server, PostgreSQL, or MongoDB
  • Experience building cyber ranges, test environments, or other disposable cloud infrastructure
  • Ability to clearly communicate technical designs and troubleshooting findings to engineers, operators, and leadership

Responsibilities

  • Automate Windows Server and workstation deployments using AWS CDK, CloudFormation, Terraform, or similar infrastructure-as-code tools
  • Design and maintain Active Directory, DNS, Group Policy, and identity services for isolated range environments
  • Develop advanced PowerShell scripts for provisioning, domain joins, configuration management, security auditing, and software installation
  • Build and maintain reusable Windows machine images through automated image pipelines
  • Apply STIGs and other security-hardening standards to Windows servers and endpoints
  • Automate patching, vulnerability remediation, inventory, and compliance reporting
  • Integrate systems with secrets management, logging, monitoring, and remote-management services
  • Develop automated tests and deployment validation to identify configuration issues before release
  • Troubleshoot complex Windows, Active Directory, authentication, networking, and application issues
  • Maintain technical documentation, configuration standards, and operational runbooks

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service