- Job type
- Full-time
- Work mode
- Hybrid
- Level
- Not listed
- Department
- Information Technology
- Experience
- 4+ years experience
- Posted
- Aug 5, 2026
About the role
Job Summary:
The Network System Administrator will administer and maintain the reliability of Lynk's corporate network and core infrastructure — connecting Chevy Chase, MD and Chantilly, VA and supporting a globally distributed, mission-critical operation. This role is responsible for network administration, server and systems infrastructure, and the security/compliance posture of Lynk's infrastructure stack, including maintaining endpoint compliance in support of Lynk's CMMC Level 2 requirements. The role also serves as an escalation point for basic end-user IT support. This position is based in our Chevy Chase, MD office and will require some travel to our Chantilly, VA office as needed (Hybrid: 2–3 days onsite per week).
Duties & Responsibilities:
- Configure, deploy, and maintain LAN/WAN, wireless, VPN, and firewall infrastructure across Lynk office and lab locations
- Administer network segmentation, routing, and VLANs, and support capacity planning as the company scales
- Administer and harden core infrastructure: Microsoft Entra ID (Azure AD), Conditional Access, DNS/DHCP, Office 365, and endpoint security (ESET, Microsoft Defender) at the systems-administration level
- Manage endpoint and device compliance through Microsoft Intune and MDM platforms (e.g., NinjaOne), including policy design, patch management, and fleet-wide enforcement
- Deploy, monitor, and maintain security posture via Microsoft Defender (Endpoint/365) — threat detection, alerting, and remediation
- Manage server infrastructure (physical and virtual), including provisioning, patching, backup, and lifecycle management
- Monitor network and infrastructure health; lead incident response and root-cause analysis for outages and performance issues
- Implement and maintain infrastructure security controls (firewalls, VPN, MFA, network segmentation, endpoint protection) in line with ITAR and export-control obligations
- Support Lynk's CMMC Level 2 compliance program — maintain endpoint compliance (patching, configuration baselines, encryption, access control) across the device fleet and evidence controls for audits
- Monitor and remediate endpoint compliance drift via Intune/NinjaOne and Microsoft Defender to keep the environment aligned with NIST SP 800-171 control requirements
- Partner with security/compliance stakeholders on System Security Plans (SSPs), POA&Ms, and audit readiness for CMMC assessments
- Document network topology, infrastructure configuration, and disaster recovery/business continuity procedures
Basic End-User IT Support:
- Serve as a secondary/escalation point of contact for basic end-user technical issues (hardware, software, connectivity, account access)
- Provision and configure end-user hardware (laptops, peripherals) in line with security and compliance baselines
- Troubleshoot common Windows/macOS and Office 365 issues for staff as needed
- Support onboarding/offboarding from an infrastructure and access-management perspective (accounts, device enrollment, permissions)
Qualifications:
- 4+ years of experience in network engineering, systems administration, or infrastructure management
- Hands-on experience administering and maintaining LAN/WAN, VPN, firewall, and wireless network infrastructure
- Strong Windows Server and macOS environment administration experience
- Experience managing Microsoft Entra ID (Azure AD), Conditional Access, and Office 365 at an administrative/architectural level
- Hands-on experience with Microsoft Intune for device/endpoint management and compliance policy
- Experience with MDM platforms such as NinjaOne, ManageEngine, or similar
- Experience deploying and managing Microsoft Defender (Endpoint/365) or comparable endpoint security/EDR tooling
- Understanding of network security fundamentals: firewalls, segmentation, VPN, and endpoint protection
- Familiarity with CMMC Level 2 / NIST SP 800-171 control requirements and experience maintaining endpoint compliance in a regulated environment
- Comfortable providing basic end-user technical support alongside infrastructure duties
- Strong documentation, troubleshooting, and incident-response skills
- Relevant certification preferred (e.g., CompTIA Network+/Security+, CCNA, Microsoft Certified: Intune/Endpoint Manager, or equivalent experience)
Bonus:
- Experience with PowerShell or other scripting/automation tools
- Direct experience preparing for or supporting a CMMC Level 2 assessment (SSP/POA&M development, C3PAO audit support)
- Experience supporting infrastructure in a regulated or export-controlled (ITAR) environment
- Previous startup experience is a strong plus
ITAR Requirements:
To comply with U.S. Government export control regulations (ITAR), applicants must be one of the following: (i) a U.S. citizen or national, (ii) a lawful permanent resident (green card holder), (iii) a refugee under 8 U.S.C. § 1157, or (iv) an asylee under 8 U.S.C. § 1158. Individuals who do not meet these criteria must be eligible to obtain the necessary authorizations from the U.S. Department of State.
Learn about ITAR here: https://www.pmddtc.state.gov