Lynk logo
Lynk

Network System Administrator

Chevy Chase, USAHybridPosted 1 month ago

Apply opens Lynk's site. When you're back, we'll ask whether you applied.

Job type
Full-time
Work mode
Hybrid
Level
Not listed
Department
Information Technology
Experience
4+ years experience
Posted
Aug 5, 2026

About the role

Job Summary:

The Network System Administrator will administer and maintain the reliability of Lynk's corporate network and core infrastructure — connecting Chevy Chase, MD and Chantilly, VA and supporting a globally distributed, mission-critical operation. This role is responsible for network administration, server and systems infrastructure, and the security/compliance posture of Lynk's infrastructure stack, including maintaining endpoint compliance in support of Lynk's CMMC Level 2 requirements. The role also serves as an escalation point for basic end-user IT support. This position is based in our Chevy Chase, MD office and will require some travel to our Chantilly, VA office as needed (Hybrid: 2–3 days onsite per week).

Duties & Responsibilities:

  • Configure, deploy, and maintain LAN/WAN, wireless, VPN, and firewall infrastructure across Lynk office and lab locations
  • Administer network segmentation, routing, and VLANs, and support capacity planning as the company scales
  • Administer and harden core infrastructure: Microsoft Entra ID (Azure AD), Conditional Access, DNS/DHCP, Office 365, and endpoint security (ESET, Microsoft Defender) at the systems-administration level
  • Manage endpoint and device compliance through Microsoft Intune and MDM platforms (e.g., NinjaOne), including policy design, patch management, and fleet-wide enforcement
  • Deploy, monitor, and maintain security posture via Microsoft Defender (Endpoint/365) — threat detection, alerting, and remediation
  • Manage server infrastructure (physical and virtual), including provisioning, patching, backup, and lifecycle management
  • Monitor network and infrastructure health; lead incident response and root-cause analysis for outages and performance issues
  • Implement and maintain infrastructure security controls (firewalls, VPN, MFA, network segmentation, endpoint protection) in line with ITAR and export-control obligations
  • Support Lynk's CMMC Level 2 compliance program — maintain endpoint compliance (patching, configuration baselines, encryption, access control) across the device fleet and evidence controls for audits
  • Monitor and remediate endpoint compliance drift via Intune/NinjaOne and Microsoft Defender to keep the environment aligned with NIST SP 800-171 control requirements
  • Partner with security/compliance stakeholders on System Security Plans (SSPs), POA&Ms, and audit readiness for CMMC assessments
  • Document network topology, infrastructure configuration, and disaster recovery/business continuity procedures

Basic End-User IT Support:

  • Serve as a secondary/escalation point of contact for basic end-user technical issues (hardware, software, connectivity, account access)
  • Provision and configure end-user hardware (laptops, peripherals) in line with security and compliance baselines
  • Troubleshoot common Windows/macOS and Office 365 issues for staff as needed
  • Support onboarding/offboarding from an infrastructure and access-management perspective (accounts, device enrollment, permissions)

Qualifications:

  • 4+ years of experience in network engineering, systems administration, or infrastructure management
  • Hands-on experience administering and maintaining LAN/WAN, VPN, firewall, and wireless network infrastructure
  • Strong Windows Server and macOS environment administration experience
  • Experience managing Microsoft Entra ID (Azure AD), Conditional Access, and Office 365 at an administrative/architectural level
  • Hands-on experience with Microsoft Intune for device/endpoint management and compliance policy
  • Experience with MDM platforms such as NinjaOne, ManageEngine, or similar
  • Experience deploying and managing Microsoft Defender (Endpoint/365) or comparable endpoint security/EDR tooling
  • Understanding of network security fundamentals: firewalls, segmentation, VPN, and endpoint protection
  • Familiarity with CMMC Level 2 / NIST SP 800-171 control requirements and experience maintaining endpoint compliance in a regulated environment
  • Comfortable providing basic end-user technical support alongside infrastructure duties
  • Strong documentation, troubleshooting, and incident-response skills
  • Relevant certification preferred (e.g., CompTIA Network+/Security+, CCNA, Microsoft Certified: Intune/Endpoint Manager, or equivalent experience)

Bonus:

  • Experience with PowerShell or other scripting/automation tools
  • Direct experience preparing for or supporting a CMMC Level 2 assessment (SSP/POA&M development, C3PAO audit support)
  • Experience supporting infrastructure in a regulated or export-controlled (ITAR) environment
  • Previous startup experience is a strong plus

ITAR Requirements:

To comply with U.S. Government export control regulations (ITAR), applicants must be one of the following: (i) a U.S. citizen or national, (ii) a lawful permanent resident (green card holder), (iii) a refugee under 8 U.S.C. § 1157, or (iv) an asylee under 8 U.S.C. § 1158. Individuals who do not meet these criteria must be eligible to obtain the necessary authorizations from the U.S. Department of State.

Learn about ITAR here: https://www.pmddtc.state.gov