Windows Systems Automation Engineer
Booz Allen Hamilton
- Location
- McLean, VA
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 9 approvals (FY2023)
- Posted
- 23h ago
Skills
About this role
Windows Systems Automation Engineer The Opportunity: Secure cyber training environments need Windows systems that can be deployed, configured, tested, and removed consistently through automation. We need a Windows Systems Automation Engineer who can combine Windows administration, cloud engineering, and infrastructure-as-code practices to build reliable and repeatable environments supporting Department of Defense missions. On our team, you’ll engineer Windows Server and workstation capabilities for isolated, cloud-based cyber ranges. You’ll automate Active Directory, DNS, Group Policy, domain joins, security hardening, software installation, patching, and endpoint configuration using PowerShell and infrastructure as code. You’ll develop reusable deployment components, bootstrap scripts, and automated machine-image pipelines. You’ll also integrate Windows systems with cloud services for identity, secrets management, logging, monitoring, and remote administration. Your work will help ensure environments can be securely deployed and completely removed without relying on manual configuration. You’ll collaborate with platform engineers, network engineers, cybersecurity SMEs, and range operators to troubleshoot identity, authentication, configuration, and application issues. You’ll apply STIGs, remediate vulnerabilities, document system designs, and continuously improve deployment reliability.
What You'll Work On
Automate Windows Server and workstation deployments using AWS CDK, CloudFormation, Terraform, or similar infrastructure-as-code tools Design and maintain Active Directory, DNS, Group Policy, and identity services for isolated range environments Develop advanced PowerShell scripts for provisioning, domain joins, configuration management, security auditing, and software installation Build and maintain reusable Windows machine images through automated image pipelines Apply STIGs and other security-hardening standards to Windows servers and endpoints Automate patching, vulnerability remediation, inventory, and compliance reporting Integrate systems with secrets management, logging, monitoring, and remote-management services Develop automated tests and deployment validation to identify configuration issues before release Troubleshoot complex Windows, Active Directory, authentication, networking, and application issues Maintain technical documentation, configuration standards, and operational runbooks Join us. The world can’t wait. You Have: 6+ years of experience administering or engineering Windows Server environments 2+ years of experience supporting a U.S. Government or federal environment Experience with Active Directory, DNS, Group Policy, and automated domain provisioning Experience developing PowerShell automation for infrastructure deployment, configuration, and security auditing Experience with infrastructure-as-code tools such as AWS CDK, CloudFormation, or Terraform Experience using Git and CI/CD pipelines to manage and deploy infrastructure changes Experience with automated patching, compliance tracking, and endpoint management Knowledge of STIGs, NIST SP 800-53 controls, and Windows security-hardening practices Experience troubleshooting complex system, identity, network, and application issues HS diploma or GED DoD 8570/8140 IAT Level II-compliant certification, such as Security+, CySA +, or GSEC Ability to obtain an IAT Level III-compliant certification, such as SecurityX , CISSP, or CCNP Security, within 6 months of start date Nice If You Have: Experience administering Windows workloads in AWS Experience with AWS Systems Manager, Secrets Manager, IAM, S3, or CloudWatch Experience with AWS EC2 Image Builder, Packer, or another automated image-building platform Experience with AWS CDK and TypeScript Experience with