Sr. Windows Systems & Automation Engineer; Remote
Coos Bay, Coos County, Oregon, 97458, USA
Listed on 2026-03-05
-
IT/Tech
Cybersecurity, Systems Engineer
As a global leader in cybersecurity, Crowd Strike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on Crowd Strike to keep their businesses running, their communities safe and their lives moving forward.
We’re also a mission-driven company. We cultivate a culture that gives every Crowd Striker both the flexibility and autonomy to own their careers. We’re always looking to add talented Crowd Strikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters?
The future of cybersecurity starts with you.
We’re looking for a Windows expert with a proven track record of designing, automating, and securing large‑scale enterprise environments. You’ll own core Windows platform services (AD, DNS/DHCP, NPS/RADIUS), build and run certificate management as a service (CMaaS), and lead automation across tens of thousands of endpoints and servers. You’ll also be our SCCM expert for endpoint computing (Windows 10/11), bringing hands‑on systems administration depth and top‑tier troubleshooting across OS, apps, networking, and identity.
Our footprint is hybrid data center with multi‑cloud (AWS + GCP).
- Architect, operate, and harden Active Directory (multi‑forest, multi‑site), DNS/DHCP, and NPS/RADIUS for Wi‑Fi/VPN/802.1X (EAP‑TLS).
- Lead GPO strategy, OU design, admin tiering, delegation, and AD replication/site topology.
- Own endpoint lifecycle at scale: imaging/OSD, driver/firmware management, software packaging/distribution, update rings, device health/telemetry, and fleet compliance.
- Engineer endpoint security baselines:
Bit Locker, LAPS, WDAC/App Locker, Defender/EDR integrations, credential hardening, and certificate deployment for EAP‑TLS/mTLS. - Lead SCCM/MECM architecture and operations:
Task Sequences/OSD, app packaging, SUP/WSUS patching, compliance baselines, collections, reporting/CMPivot, and role‑based access. - Drive release rings, maintenance windows, and measurable patch compliance SLOs across large fleets.
- Triage and resolve complex endpoint/server issues: logon slowness, BSODs/hangs, app crashes, update/install failures, 802.1X/RADIUS auth problems, and TLS/certificate breakage.
- Use deep diagnostics:
Sysinternals (Proc Mon/Proc Exp/Autoruns), Windows Performance Toolkit (WPR/WPA), Win Dbg/WER, ETW/WEF, Perf Mon, Wireshark, and netsh/packet capture to find root causes and prevent recurrences. - Deliver automation (Power Shell, Power Shell DSC, Terraform, Packer) for provisioning, configuration, drift control, and compliance—with CI/CD (Git Hub Actions/Git Lab/Jenkins).
- Build self‑service patterns and APIs (golden images, desired‑state baselines, just‑in‑time access).
- Design and operate enterprise PKI: policy‑driven issuance/renewal, inventory/attestation, CRL/OCSP, and revocation at scale.
- Integrate with ADCS, AWS ACM / ACM Private CA, GCP Certificate Authority Service, Venafi, Hashi Corp Vault PKI, cert‑manager/ACME; enable EAP‑TLS, service mTLS, code‑signing, and device certs.
- Standardize and harden Windows workloads in AWS (EC2/SSM/KMS/IAM/ACM/Directory Service/Route 53) and GCP (Managed Microsoft AD, GCE, Cloud DNS/KMS/CAS).
- Build reproducible images and baseline configs for domain‑joined and cloud‑native instances.
- Hands‑on Windows server ops (storage/SMB, DFS, file/print), performance tuning, and core network triage (DHCP/DNS/Kerberos).
- Familiarity with virtualization (VMware vSphere/Hyper‑V), backup/restore workflows, and operational monitoring.
- 8+ years designing, building, and operating enterprise Windows platforms (server + endpoint); 8+ years owning AD, DNS/DHCP, NPS at large scale (10k+ endpoints or equivalent).
- Proven track record delivering large‑scale SCCM (MECM) programs: OSD/Task Sequences, application packaging, SUP/WSUS patching at fleet scale, compliance baselines, and reporting.
- Experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).