Senior Windows Administrator

  • Makati City, Metro Manila, Philippines
  • Full-Time
  • Hybrid

Job Description:

Role Overview
We are looking for a Senior Windows Administrator responsible for the design, administration, security, and day-to-day operation of enterprise Windows infrastructure and Microsoft-based platforms.
The role has a strong focus on Windows Server, Active Directory, Microsoft Entra ID, endpoint management, Microsoft 365, server hosting, patching, backup, monitoring, and infrastructure operations, while also contributing to Azure, identity security, automation, and hybrid infrastructure initiatives.
This is a hands-on senior infrastructure role requiring someone who can independently manage the organization's server fleet and directory services, maintain secure and resilient infrastructure, troubleshoot complex issues, and contribute to infrastructure improvements and technology initiatives.

Key Responsibilities


Windows Server & Infrastructure Administration

  • Administer, maintain, and support enterprise Windows Server environments across physical, virtualized, and hosted platforms.
  • Manage the day-to-day operation, availability, performance, and reliability of Windows infrastructure.
  • Perform server provisioning, configuration, hardening, patching, maintenance, and lifecycle activities.
  • Maintain secure baseline configurations for Windows servers and endpoints.
  • Manage server logging, monitoring, capacity, and performance.
  • Troubleshoot complex Windows infrastructure issues and perform root-cause analysis.
  • Support hosting and virtualization environments and associated infrastructure platforms.
  • Contribute to disaster recovery and business continuity activities, including RPO/RTO planning and testing.

Active Directory & Microsoft Entra ID

  • Administer and maintain Active Directory and Microsoft Entra ID environments.
  • Support hybrid identity architecture and synchronization between on-premises and cloud environments.
  • Manage users, groups, organizational structures, authentication, and access controls.
  • Implement and maintain Conditional Access policies and identity security controls.
  • Support enterprise Single Sign-On (SSO) using protocols such as OAuth and SAML.
  • Manage privileged access using PAM, PIM, and Just-in-Time (JIT) access models.
  • Apply least-privilege and Zero Trust principles across identity and access management.
  • Manage Microsoft Entra enterprise applications, app registrations, permissions, and consent.

Endpoint & Device Management

  • Manage the enterprise Standard Operating Environment (SOE) for Windows devices.
  • Administer endpoint configurations, local administrator access, and security baselines.
  • Implement and maintain LAPS and secure endpoint administration practices.
  • Manage device lifecycle and endpoint configuration using Microsoft Intune.
  • Administer Windows Autopilot for device provisioning and deployment.
  • Support endpoint compliance, configuration, patching, and security management.
  • Troubleshoot endpoint and device management issues across the organization.

Microsoft 365 Administration

  • Administer and support Microsoft 365 services and associated workloads.
  • Support identity, access, security, configuration, and operational requirements across Microsoft 365.
  • Troubleshoot Microsoft 365 service and user access issues.
  • Support integration between Microsoft 365, Entra ID, endpoint management, and enterprise applications.

Azure Infrastructure & Platform Support

  • Support Azure infrastructure and platform services within a hybrid enterprise environment.
  • Work with Azure networking components including:
  • Virtual Networks
  • Hub-and-Spoke architectures
  • Landing Zones
  • Network Security Groups (NSGs)
  • Application Security Groups (ASGs)
  • User Defined Routes (UDRs)
  • VNet peering
  • Trust-zone segmentation
  • Support Azure Virtual Desktop (AVD) environments and associated access and security controls.
  • Contribute to cloud infrastructure design, implementation, resilience, and cost optimization.
  • Apply infrastructure standards and best practices to Azure environments.

Infrastructure Security

  • Implement secure infrastructure configurations across servers, endpoints, identity, and cloud environments.
  • Apply Zero Trust principles across identity, devices, networks, and applications.
  • Support Microsoft security platforms including:
  • Microsoft Defender
  • Microsoft Sentinel
  • Microsoft Purview
  • Azure security services
  • Support endpoint detection and response (EDR) operations and remediation activities.
  • Implement and maintain information protection and DLP controls.
  • Support security hardening based on recognized security standards and benchmarks.
  • Assist with infrastructure and security incident response and remediation.

Core Infrastructure Services

  • Administer and support core infrastructure services including:
  • DNS
  • NTP
  • DHCP and related infrastructure services where applicable
  • Server patching
  • Logging
  • Monitoring
  • Support firewalls, cloud proxy, SASE/CASB, and related infrastructure security controls.
  • Manage certificate lifecycle and PKI services for internal and external infrastructure.
  • Troubleshoot connectivity, authentication, certificate, and infrastructure service issues.

Automation & Infrastructure as Code

  • Identify repetitive infrastructure and operational activities that can be automated.
  • Develop and maintain automation for server, endpoint, identity, and operational tasks.
  • Support Infrastructure as Code (IaC) practices to standardize infrastructure deployment and configuration.
  • Work with automation and scripting technologies appropriate to the Microsoft infrastructure environment.
  • Support CI/CD and infrastructure automation using GitHub and/or Azure DevOps.

Hybrid Infrastructure & Platform Operations

  • Support Windows and UNIX/Linux environments within a hybrid infrastructure landscape.
  • Administer virtualization platforms and containerized workloads.
  • Support infrastructure integrations across on-premises and cloud environments.
  • Maintain operational documentation, standard operating procedures, infrastructure configurations, and technical designs.
  • Contribute to infrastructure technology evaluations and recommendations.

Incident, Problem & Operational Management

  • Provide proactive and reactive response to infrastructure and security incidents.
  • Investigate and resolve complex infrastructure problems.
  • Manage escalations and coordinate with internal teams, vendors, and technology partners.
  • Participate in an on-call or escalation roster, where required.
  • Perform root-cause analysis and implement corrective and preventive actions.
  • Work within established IT service management and operational processes.

Infrastructure Architecture & Continuous Improvement

  • Contribute to infrastructure architecture and technology roadmap activities.
  • Evaluate existing infrastructure solutions and recommend improvements.
  • Identify opportunities to improve resilience, security, performance, automation, and cost efficiency.
  • Contribute to infrastructure standards, technical designs, and secure architecture decisions.
  • Ensure infrastructure solutions follow appropriate industry practices and organizational standards.


Required Qualifications & Experience

  • 7+ years of hands-on experience in Windows Infrastructure, Systems Administration, Systems Engineering, Infrastructure Engineering, or Cloud Platform Engineering.
  • Strong hands-on experience administering Windows Server environments.
  • Strong expertise in Active Directory and Microsoft Entra ID.
  • Experience with hybrid identity environments and enterprise authentication.
  • Hands-on experience with Conditional Access and SSO, including OAuth and/or SAML.
  • Experience managing privileged access using PAM, PIM, and/or JIT models.
  • Experience managing Windows endpoint environments, including SOE and local administrator controls.
  • Hands-on experience with Microsoft Intune and Windows Autopilot.
  • Experience with LAPS and secure endpoint administration.
  • Experience with Microsoft 365 administration.
  • Experience with server patching, logging, monitoring, and infrastructure operations.
  • Experience with Azure infrastructure and networking.
  • Experience administering or supporting Azure Virtual Desktop (AVD).
  • Experience with virtualization and/or hosting environments.
  • Experience with infrastructure automation and/or Infrastructure as Code.
  • Experience with certificate management and PKI.
  • Working knowledge of UNIX/Linux administration alongside Windows infrastructure.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Strong stakeholder communication and collaboration skills.
  • Ability to work independently and manage infrastructure responsibilities with minimal supervision.
  • Willingness to participate in on-call/escalation support when required.


Strongly Preferred Experience

  • Experience with Microsoft Defender, Microsoft Sentinel, and Microsoft Purview.
  • Experience with DLP and information protection controls.
  • Experience applying Zero Trust principles across identity, endpoint, network, and application layers.
  • Experience with Azure Landing Zones and Hub-and-Spoke architecture.
  • Experience with NSGs, ASGs, UDRs, VNet peering, and network segmentation.
  • Experience with Graph API and Microsoft Entra application registrations.
  • Experience with enterprise application permissions and consent management.
  • Experience with GitHub and Azure DevOps.
  • Experience supporting CI/CD and infrastructure automation.
  • Experience with Docker, Kubernetes, or containerized workloads.
  • Experience with EDR, cloud proxy, SASE, or CASB technologies.
  • Experience with firewalls and network security controls.
  • Experience with disaster recovery and business continuity planning.
  • Experience defining or supporting RPO/RTO requirements.
  • Experience working under ITIL practices.
  • Familiarity with Azure Well-Architected Framework, NIST CSF, and CIS Benchmarks.
  • Exposure to OCI or other cloud platforms.


Technology & Tools

Microsoft / Windows

  • Windows Server
  • Active Directory
  • Microsoft Entra ID
  • Microsoft 365
  • Microsoft Intune
  • Windows Autopilot
  • LAPS
  • Azure Virtual Desktop
  • Microsoft Graph

Azure

  • Azure Virtual Networks
  • Hub & Spoke
  • Azure Landing Zones
  • NSG / ASG
  • UDR
  • VNet Peering
  • Azure Security Services

Security & Identity

  • Microsoft Defender
  • Microsoft Sentinel
  • Microsoft Purview
  • Conditional Access
  • PAM / PIM / JIT
  • SSO
  • OAuth
  • SAML
  • DLP
  • PKI / Certificate Management
  • EDR
  • Zero Trust

Infrastructure

  • DNS
  • NTP
  • Patching
  • Logging & Monitoring
  • Virtualization
  • Hosting Platforms
  • Windows / UNIX / Linux
  • Containers / Kubernetes

DevOps & Automation

  • Infrastructure as Code
  • GitHub
  • Azure DevOps
  • CI/CD
  • Automation / Scripting


Applicable Certifications
One or more of the following certifications is preferred:

  • Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Microsoft Certified: Azure Fundamentals
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals
  • Microsoft Certified: Identity and Access Administrator Associate
  • Microsoft Certified: DevOps Engineer Expert
  • Microsoft Certified: Cybersecurity Architect Expert


Key Competencies

  • Windows Server Administration
  • Active Directory Administration
  • Microsoft Entra ID
  • Hybrid Identity
  • Endpoint Management
  • Intune & Autopilot
  • Microsoft 365 Administration
  • Azure Infrastructure
  • Infrastructure Security
  • Zero Trust
  • Server & Endpoint Hardening
  • Infrastructure Automation
  • Infrastructure as Code
  • PKI & Certificate Management
  • Virtualization & Hosting
  • Incident & Problem Management
  • Disaster Recovery / Business Continuity
  • Infrastructure Architecture
  • Technical Troubleshooting
  • Vendor Management
  • Stakeholder Management