Windows Server Administrator – Active Security Clearance Required
LLNLJoin us and make YOUR mark on the World!
Lawrence Livermore National Laboratory (LLNL) has turned bold ideas into world-changing impact advancing science and technology to strengthen U.S. security and promote global stability.
Our mission spans four critical national security areas nuclear deterrence, threat preparedness, energy security, and multi-domain defense empowering teams to take on the toughest challenges of today and tomorrow. With a culture built on innovation and operational excellence, LLNL is a place where your expertise can make a real impact.
We’re looking for a Windows Systems Administrator to provide advanced technical computer, infrastructure, and operations support for enterprise Windows systems and related services. You will work in a safety-conscious, challenging, rapidly changing, and team-oriented environment to solve complex technical problems in a timely manner. This position is in the Information Technology Operations, ITO, Division within the Computing Directorate.
This position requires full-time on-site presence due to the nature of the work.
This position will be filled at either level based on knowledge and related experience as assessed by the hiring team. Additional job responsibilities (outlined below) will be assigned if hired at the higher level.
You will
- Perform advanced troubleshooting and administration for Windows Server, Active Directory, DNS, Group Policy, authentication, and related system integrations.
- Install, configure, maintain, patch, harden, and secure Windows servers and supporting infrastructure services.
- Administer enterprise backup systems, including job monitoring, failure remediation, restore operations, retention management, and recovery validation.
- Analyze complex incidents, identify root causes, implement corrective actions, and document resolutions.
- Develop and maintain PowerShell scripts and utilities to automate administration, monitoring, reporting, and support processes.
- Support cybersecurity operations, including account management, access controls, vulnerability remediation, system monitoring, compliance activities, and preparation of technical artifacts for Assessment and Authorization and ATO activities.
- Provide technical guidance and escalation support to Tier 1 and Tier 2 staff, and maintain accurate SOPs, knowledge articles, and system documentation.
- Participate in infrastructure upgrades, migrations, disaster-recovery and business-continuity exercises, datacenter operations, and operational improvement projects across Corporate and Isolated Networks.
- Perform other duties as assigned.
Additional job responsibilities, at the 393.2 level
- Diagnose, troubleshoot, and resolve highly complex Windows, system, network, backup, and integration problems, including driving problem resolution, working with vendors, and managing support cases as required.
- Serve as a technical leader and internal and external consultant, providing highly advanced technical assistance to the user community and collaborating with customers in the design and implementation of computing environments.
- Provide technical leadership for complex upgrades, migrations, disaster-recovery activities, cybersecurity remediation, and operational improvement projects.
- Mentor Tier 1 and Tier 2 staff and provide guidance on troubleshooting methods, system administration practices, and technical procedures.
- Lead root-cause investigations and develop corrective actions for recurring or highly complex incidents.
- Support the development, review, and maintenance of technical artifacts and evidence for ATO packages and other compliance activities.
- Active DOE Q clearance (or active Top Secret clearance) with the ability to obtain and maintain Sensitive Compartmented Information (SCI) access.
- Bachelor’s degree in a computer-related field, or an equivalent combination of education, technical training, and experience.
- Substantial experience administering Windows Server environments, including Active Directory, DNS, Group Policy, and related infrastructure.
- Extensive experience troubleshooting complex Windows infrastructure and enterprise services, or equivalent senior support role.
- Experience installing, configuring, maintaining, patching, Windows servers and supporting services.
- Ability to independently prioritize work, manage multiple assignments, and resolve complex technical problems.
- Strong interpersonal, verbal, and written communication skills, with the ability to work independently and collaborate with multidisciplinary teams.
- Ability to independently set priorities, manage multiple assignments, and resolve complex problems in a fast-paced environment.
- <Insert role specific Qualifications, as applicable>
Additional qualifications at the 393.2 level
- Highly advanced knowledge of and substantial experience with Windows Server, Active Directory, DNS, Group Policy, authentication, and related infrastructure.
- Substantial experience providing technical leadership, mentoring technical staff, and resolving complex infrastructure problems.
- Substantial experience developing or modifying PowerShell scripts and utilities for administration, monitoring, reporting, and process automation.
- Substantial experience leading system upgrades, migrations, disaster-recovery exercises, root-cause investigations, and corrective-action activities.
Qualifications We Desire
- Experience with cybersecurity tools, vulnerability remediation, access controls, security monitoring, and compliance activities.
- Experience administering enterprise backup and recovery platforms, including job monitoring, failure remediation, restore operations, retention management, and recovery validation.
- Experience with Windows hardening, security baselines, vulnerability remediation, access controls, and cybersecurity monitoring tools.
- Experience with enterprise management, patching, software distribution, virtualization, storage, and infrastructure-monitoring tools.
- Professional computer or network certification, such as Microsoft, CompTIA, Red Hat, or Cisco certifications.
- Experience supporting classified, regulated, isolated, or otherwise security-sensitive computing environments, including NIST-based security controls or comparable authorization activities.
- Experience serving as a technical team lead.
Pay Range
$125,310 - $153,444 Yearly at the 393.1 level
$151,620 - $185,640 Yearly at the 393.2 level
This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting; pay will not be below any applicable local minimum wage. An employee’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs.
#LI-Onsite
Position Information
This is a Career Indefinite position, open to Lab employees and external candidates.
Why Lawrence Livermore National Laboratory?
- Included in 2026 Best Places to Work by Glassdoor!
- Flexible Benefits Package
- 401(k)
- Relocation Assistance
- Education Reimbursement Program
- Flexible schedules (*depending on project needs)
- Our values - visit https://www.llnl.gov/inclusion/our-values
Security Clearance
This position requires an active Department of Energy (DOE) Q-level clearance or active Top Secret clearance issued by another U.S. government agency at time of hire. Also, you must have the ability to obtain and maintain Sensitive Compartmented Information (SCI) access. Please note that your current active Q or Top Secret clearance with DOE or another agency does not guarantee DOE SCI access approval; if you are denied access, you may be subject to reinvestigation of your existing Q or Top Secret Clearance.
Pre-Employment Drug Test
External applicant(s) selected for this position must pass a post-offer, pre-employment drug test. This includes testing for use of marijuana as Federal Law applies to us as a Federal Contractor.
Wireless and Medical Devices
Per the Department of Energy (DOE), Lawrence Livermore National Laboratory must meet certain restrictions with the use and/or possession of mobile devices in Limited Areas. Depending on your job duties, you may be required to work in a Limited Area where you are not permitted to have a personal and/or laboratory mobile device in your possession. This includes, but not limited to cell phones, tablets, fitness devices, wireless headphones, and other Bluetooth/wireless enabled devices.
If you use a medical device, which pairs with a mobile device, you must still follow the rules concerning the mobile device in individual sections within Limited Areas. Sensitive Compartmented Information Facilities require separate approval. Hearing aids without wireless capabilities or wireless that has been disabled are allowed in Limited Areas, Secure Space and Transit/Buffer Space within buildings.
How to identify fake job advertisements
Please be aware of recruitment scams where people or entities are misusing the name of Lawrence Livermore National Laboratory (LLNL) to post fake job advertisements. LLNL never extends an offer without a personal interview and will never charge a fee for joining our company. All current job openings are displayed on the Career Page under “Find Your Job” of our website. If you have encountered a job posting or have been approached with a job offer that you suspect may be fraudulent, we strongly recommend you do not respond.
To learn more about recruitment scams: https://www.llnl.gov/sites/www/files/2023-05/LLNL-Job-Fraud-Statement-Updated-4.26.23.pdf
Equal Employment Opportunity
We are an equal opportunity employer that is committed to providing all with a work environment free of discrimination and harassment. All qualified applicants will receive consideration for employment without regard to race, color, religion, marital status, national origin, ancestry, sex, sexual orientation, gender identity, disability, medical condition, pregnancy, protected veteran status, age, citizenship, or any other characteristic protected by applicable laws.
Reasonable Accommodation
Our goal is to create an accessible and inclusive experience for all candidates applying and interviewing at the Laboratory. If you need a reasonable accommodation during the application or the recruiting process, please use our online form to submit a request.
California Privacy Notice
The California Consumer Privacy Act (CCPA) grants privacy rights to all California residents. The law also entitles job applicants, employees, and non-employee workers to be notified of what personal information LLNL collects and for what purpose. The Employee Privacy Notice can be accessed here.