via Glassdoor
$150K - 175K a year
Secure, administer, and maintain Windows environments with focus on DISA STIG implementation, compliance, and cloud migration support.
Requires 5+ years Windows Server administration, 3+ years STIG experience, CompTIA Security+ certification, and active Secret clearance.
Job Title: Windows OS Security & STIG Administrator Location: Remote (Offsite-WEST COAST Preferred) Clearance Required: Active Secret Employment Type: Full-Time Overview Cornerstone Technology Enterprises is seeking an experienced Windows OS Security & STIG Administrator to secure, administer, and maintain Windows environments across on-premises infrastructure and Oracle Cloud Infrastructure (OCI) in support of our government customer. This role focuses on Windows administration, DISA STIG implementation, cybersecurity compliance, vulnerability remediation, and secure configuration management, supporting both current on-premises operations and the ongoing transition to OCI-based workloads. The ideal candidate will collaborate closely with the automation team to integrate Windows security requirements into automated hardening and compliance processes, using Git for version control, peer review, documentation, and change management. Key Responsibilities • Administer and secure Windows Server environments across on-premises and OCI infrastructure • Implement, assess, and remediate DISA STIG requirements for Windows operating systems • Analyze and remediate CAT I, CAT II, and CAT III findings • Support consistent Windows security baselines across on-premises and OCI environments • Provide Windows-specific requirements, testing, and troubleshooting support for Ansible playbooks and roles • Execute and troubleshoot Ansible-based hardening, compliance validation, and remediation activities • Use Git for branching, pull requests, peer review, issue tracking, and controlled change management • Develop and maintain PowerShell scripts, configuration checks, and validation utilities • Support Group Policy, Active Directory, auditing, least privilege, patching, and vulnerability management • Support OCI services and security controls, including Compute, VCNs, IAM, compartments, security lists, network security groups, logging, and monitoring • Evaluate the impact of STIG controls on OCI agents, monitoring tools, management services, and system connectivity • Maintain compliance evidence, remediation records, exception documentation, POA&M inputs, and technical procedures • Collaborate with Windows, cloud, cybersecurity, automation, and infrastructure teams Required Qualifications • Active Secret security clearance required • DoD 8570 IAT Level II certification, such as CompTIA Security+, or another customer-approved equivalent aligned with applicable DoD 8140 requirements • Five or more years of Windows Server administration experience • Three or more years of hands-on Windows STIG implementation, assessment, or remediation experience • Strong knowledge of Windows security baselines, Group Policy, Active Directory, auditing, least privilege, patching, and vulnerability remediation • Experience with Ansible for Windows configuration management, security hardening, or compliance activities • Experience with Git, including branching, pull requests, peer review, and change tracking • Strong PowerShell skills and a software engineering mindset, including testing, documentation, reusable code, and controlled releases • Experience securing Windows environments across on-premises and cloud infrastructure • Experience with OCI (Oracle Cloud Infrastructure) or a comparable cloud platform • Strong technical documentation, troubleshooting, and communication skills Preferred Qualifications • Experience with Windows Server 2016, 2019, 2022, or later • Experience with WinRM over HTTPS and Windows Ansible modules • Experience with STIG Viewer, SCAP Compliance Checker, Evaluate-STIG, or comparable tools • Experience supporting Windows workload migration to OCI • Familiarity with CI/CD, infrastructure as code, DevSecOps, or automated testing • Python or another scripting language • OCI certification or equivalent hands-on experience • Experience in federal, defense, regulated, or compliance-driven environments Why Join Cornerstone? Cornerstone Technology Enterprises is a veteran-owned small business with deep experience supporting federal and defense missions. Our teams operate inside production environments, supporting systems that matter, while maintaining a culture that values trust, accountability, and technical excellence. This role offers the opportunity to work remotely while contributing directly to the security, compliance, and reliability of a mission-critical enterprise environment for the DMDC IT GEMS program. Pay: $150,000.00 - $175,000.00 per year Benefits: • 401(k) • 401(k) matching • Dental insurance • Employee discount • Flexible spending account • Health insurance • Health savings account • Life insurance • Paid time off • Retirement plan • Vision insurance Experience: • Windows Server Administration: 5 years (Required) • Windows DISA STIG implementation: 3 years (Required) License/Certification: • CompTIA Security+ (Required) Security clearance: • Secret (Required) Work Location: Remote
This job posting was last updated on 9/28/2026