Source description
About the role
Job Description Insight Global is seeking a Windows Server Engineer for one of our clients Global Windows Server (Wintel) team, administering a global fleet of physical, virtual, and cloud Windows servers. Youll manage Windows Server 20162025, Active Directory, and Group Policy, and most importantly bring Ansible-based automation to the Windows fleet (a skillset the current team lacks). Working with the security green team, youll own the Windows patch lifecycle, automate patching to shrink the cycle, and turn vulnerability findings into fast, permanent fixes. Key Responsibilities Operate the fleet: Administer and optimize Windows Server 20162025 across physical, virtual, and cloud.Identity & policy: Manage Active Directory, Group Policy, DNS/DHCP, and certificates.Automate (Ansible + PowerShell): Bring Ansible automation to the Windows fleet and use PowerShell for provisioning, patching, and reporting this automation gap is the core of the role.Patch lifecycle (Mythos): Own Windows patching end to end via SCCM/MECM deployment, compliance, and reporting against SLAs.Green-team collaboration: Work with the security green team and cross-functional teams to automate and shorten the patch/vulnerability cycle.Fix at the source: Update golden images, templates, and baselines so vulnerabilities dont recur.Harden & report: Apply CIS/STIG baselines with drift detection; maintain dashboards for patch coverage, velocity, and risk.On-call: Join the on-call rotation (some nights/weekends).Required Skills & Experience 6+ years administering Windows Server in an enterprise, including Active Directory and Group Policy.Ansible for configuration management and patch automation a core requirement (the automation gap this team is filling).PowerShell scripting for automation and reporting.Proven track record addressing patching and security vulnerability remediation.Hands-on SCCM / Microsoft Endpoint Configuration Manager for patching and compliance.Strong VMware vSphere / ESXi.Production cloud experience, primarily Azure (AWS/GCP a plus).Working knowledge of vulnerability management (CVEs, CVSS, risk-based prioritization).Flexible for on-call, nights, and weekends.Nice to Have CIS/STIG hardening and drift detectionVulnerability scanners (Qualys, Wiz, Tenable, Rapid7)IaC / Git workflows (Terraform, GitHub)Certs: Azure Administrator, MCSE, VCP, Ansible (RHCE), Security+ .
More at Insight Global