About this role
RELOCATION ASSISTANCE: No relocation assistance available
CLEARANCE REQUIRED FOR START: No
CLEARANCE TYPE: Secret
TRAVEL: Yes, 10% of the Time
## Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
At the heart of Defining Possible is our commitment to missions. In rapidly changing global security environments, Northrop Grumman brings informed insights and secure technological solutions to enable strategic objectives. We’re looking for innovators who can help us keep building on our wide portfolio of secure, affordable, integrated, and multi-domain systems and technologies that fuel those missions. By joining in our shared mission, we will support yours by expanding your personal network and developing skills, whether you are new to the field or an industry thought leader. At Northrop Grumman, you will have the resources, support, and team to do some of the best work of your career.
Northrop Grumman’s CIDO Space Operations organization is seeking a qualified Computer Operations Analyst – Windows Systems Administrator to provide server and systems administration support to include a high-demand, off-net/enclave production environment running primarily Windows server at our Gilbert, AZ facility.
Job responsibilities will include, but are not limited to, the following:
Core Responsibilities
- Administer, monitor, and troubleshoot server/client systems across the standard corporate network as well as offnet/enclave environments that operate behind a firewall.
- Understand and correctly apply the difference between domain-joined (high-trust) systems, managed via domain Group Policy, and off-domain/standalone systems using local accounts and local Group Policy/security settings, including appropriate account management, authentication, and security configuration for each.
- Perform routine system administration tasks: account creation and management, permissions, storage, backups, and performance monitoring.
- Troubleshoot hardware, OS, and application issues; perform root cause analysis and document resolutions clearly and consistently.
- Support physical server maintenance, including racking/unracking equipment, cabling, and hardware swaps; ability to lift equipment up to 50 lbs.
- Maintain accurate records in ServiceNow, including incident, change, and asset records; ensure SLAs are met and customer expectations are managed appropriately.
- Support security compliance and vulnerability management activities, including remediation tracking using tools such as Tenable (vulnerability scanning), Armis (asset/network visibility), and ArcherGRC (governance, risk, and compliance documentation).
- Provide on-call/after-hours support during production-impacting incidents and scheduled maintenance windows, as needed.
- Collaborate with engineering, security, and program teams to support IT initiatives across on-net and offnet environments.
- Identify firewall rule requirements using a working knowledge of core networking concepts (TCP/UDP, IP addressing, and ports), and submit requests to the network/firewall team, who own firewall configuration.
- Where no corporate or centrally provided solution is available or reachable (particularly in offnet/enclave environments), independently identify, build, or adapt a solution that meets the requirement while remaining within the company's security compliance standards.
Windows-Specific Responsibilities
- Image and deploy Windows workstations and servers using the appropriate pre-built image for the situation.
- Apply appropriate software licensing — including the operating system, Microsoft Office, and other applications — using offline/manual activation methods for systems in offnet environments without internet connectivity, and ensure licensing remains up to date in the event of an audit.
- Administer Windows Server environments (2016/2019/2022), including DNS/DHCP and file/print services.
- Modify and enforce configuration and security baselines through Local Group Policy on client systems, coordinating with the team that administers domain-level Group Policy Objects (GPOs).
- Maintain working knowledge of the Microsoft Endpoint Configuration Manager (MECM/SCCM) client, including basic agent troubleshooting and connectivity checks; use console access to remote control workstations and review client data as needed, while the underlying MECM infrastructure is administered by another team.
- Configure and manage WSUS (Windows Server Update Services) for patch approval, scheduling, and deployment across corporate and offnet environments.
- Support Windows-based business and engineering applications and coordinate with software vendors as needed.
- Support Windows workstations on shop floor and manufacturing lines, whether on the corporate network or a segmented/isolated VLAN.
- Understand, configure, and help manage Active Directory, Group Policy, and DNS settings that affect these workstations, supporting and troubleshooting them.
- Support and troubleshoot current Windows 10/11 workstations; some offnet/legacy environments may still run Windows 7 or Windows XP, requiring familiarity with those older operating systems.
- Understand client-side DNS configuration for workstations.
Other considerations
- Ability to work independently on routine tasks
- Ability to lift equipment up to 50 lbs
- Support occasional on‑call/after‑hours work, as needed
Note: Due to the nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply, only if they are willing to work on-site.
Basic Qualifications:
- Master's Degree with 0 years of experience; OR a Bachelor's Degree with 2 years of experience; OR an Associate's Degree with 4 years of experience; OR a High School Diploma (or equivalent) with 6 years of experience is required
- Must have a CompTIA A+, Network+, Security+, or Linux+ OR must have the ability to obtain one within 6 months of hire
- Experience administering Windows severs is required
- Must have experience using Active Directory (configuring user accounts or look up computer accounts)
- Working knowledge of Group Policy is needed
- Candidates must have the ability to obtain a Secret level security clearance as a condition of continued employment
Preferred Qualifications:
- Bachelor's degree in Information Technology, Computer Science, or a related field, a Security+ CE, and 3 years of Windows Server administration experience beyond the level minimum, ideally in a classified, enclave, or similarly secured environment
- WSUS patch management preferred; Basic familiarity with the Microsoft Endpoint Configuration Manager (MECM) console (remote control, client data review) a plus
- A relevant certification reflecting the team's current mix of desktop and server work and potential future work — for example, Microsoft Certified: Windows Server Hybrid Administrator Associate (or equivalent, e.g., MD-102/AZ-800), CompTIA Server+, an AWS certification, a database administration certification, or a certification in automation or AI-assisted tooling.
- Experience packaging and deploying custom software installers (e.g., MSI/MSIX) for Windows environments.
- Experience with NAS storage administration and enterprise storage concepts, including commonly used RAID levels.
- Solid understanding of vulnerability remediation and system hardening in accordance with RMF and STIGs, including Windows Defender Firewall configuration and Group Policy-based security baselines.
- Experience operating within a classified or controlled information system environment governed by frameworks such as RMF and JSIG (or their legacy predecessors — NISPOM Chapter 8, DCID 6/3/ICD 503, JAFAN); familiarity with DFARS and NIST information security controls (e.g., NIST SP 800-53/800-171).
- Scripting/automation experience (PowerShell, Python, or Ansible).
- Cross-platform experience (Windows and Linux/RHEL), including familiarity with Red Hat Satellite Server and RHEL administration in mixed environments.
- Experience supporting manufacturing, engineering, or other mission-critical operational environments.
- Strong troubleshooting and root-cause-analysis skills; good written and verbal communication
- Active Secret level clearance highly desirable
We offer flexible work arrangements, phenomenal learning opportunities, exposure to a wide variety of projects and customers, and a very friendly team environment. At Northrop Grumman, we are on the cutting edge of innovation. Our diverse portfolio of programs means there are endless paths to cultivate your career. We also offer exceptional benefits/healthcare, a 9/80 work schedule, and a great 401k matching program. Come join us!
Primary Level Salary Range: $72,100.00 - $108,100.00
The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.
Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.
The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.
Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.