About Lynk Global Lynk Global is the inventor of satellite direct to device or D2D technology and has the world’s only commercial license from the FCC to operate a commercial D2D system. Today, Lynk allows mobile network operators' subscribers to send and receive text messages to and from space via standard unmodified, mobile devices. Lynk’s service has been tested and proven on all seven continents, has regulatory approvals in more than 30 countries and is currently being deployed commercially based on more than 40 MNO commercial service contracts covering approximately 50 countries. Our technology will enable all 8 billion people on the planet to stay connected with the existing standard phone in their pocket. Everywhere. No matter what. The Network & Infrastructure Engineer will own the design, build-out, and reliability of Lynk's corporate network and core infrastructure — connecting Chevy Chase, MD and Chantilly, VA and supporting a globally distributed, mission-critical operation. This role is responsible for network architecture and administration, server and systems infrastructure, and the security/compliance posture of Lynk's infrastructure stack, including maintaining endpoint compliance in support of Lynk's CMMC Level 2 requirements. The role also serves as an escalation point for basic end-user IT support. This position is based in our Chevy Chase, MD office and will require some travel to our Chantilly, VA office as needed (Hybrid: 2–3 days onsite per week). - Experience with PowerShell or other scripting/automation tools - Direct experience preparing for or supporting a CMMC Level 2 assessment (SSP/POA&M development, C3PAO audit...
Responsibilities:
•
- Design, deploy, and maintain LAN/WAN, wireless, VPN, and firewall infrastructure across Lynk office and lab locations
•
- Own network architecture decisions — segmentation, routing, VLANs, redundancy, and capacity planning as the company scales
•
- Administer and harden core infrastructure: Microsoft Entra ID (Azure AD), Conditional Access, DNS/DHCP, Office 365, and endpoint security (ESET, Microsoft Defender) at the systems-administration level
•
- Manage endpoint and device compliance through Microsoft Intune and MDM platforms (e.g., NinjaOne), including policy design, patch management, and fleet-wide enforcement
•
- Deploy, monitor, and maintain security posture via Microsoft Defender (Endpoint/365) — threat detection, alerting, and remediation
•
- Manage server infrastructure (physical and virtual), including provisioning, patching, backup, and lifecycle management
•
- Monitor network and infrastructure health; lead incident response and root-cause analysis for outages and performance issues
•
- Implement and maintain infrastructure security controls (firewalls, MFA, network segmentation, endpoint protection) in line with ITAR and export-control obligations
•
- Support Lynk's CMMC Level 2 compliance program — maintain endpoint compliance (patching, configuration baselines, encryption, access control) across the device fleet and evidence controls for audits
•
- Monitor and remediate endpoint compliance drift via Intune/NinjaOne and Microsoft Defender to keep the environment aligned with NIST SP 800-171 control requirements
•
- Partner with security/compliance stakeholders on System Security Plans (SSPs), POA&Ms, and audit readiness for CMMC assessments
•
- Document network topology, infrastructure architecture, and disaster recovery/business continuity procedures
Requirements:
•
- 4+ years of experience in network engineering, systems administration, or infrastructure management
•
- Hands-on experience designing and maintaining LAN/WAN, VPN, firewall, and wireless network infrastructure
•
- Strong Windows Server and macOS environment administration experience
•
- Experience managing Microsoft Entra ID (Azure AD), Conditional Access, and Office 365 at an administrative/architectural level
•
- Hands-on experience with Microsoft Intune for device/endpoint management and compliance policy
•
- Experience with MDM platforms such as NinjaOne, ManageEngine, or similar
•
- Experience deploying and managing Microsoft Defender (Endpoint/365) or comparable endpoint security/EDR tooling
•
- Understanding of network security fundamentals: firewalls, segmentation, and endpoint protection
•
- Relevant certification preferred (e.g., CompTIA Network+/Security+, CCNA, Microsoft Certified: Intune/Endpoint Manager, or equivalent experience)