This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Moderna is expanding our footprint to deliver the greatest possible impact to people through mRNA medicines. Our Cambridge technology hub server team is responsible for the design, implementation, administration, and support of the server environments supporting our research and pharmaceutical production. This role requires deep expertise across all core Windows Server roles and features, including Active Directory, DNS, DHCP, Group Policy, and File/Print services. The ideal candidate is a hands-on technical expert who excels in troubleshooting, automation, and system optimization to ensure stability, scalability, and security across enterprise systems. We are seeking experienced engineers who embody the Moderna Mindsets and want to help transform patients’ lives by building reliable, secure, and scalable systems.
Job Responsibility:
Own the architecture, health, and security of Active Directory, including forests, domains, trusts, and replication topology
Lead advanced integration and troubleshooting of authentication and identity (Kerberos, NTLM, SPNs, delegation, replication)
Design and enforce Active Directory security controls, including tiered administration models (Tier 0/1/2) and privileged access strategies
Architect, manage, and secure enterprise PKI (ADCS), including certificate lifecycle, template governance, and CRL distribution
Define and maintain standards for Group Policy design, DNS architecture, and domain-joined systems
Own the operational health, lifecycle, and performance of enterprise Windows Server platforms (2016/2019/2022/2025)
Lead server lifecycle management, including build standards, patching strategy, compliance, and decommissioning
Drive root cause analysis for complex systems, authentication, and performance issues across distributed environments
Define and enforce standards for server configuration, hardening, monitoring, and resiliency
Develop and maintain automation using PowerShell and related tooling to improve consistency and efficiency
Act as a senior escalation point and technical mentor for other engineers
Participate in escalation-level on-call, owning resolution of high-impact incidents
Requirements:
Bachelor’s degree in computer science, engineering, or related field (or equivalent experience)
3-5 years deploying, securing and maintaining a global Active Directory environment
7–10 years of professional experience supporting Microsoft Windows Server environments including all role and features
Proven experience operating enterprise-scale Windows Server environments, including performance, patching, and reliability
Deep ability to troubleshoot authentication, replication, network, and performance issues
Experience with patch management process and tooling, endpoint protection, and server hardening
Nice to have:
Microsoft certifications (AZ800/AZ801, SC300, MCSA, MCSE, or equivalent)
Experience implementing Active Directory security best practices (tiering models, privileged access controls, hardening)
Experience working in hybrid on premises and cloud environments (VMware, AWS, Azure)
Proficient with Microsoft and third-party monitoring and management tools
Experience in regulated environments (GXP, DISA-STIG, CIS, PCI, etc.)
Ability to work independently, develop long term strategic Infrastructure enterprise goals
What we offer:
Best-in-class healthcare coverage, plus voluntary benefit programs to support your unique needs
A holistic approach to well-being, with access to fitness, mindfulness, and mental health support
Family planning benefits, including fertility, adoption, and surrogacy support
Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown
Savings and investment opportunities to help you plan for the future