IT Support Specialist
Job Description
Tampa Brass & Aluminum Corporation is a fourth-generation, family-owned precision nonferrous foundry and machine shop supporting the defense, aerospace, maritime, and energy sectors. TBA operates in a controlled environment handling Controlled Unclassified Information (CUI) and ITAR-regulated technical data, and is preparing for a NIST SP 800-171 r2 compliance assessment.
Position OverviewTBA is hiring an IT Support Specialist to own day-to-day technology operations across the company: end-user support, network and server administration, and endpoint management. This role keeps both general business systems and CUI-scoped systems running reliably, securely, and in line with company security procedures. You will work closely with the compliance lead and the MSSP to maintain a stable, well-documented environment.
This is a hands-on individual contributor role covering the full range of internal IT operations, from helpdesk tickets to network and server administration.
Key ResponsibilitiesEnd-User Support
- Provide day-to-day helpdesk support for office and shop-floor staff
- Manage new-hire onboarding and offboarding: account provisioning, hardware imaging/deployment, and access assignment
- Support Microsoft 365 (email, file storage, Teams) for general business use
- Troubleshoot workstation, printer, and peripheral issues
Network & Server Administration
- Administer and maintain on-premises servers across a mixed environment (Windows Server, Ubuntu Server, SUSE), including file servers and the VLAN-segmented network
- Administer and monitor firewalls (Ubiquiti, Fortinet)
- Manage VPN and VDI access for remote and BYOD connections into locked-down virtual desktops
- Maintain server patching, backups, and disaster recovery procedures across all server platforms
- Administer Active Directory, group policy, and access controls
Endpoint & Asset Management
- Maintain an accurate hardware and software asset inventory across the environment
- Deploy and manage endpoint protection (SentinelOne), vulnerability scanning (Qualys), patching, and configuration baselines
- Manage device enrollment and policy via Microsoft Intune
- Support secure handling procedures for USB media and any CUI-scoped hardware (e.g., dedicated printers)
Compliance-Aligned Operations
- Support day-to-day operations of systems in scope for NIST SP 800-171 r2, maintaining system boundary integrity
- Assist in documenting system configurations and changes relevant to the SSP as requested
- Coordinate with the MSSP on security monitoring, alerts, and incident response support
- Support physical and access control requirements for CUI-handling areas
Required
- 5+ years of experience in IT support, network administration, or systems administration
- Strong Windows Server administration experience
- Linux server administration experience (Ubuntu Server, SUSE, or similar)
- Windows desktop administration and end-user support experience
- Solid understanding of networking fundamentals (VLANs, firewalls, VPN)
- Experience with Active Directory and Microsoft 365 administration
- Experience with endpoint security and management tooling (e.g., SentinelOne, Qualys, Microsoft Intune)
- Experience administering firewalls (Ubiquiti, Fortinet, or similar)
- Comfortable troubleshooting end-user hardware and peripheral issues
- Ability to follow documented security procedures in a controlled, regulated environment
- U.S. Person status, as required for access to ITAR-controlled technical data and CUI-scoped systems
- Ability to pass a background check and meet screening requirements for access to NIST SP 800-171 r2-scoped systems
Preferred
- Exposure to Kubernetes or other container orchestration platforms
- Exposure to NIST SP 800-171 r2 or other regulated/compliance-driven environments
- Experience supporting VDI environments
- Basic scripting (PowerShell or similar) to automate routine administrative tasks
- Experience with backup and disaster recovery tooling
This role is fully on-site in Tampa, FL. Due to ITAR and CUI handling requirements, this position requires day-to-day physical presence and hands-on access to on-premises systems.
SMART GoalsEndpoint & Network Hardening
- Specific: Complete a full inventory of endpoints and in-scope servers, and bring all assets to a current patch and configuration baseline
- Measurable: All assets documented in the asset inventory and confirmed on current patch baseline
- Achievable: Using existing endpoint management and patching tools
- Relevant: Supports readiness for the upcoming compliance assessment and reduces recurring support issues
- Time-bound: Complete within 60 days
Helpdesk & Access Management
- Specific: Standardize and streamline the onboarding/offboarding process and general helpdesk workflow
- Measurable: Documented onboarding/offboarding checklist in use for all personnel changes; ticket backlog kept current
- Achievable: Using existing ticketing and Active Directory tools
- Relevant: Improves employee experience and reduces access-related security risk
- Time-bound: Complete within 90 days
