Windows server hardening consultant M/F
Published on 23/04/2026
Hays Luxembourg
Working time
Type of contract
Professional experience
Educational level
Share your Windows server hardening expertise !
Hays is looking for a Windows Server Hardening Consultant for one of its client based in Luxembourg.
- Freelance contrat or permanent contract via a payrolling company
- 1 remote day per week
- Location : Sandweiler (Luxembourg)
Your responsabilities :
- Windows Server security analysis
- Implementation of CIS Benchmarks
- Windows Server OS hardening
- Advanced Group Policy (GPO) configuration
- Active Directory (AD) security management
- Operational impact testing
- Hardening exception management
- PowerShell / DSC automation
- Security documentation
- Post-hardening Level 3 (L3) support
- Internal compliance audits
- Collaboration with infrastructure teams
- Security integration into IT projects
- Secure patch management
- Privileged account security management
- Security log management and analysis
- Microsoft security monitoring & threat intelligence
Your profile :
Technical Expertise
- Expert-level knowledge of Windows Server OS (2016/2019/2022) internals, services, security components, and registry-based configurations.
- Hands-on experience implementing CIS Windows Server Benchmarks (Level 1 & Level 2).
- Strong understanding of Active Directory, domain security policies, and Kerberos/NTLM authentication flows.
- Experience with Azure IaaS, including:
- Azure VM extensions
- Azure Policy
- Azure Automation / DSC
- Azure Monitor / Log Analytics
- Proficiency in PowerShell for automation, configuration, and troubleshooting.
Soft Skills
- Excellent analytical and diagnostic abilities.
- Strong communication skills for explaining complex technical impacts to non-technical stakeholders.
- Ability to work independently and serve as a trusted security advisor.
Preferred Qualifications
- CIS Benchmark certification or previous CIS hardening project experience.
- Microsoft certifications:
- AZ-104 (Azure Administrator)
- AZ-305 (Solutions Architect)
- SC-100/SC-200/SC-300 (Security)
- Experience with:
- Microsoft Defender for Cloud
- GPO modeling & Resultant Set of Policy (RSoP) analysis
- Blue Team / Security Operations