Sr Systems Engineer
About the Role
Architects, engineers, and administers cloud and on-premises system solutions with a focus on identity and access management (IAM) systems, Microsoft 365 solutions, virtualized server infrastructure, storage area network (SAN) environments, and operating systems.
Responsibilities
- Supports and ensures integrity and security for identity management and security systems.
- Deploys, maintains, upgrades, and resolves issues with Active Directory, Entra ID, and Identity and Access Management Systems for HR system integration, including joiner, mover, and termination processes, role-based access, and automated processes.
- Supports identity management for 3rd party applications and Azure Enterprise Applications, securing access using conditional access and MFA (Multi-Factor Authentication).
- Designs and supports authentication methodologies including Radius, LDAPS, SAML, Kerberos, PAM (Privileged Access Management), and certificate-based authentication.
- Designs, installs, and maintains the enterprise certificate environment.
- Works with Information Security to implement controls and security measures to protect local and cloud-based data.
- Deploys and supports Microsoft 365, MS Modern Desktop, and other SaaS solutions, including Exchange, SharePoint, and Teams.
- Architects the migration of on-premises files and data to SharePoint Online and OneDrive.
- Implements DLP (Data Loss Prevention), sensitivity, and retention labeling for data integrity and security.
- Serves as the senior administrator for one or more Microsoft 365 tenants, managing tenant configuration, security posture, licensing, and service health across the M365 suite (Exchange Online, SharePoint Online, Teams, OneDrive for Business, and Intune).
- Manages M365 identity and access governance, including role-based access control (RBAC), privileged identity management (PIM), guest/external access policies, and cross-tenant collaboration settings.
- Oversees Exchange Online administration, including mail flow rules, connectors, anti-spam/anti-phishing policies, shared mailboxes, and distribution groups.
- Administers Microsoft Teams governance, including team lifecycle policies, meeting configurations, and compliance recording.
- Monitors tenant health, service incidents, and adoption metrics through the M365 Admin Center and Defender portals.
- Supports system administrators with endpoint management and security solutions for Windows workstations and servers, Android, and iOS devices.
- Assists system engineers in designing and implementing security at the server operating system level, including hardening and patches.
- Manages Azure, AWS, and GCP public cloud platforms, including identity, security, policy management, and cost allocation.
- Designs, implements, and manages other cloud SaaS systems to reduce enterprise costs and complexity while increasing reliability.
- Owns and administers the on-premises Active Directory environment, including domain and forest architecture, domain controller deployment, AD sites and services, replication topology, and Group Policy infrastructure.
- Designs and maintains Group Policy Objects (GPOs) for security baselines, software deployment, and compliance enforcement.
- Manages AD trust relationships, organizational unit (OU) structure, delegation of control, and role-based administrative access.
- Administers and maintains Microsoft Entra ID (Azure AD) Connect for hybrid identity synchronization and seamless SSO configurations.
- Leads identity lifecycle management processes, including provisioning, de-provisioning, access reviews, and privileged account governance.
- Monitors AD health and security using tools such as Microsoft Defender for Identity.
- Maintains AD disaster recovery capabilities, including authoritative and non-authoritative restore procedures.
- Serves as the primary subject matter expert and administrator for hybrid virtualized environments spanning VMware vSphere/ESXi and Microsoft Hyper-V platforms.
- Designs, deploys, and maintains VMware vSphere clusters, including vCenter Server, ESXi hosts, vMotion, High Availability (HA), Distributed Resource Scheduler (DRS), and Fault Tolerance configurations.
- Administers Microsoft Hyper-V environments, including failover clustering, Live Migration, and Hyper-V Replica.
- Leads capacity planning efforts across VMware and Hyper-V platforms.
- Develops and enforces standards, policies, and procedures for VM provisioning, template management, and lifecycle management.
- Architects, deploys, and administers VMware vSAN clusters and Fibre Channel SAN infrastructure, including zoning, LUN provisioning, and HBA configuration.
- Oversees SAN connectivity for VMware and Hyper-V hosts, ensuring proper multipathing and failover validation.
- Monitors SAN and vSAN performance, diagnosing and resolving storage latency, throughput, and connectivity issues.
- Configures and manages virtual networking components within VMware and Hyper-V environments.
- Collaborates with network engineering teams on integrating virtual infrastructure with physical switching, routing, and Fibre Channel fabric.
- Installs and troubleshoots TCP/IP support infrastructure, including DHCP and DNS.
- Collaborates with operations staff to ensure reliable operation of software and systems for business objectives.
- Builds and maintains complex real-time monitoring systems for critical business applications.
- Participates in business continuity and disaster recovery design, implementation, and testing.
- Creates and maintains documentation related to system configuration, mapping, processes, and service records.
- Maintains technical adherence to external compliance mandates and assists in developing policies and procedures.
- Drives infrastructure automation and operational efficiency through scripting (PowerCLI, PowerShell) and infrastructure-as-code toolsets.
- Mentors junior systems staff on virtualization best practices, storage fundamentals, and operational procedures.
Requirements
- Minimum of 7 years of experience in systems administration, administering Windows-based systems and Active Directory, RDP, security and user management, disaster recovery, and documentation.
- Demonstrated hands-on experience administering VMware vSphere/ESXi and Microsoft Hyper-V environments in a production setting.
- Experience managing Fibre Channel SAN infrastructure, including zoning, LUN management, and HBA configuration.
- Experience with VMware vSAN architecture, configuration, and administration.
- On-call support (continuously or rotationally) required.
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent experience.
- Knowledge and experience with Identity and Access Management Systems.
- Tenant Global Administrator for M365 experience.
- VMware Certified Professional (VCP) or Microsoft Certified: Azure Administrator / Hybrid Administrator credentials.
Skills
- Knowledge of engineering science and technology principles, techniques, and equipment.
- Knowledge of data privacy and security practices and laws.
- Ability to develop and follow best practices and prescribed methodologies.
- Ability to conduct research into systems issues and products.
- Strong communication skills, both technical and business-friendly, for executive and managerial audiences.
- Strong customer service orientation.
- Ability to prioritize and execute tasks in a high-pressure, team-oriented environment.
- High level of professionalism and interpersonal skills.
- Excellent critical thinking, analytical, and problem-solving skills.
- General knowledge of network switches, firewalls, and routers.
- Proficiency in scripting languages such as PowerShell, PowerCLI, Java, or ASP.NET.
Other Duties
This job description includes essential functions and duties required for this position. Additional duties may be assigned as needed to meet organizational requirements.
Serves as a role model in carrying out activities and behaviors that reflect the values and principles of the organization.
Work Environment
Position is relatively sedentary in a normal office administrative environment with minimal exposure to physical risks. Involves the use of office equipment such as a computer/laptop, monitor, keyboard, and a general workstation setup.