GENERAL SUMMARY:
The Senior IT Systems Engineer is responsible for the architecture, design, implementation, optimization, and operational support of enterprise infrastructure solutions in a Microsoft Azure cloud environment. This role provides technical leadership and advanced engineering expertise in Microsoft Azure, Active Directory, Microsoft Entra, Okta, Cisco Duo, Windows Server, enterprise networking, and hybrid cloud services.
The Senior IT Systems Engineer serves as the senior technical resource for cloud strategy, infrastructure architecture, identity and access management (IAM), networking, systems modernization, and security initiatives. This position is responsible for designing scalable, secure, and highly available solutions; establishing technical standards; leading enterprise infrastructure projects; and serving as the highest-level escalation point for complex infrastructure-related issues.
This position is also responsible for recommending, defining, standardizing, documenting, testing, and implementing solutions that align with business objectives. The Senior IT Systems Engineer develops technical roadmaps, mentors engineering staff, collaborates with vendors and stakeholders, and ensures the reliability, security, and performance of critical technology platforms.
MAJOR DUTIES/RESPONSIBILITIES:
- Architect, design, implement, and support enterprise cloud solutions utilizing Microsoft Azure services including Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), storage, networking, backup, disaster recovery, monitoring, security, and identity services.
- Lead Azure modernization, optimization, governance, and cloud transformation initiatives.
- Develop and maintain Azure landing zones, governance standards, subscription management strategies, and cloud security best practices.
- Architect and administer Azure networking services including Virtual Networks, VPN Gateways, ExpressRoute, Azure Firewall, Application Gateways, Network Security Groups, Load Balancers, and connectivity solutions.
- Architect, implement, and support enterprise Identity and Access Management (IAM) solutions utilizing Active Directory, Microsoft Entra ID, Okta, and Cisco Duo.
- Design and maintain hybrid identity architectures supporting cloud and on-premises environments.
- Implement and administer Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access policies, adaptive authentication, and identity governance controls.
- Lead Active Directory administration activities including domain architecture, forest management, replication troubleshooting, Group Policy management, domain controller deployments, upgrades, migrations, and health monitoring.
- Design, administer, and maintain Group Policy Objects (GPOs) to support security, compliance, endpoint management, and operational requirements.
- Perform advanced engineering and administration for Windows Server environments, including DNS, DHCP, Certificate Services, file services, and core infrastructure components.
- Architect, implement, and support Cisco Meraki networking solutions, including:
- Meraki MX Security Appliances
- Meraki MS Switching
- SD-WAN Technologies
- Site-to-Site VPN Connectivity
- Cloud-Managed Network Monitoring and Administration
- Manage and support physical and virtual network infrastructure, ensuring security, high availability, performance, and reliability.
- Monitor, troubleshoot, and optimize enterprise infrastructure across cloud, server, identity, networking, and virtualization platforms.
- Collaborate with Information Security teams to implement infrastructure security controls, vulnerability remediation programs, and compliance initiatives.
- Serve as the highest-level escalation point for complex Azure, Active Directory, networking, identity, and infrastructure issues.
- Evaluate emerging technologies and recommend solutions that improve scalability, resiliency, security, operational efficiency, and user experience.
- Develop and maintain infrastructure standards, technical documentation, operational procedures, diagrams, and support processes.
- Lead infrastructure projects and provide technical leadership and mentoring to engineering staff.
- Oversee installation, configuration, patching, lifecycle management, and performance optimization of enterprise infrastructure platforms.
- Support Azure-based virtualization technologies.
- Maintain accountability for infrastructure availability, disaster recovery readiness, business continuity planning, and operational excellence.
- Manage relationships with technology vendors, consultants, cloud providers, and managed service partners.
- Support Citrix technologies as required for application delivery and legacy platform support.
BASIC REQUIREMENTS:
- Bachelor's degree in Information Technology, Computer Science, Engineering, or equivalent combination of education, certifications, and experience.
- 7+ years of experience supporting engineering enterprise infrastructure environments.
- 5+ years of hands-on experience architecting, deploying, and supporting Microsoft Azure solutions.
- Strong experience with Azure services including:
- Azure Virtual Machines
- Azure Storage
- Azure Backup
- Azure Site Recovery
- Azure Networking
- Azure Monitor
- Azure Security Services
- Azure Identity Services
- 5+ years of experience supporting Active Directory within complex enterprise environments.
- 5+ years of experience creating, managing, and deploying Active Directory Group Policy Objects (GPOs).
- Demonstrated experience performing Active Directory domain controller upgrades, migrations, replication troubleshooting, and overall domain health management.
- Experience implementing and supporting Microsoft Entra ID (Azure AD), hybrid identity solutions, and cloud authentication services.
- 5+ years of experience supporting Identity and Access Management (IAM) platforms.
- Experience implementing and administering Okta and Cisco Duo authentication solutions.
- Strong understanding of authentication and identity protocols including LDAP, Kerberos, SAML, OAuth 2.0, OpenID Connect (OIDC), and SCIM.
- Experience configuring Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, and identity lifecycle management processes.
- Strong experience administering Windows Server operating systems and enterprise infrastructure services.
- Experience supporting Cisco Meraki networking platforms including security appliances, switching, wireless networking, SD-WAN, VPN technologies, and cloud-managed networking.
- Strong networking knowledge including:
- Routing and Switching
- VLAN Configuration
- WAN Technologies
- TCP/IP
- DNS
- DHCP
- Network Security
- VPN Technologies
- Experience utilizing PowerShell and automation tools for systems administration and infrastructure management.
- Extensive experience troubleshooting and resolving complex infrastructure, networking, identity, and cloud-related issues.
- Strong analytical and independent problem-solving abilities.
- Excellent written, verbal, and presentation communication skills.
- Ability to lead technical teams and successfully manage engineering projects and initiatives.
- Proven ability to collaborate effectively with business stakeholders, vendors, security teams, and IT leadership.
PREFERRED/DESIRED QUALIFICATIONS:
- Experience within the Financial Services, Banking, or Consumer Finance industry.
- Microsoft Azure certifications such as:
- Azure Administrator Associate (AZ-104)
- Azure Network Engineer Associate (AZ-700)
- Azure Solutions Architect Expert (AZ-305)
- Okta Certified Professional, Administrator, or Consultant certification.
- Cisco Meraki certifications (CMNA, ECMS, or equivalent).
- Experience with Infrastructure as Code (IaC) tools such as Terraform.
- Experience with Microsoft Intune and Endpoint Management solutions.
- Experience administering Microsoft 365 services and security technologies.
- Experience with disaster recovery, business continuity, and high-availability architectures.
- Experience with enterprise monitoring and observability platforms.
COMPENSATION:
- The salary range for this position is competitive based on the job duties as well as the specific Knowledge, Skills, Abilities and Experience of the selected candidate.
- This position is eligible for Quarterly Incentive compensation based on individual and company performance guidelines.
WORKING CONDITIONS:
- Normal office environment.
- Participation in after-hours maintenance windows and on-call support rotations as needed.
- Travel by car and air may be required.
- Travel frequency up to 10%.