Senior Systems Engineer

Posted 48mins ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Systems Engineer building internal cloud, IT, and cybersecurity functions for WRA, an employee-owned environmental consultancy. Owning Azure, Microsoft 365, identity, endpoints, automation, and security operations.

Responsibilities:

  • Build WRA’s new internal IT and cybersecurity functions while transitioning from an MSP model to an in-house model
  • Act as primary engineer for cloud and SaaS platforms, including Microsoft 365, Azure, Entra ID, endpoint management, and departmental platforms
  • Stand up new tools and assist with migration of tools currently used by the MSP
  • Engineer Azure Virtual Desktop, Microsoft 365/Entra ID, endpoint management, and automations
  • Own Azure Virtual Desktop and virtual servers, including image management, patching, right-sizing, scaling, scheduling, backups, performance optimization, and software versioning
  • Deploy monitoring and alerts for virtual machine performance, capacity, usage, and session latency
  • Perform root-cause analysis and propose solutions for virtual infrastructure issues
  • Administer Microsoft 365, including Exchange, SharePoint, OneDrive, Teams, and data governance
  • Coordinate with the Director and specialized departments to ensure tools are appropriately sized, configured, and performant
  • Co-manage SaaS and cloud infrastructure backup platforms
  • Administer Entra ID and SSO, including conditional access, authentication, dynamic groups, and guest access governance
  • Own identity lifecycle automations for onboarding, offboarding, and role changes
  • Maintain SCIM provisioning across SaaS applications
  • Manage Windows and limited Mac endpoints, including enrollment, Autopilot, compliance/configuration policies, app deployments, and patching
  • Manage mobile device configuration and application policies
  • Automate IT processes using PowerShell, Microsoft Graph, and other platforms
  • Improve implementation of Claude AI, including connector configurations, skills, and design
  • Build security operations capabilities from product selection through implementation and administration
  • Administer managed detection and response, email security, DNS/web filtering, and vulnerability management tools
  • Participate in incident response, investigations, root-cause analyses, and technical containment
  • Strengthen infrastructure for compliance with CMMC and NIST SP 800-171
  • Serve as final escalation point for complex IT support requests
  • Participate in an on-call rotation for rare critical outages
  • Maintain runbooks, architecture diagrams, and system configuration documentation
  • Follow industry-standard change management practices
  • Work under the guidance of the Director of Information Technology & Cybersecurity

Requirements:

  • At least 6 years of direct experience supporting a hybrid or remote workforce of at least 50 employees as an engineer
  • Comfortable working fully remote with travel to company offices as described
  • Demonstrated history of performing duties in a high-trust role
  • Strong history managing mission-critical Azure Virtual Desktops and application-specific servers
  • Deep hands-on experience with Microsoft 365 and Entra ID, including conditional access, provisioning, identity governance, and general administration
  • Experience managing distributed endpoints and mobile devices using Intune, NinjaOne, WorkspaceOne, or comparable tools
  • Proven track record using PowerShell to administer Microsoft 365 and Azure
  • Zero-trust security mindset
  • Excellent customer service skills and ability to explain complex technical issues in plain language
  • Able to lift up to 50 lbs, climb indoor ladders, crawl under furniture, and reach behind wall-mounted equipment
  • Bonus: experience supporting CAD/GIS applications, Egnyte, VantagePoint, Elevia, Bluebeam, Adobe Acrobat, Microsoft certifications, CMMC, NIST SP 800-171, CCPA, SOC 2, ITSM, ITIL, platform migrations, IAM automations, data retention policies, or UniFi Network and Protect

Benefits:

  • Employee-owned company
  • Flexible policies
  • Learning and professional development programs
  • Sustainability-focused employee programs
  • Policies supporting family priorities and healthy, balanced lives
  • Fully remote work within California, Colorado, Arizona, or Oregon
  • Travel to company offices 1–2 times per year on average