Lead Systems Engineer (Microsoft Cloud)

PRECISESOURCE LLC
Coral Gables, FL, United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$200,000.0 - $300,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory ActiveSync Systems Engineering Microsoft Azure Microsoft Online Services Cloud Computing Data as a Services Dynamic Host Configuration Protocol Domain Name System (DNS) Hyper-V Virtual Private Networks (VPN)
+26 more
System Center Configuration Manager Windows Servers Virtual Desktops Routing Citrix Systems Windows PowerShell Role-Based Access Control Power BI Azure Active Directory Server Administration Server Virtualization Microsoft SharePoint Virtualization Technology Microsoft Power Automate Firewalls (Computer Science) Microsoft InTune HR Software Information Technology Deployment Automation Banner Advertisement 3-tier Architectures Powerapps Workday Unified Endpoint Management Citrix Netscaler Vmware

Job description

Precisesource, a national search firm is currently recruiting for a Lead Systems Engineer (Microsoft Cloud Engineer) to join for our client, a global multi-strategy private equity firm in Miami, FL (zip code 33134). In this role, the Lead Engineer will serve as a technical leader responsible for the architecture, administration, and ongoing optimization of the firm’s core Microsoft cloud and hybrid infrastructure, spanning endpoint management, identity, messaging, and virtualization. The ideal candidate needs exceptional communication skills and is equally comfortable collaborating with line employees, cross-functional IT teams, and executive leadership. This individual is an independent, organized self-starter with a proven ability to manage complex, concurrent initiatives, lead projects to completion, and influence technical direction within defined deadlines. This role is weighted toward cloud and identity engineering rather than on-premises server administration; working knowledge of virtual server environments is expected, but deep physical or virtual server build-out is a minor, not primary, part of the job.

This is a full-time position that requires the candidate to be onsite Monday - Friday to start before moving into a hybrid schedule. This is a level 2 service desk position in a Microsoft/Windows environment. Our client is offering a competitive base salary and annual bonus ranging in the $200k to $300k range, great benefits and career growth. Must be eligible to work for any US Employer unrestricted.

Role Responsibilities:

  • Own the Microsoft endpoint estate across Intune and SCCM in co-management, including workload transition, compliance and configuration profiles, and Proactive Remediations.
  • Lead Windows provisioning through Autopilot, including White Glove pre-provisioning, and maintain endpoint security baselines and GPO-to-CSP migration.
  • Administer Entra ID and hybrid Active Directory, including hybrid join, Windows Hello for Business, and device registration.
  • Design and maintain Conditional Access architecture, including guest access, device filters, and session controls, balancing security with usability.
  • Govern directory RBAC, license posture, dynamic group membership, and Multi-Geo data residency.
  • Administer Exchange Online and hybrid mail flow, distribution list lifecycle, and mobile mail via Exchange ActiveSync.
  • Hold primary responsibility for SharePoint and Microsoft Teams drive administration, including site/team creation, documentation, access review, and governance.
  • Operate the Citrix DaaS environment (VDA configuration, licensing, and Cloud Connector) and NetScaler gateway, and support ongoing evaluation and adoption of Azure Virtual Desktop and Microsoft Cloud PC / Windows 365 as the team’s virtualization footprint shifts further toward the cloud.
  • Deploy and maintain endpoint protection (for example, CrowdStrike) and drive hardening initiatives such as TLS deprecation, SMB signing, and logon banners in response to vulnerability findings.
  • Build and maintain PowerShell tooling to established coding standards, and Power Platform integrations (Power Automate, Power Apps) with Microsoft Graph, including HR-driven provisioning from Workday to Active Directory.
  • Collaborate with the teams that administer Power BI services, workspaces, and governance policies, providing identity and infrastructure support as needed.
  • Serve as a Tier 3 escalation point for the Service Desk Engineers (Tier 2), providing advanced troubleshooting and resolution for issues that fall outside standard Tier 2 scope.
  • Author change controls and lead CAB submissions; maintain SOPs, runbooks, and the IT knowledge base with disciplined, audience-aware documentation.
  • Maintain internal tooling and governance artifacts that standardize team workflows.

Requirements

  • Eight or more years in enterprise IT infrastructure or systems engineering, including three or more at a senior or lead level.
  • Proven ability to manage multiple concurrent projects and shifting priorities, paired with a generalist range across identity, endpoint, messaging, virtualization, and cloud infrastructure rather than deep specialization in a single domain.
  • Deep expertise in Microsoft endpoint management (Intune and SCCM co-management, Autopilot) and Microsoft identity (Entra ID, Active Directory, Conditional Access, and Windows Hello for Business).
  • Strong Exchange Online and hybrid administration, and broad Microsoft 365 experience.
  • Advanced PowerShell scripting and automation, including Microsoft Graph.
  • Working knowledge of virtualization and server fundamentals (for example Hyper-V or VMware, Windows Server roles) sufficient to support a hybrid environment; this is not a hands-on server build/rebuild role.
  • Strong working knowledge of enterprise networking fundamentals (DNS, DHCP, routing and firewall concepts, VPN, SSL/TLS) sufficient to troubleshoot cross-stack issues and partner effectively with the network engineering team; this is not a network engineering role.
  • Demonstrated change-control discipline and clear technical writing.
  • Experience operating in a security-conscious, regulated, or financial-services environment with least-privilege practices.

Professional Certifications and Technical Focus:

  • Citrix DaaS and NetScaler, and/or Azure Virtual Desktop experience.
  • Integration of HR systems (Workday) with identity provisioning.
  • Mimecast administration experience is a plus.
  • Relevant certifications, for example Microsoft MD-102, SC-300, MS-102, or AZ-104; Citrix CCA-V; and recognized security certifications.
  • Familiarity with IT service management frameworks such as ITIL is beneficial.

Job Type: Full-time, * Microsoft Endpoint Management: 4 years (Preferred)

  • Microsoft Identity: 4 years (Preferred)

Ability to Commute:

  • Coral Gables, FL 33134 (Preferred)

Benefits & conditions

Pulled from the full job description 401(k) Health insurance Paid time off Vision insurance Dental insurance, * 401(k)

  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · WWC 2025

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

5:06 min

Primary reasons for capability gaps in modern recruitment systems

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · WWC 2024

Videos

See all

Related articles

See all