Infrastructure Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+57 more
Job description
The Infrastructure Engineer is the District’s senior hands-on engineer for enterprise network and cloud infrastructure. Reporting to the Infrastructure Solutions Architect (ISA), the Engineer builds, configures, operates, and troubleshoots the platforms that carry every instructional and operational system in the District - the Cisco Meraki campus and wireless estate across all school sites, the data center and administrative network, the District’s SD-WAN and carrier transport, and the network foundation of the Azure environment that now hosts the majority of District workloads. Where the ISA sets architecture, standards, and roadmap, the Engineer implements those standards and owns day-to-day engineering outcomes: designs are turned into working configurations, changes are planned and executed within approved windows, and faults are isolated and resolved. The Engineer is expected to work independently on complex problems, to propose design alternatives back to the ISA with supporting analysis, and to serve as the District’s deepest source of operational knowledge on the network estate. As a secondary assignment, the Engineer serves as a backup and day-to-day implementer on the District’s endpoint and device management platforms, and supports the District’s remaining on-premises platform services - VMware vSphere, Active Directory Domain Services, DNS, file, print, and SMTP relay
-
as legacy services, while continuing migration to Azure equivalents. This is an individual contributor role. The Engineer provides technical guidance and mentorship to Specialists, Administrators, and building technicians, but does not carry supervisory responsibility; day-to-day task assignment and performance management sit with the ISA., Network Engineering and Operations
-
Engineer, configure, deploy, and maintain the District’s Networking estate: security appliances and their NextGen Layer 7 functions, Layer 3 distribution and Layer 2 access switches, and wireless access points across all school sites.
-
Maintain Layer 3 services delivered at the site edge, including DHCP scopes, relay, and inter-VLAN routing hosted on the Layer 3 switches at each building.
-
Engineer and support the data center and administrative network, including data center switching and routing platforms (OSPF/BGP as deployed), QoS, and network segmentation.
-
Support the District’s SD-WAN and WAN transport, site turn-ups, path policy, failover behavior, and carrier fault isolation and escalation.
- Implement and maintain network segmentation, access control lists, VPN services, and Network Access Control integrations in accordance with architecture standards and Cybersecurity requirements.
- Perform switch, firewall, and appliance firmware lifecycle management; plan and execute upgrades inside approved change windows.
-
Support fiber and structured cabling projects with Facilities, Capital Improvements, and District contractors: validate designs, confirm circuit and patching records, and commission or decommission new, renovated, or repurposed buildings.
-
Serve as the District’s internal escalation point for network faults raised by IT Customer Excellence, building technicians, and site staff - the level above front-line support, below vendor engineering.
- Own the onward escalation path once District-side troubleshooting is exhausted: open and drive cases directly with the network platform support vendor and engage the District’s network managed service provider for enterprise and data center network platforms. Provide the diagnostic detail the case requires, stay engaged through resolution, and confirm the fix rather than handing the fault off
Cloud Infrastructure Engineering (Azure)
-
Own the network foundation of the District’s Azure presence: ExpressRoute circuits, peering and gateways, the routing relationship between ExpressRoute and the District’s SD-WAN transport, virtual network and subnet design, route tables, network security groups, and name resolution across the on-premises boundary.
-
Engineer Azure IaaS in partnership with the Server Administrator and the District’s managed service provider, who carry day-to-day administration: sizing, placement, connectivity, resiliency, and the design decisions that follow from District architecture standards.
-
Assist in defining the backup, replication, and recovery configuration infrastructure workloads are held to - retention, recovery objectives, and replication targets - and validate that what is implemented and reported meets it; participate in recovery testing and document results.
-
Support workload migration from on-premises platforms to Azure equivalent services: network readiness, dependency assessment, cutover execution, and post-migration validation, with the Server Administrator and the managed service provider.
-
Provide depth behind the Server Administrator on Azure infrastructure work during absence, escalation, or a major incident.
-
Validate that Azure work delivered by the managed service provider meets District architecture and security standards; provide technical input on capacity, performance, and cost.
-
Apply infrastructure automation and Infrastructure-as-Code practices to network and connectivity builds where standards call for it; maintain scripts and runbooks to District coding standards
Wi-Fi Engineering and Surveying
-
Deploy, tune, and troubleshoot District wireless in line with WLAN standards: channel and power plans, RF hygiene, roaming behavior, capacity in high-density spaces, and client-side troubleshooting across Chromebook, iPad, macOS, Windows, and Android device populations.
-
Maintain the legacy wireless estate at school sites still served by Cisco Catalyst wireless LAN controllers and Aironet access points, and migrate them to the Meraki wireless standard as refresh funding allows.
-
Conduct predictive, validation, and troubleshooting wireless surveys using Ekahau; produce survey output and remediation recommendations for ISA review.
Reliability, Monitoring, and Change Management
-
Implement and maintain monitoring, alerting, and telemetry for network, cloud, and server infrastructure; tune alerting to reduce noise and surface real degradation.
-
Execute changes through the District change management process; prepare implementation plans, test plans, and rollback criteria for review.
-
Respect maintenance and change-freeze windows aligned to academic, graduation, and statewide testing calendars; schedule disruptive work accordingly.
-
Contribute capacity, lifecycle, and refresh data to the ISA’s planning and E-Rate cycles.
-
Maintain accurate configuration, circuit, IP address management, and CMDB records; keep documentation current as a condition of closing work.
Data Center and Legacy Platform Operations Support
-
Administer the VMware vSphere environment: hosts, clusters, virtual machine lifecycle, resource allocation, patching, and capacity monitoring.
-
Maintain remaining on-premises Microsoft platform services - Active Directory Domain Services, DNS, file services, print services, and SMTP relay - as legacy services pending migration.
-
Maintain the server, storage, and backup platforms remaining in the District data center; set the standards they run to and carry out lifecycle replacement and routine maintenance.
-
Execute retirement and decommissioning of legacy systems as workloads transition to Azure, including dependency validation, cutover, and documentation updates.
-
Assist in defining and maintaining disaster recovery and business continuity provisions for network, computing, and storage systems; verify recoverability through periodic exercises., * Serve as backup and day-to-day implementer on District endpoint and device management platforms (Microsoft Intune and Autopilot, Apple School Manager, Jamf, Samsung Knox, Clevertouch MDM), executing configuration, enrollment, policy, and application distribution tasks to defined baselines.
-
Support the network-side dependencies of those platforms: certificate and PKI distribution, 802.1X and NAC integration, secure Wi-Fi and VPN profiles, and connector health.
- Provide escalation support to the 1:1/Device Prep Team and Customer Excellence Specialists on platform issues with an
- infrastructure root cause.
Security and Compliance Support
-
Implement infrastructure security controls defined with the Division of Cybersecurity and IT Risk Management & Compliance; apply hardening baselines and zero-trust patterns to network and cloud builds.
-
Remediate infrastructure vulnerabilities on the priority and schedule set by Cybersecurity and the ISA; report exceptions with compensating controls.
-
Support FERPA, CIPA, and District policy compliance in infrastructure configuration, including content filtering and logging dependencies.
-
Provide technical analysis and evidence during network security incidents and audits.
Incident Response and After-Hours Support
-
Participate in after-hours and weekend maintenance windows, cutovers, and emergency response; share on-call coverage for network and infrastructure outages.
-
Serve as a technical responder on the ITOps network security incident response team; support triage, containment, recovery, and post-incident review under the ISA’s coordination.
-
Perform fault isolation with carriers, managed service providers, and vendors during outages, including fiber, power, and environmental events affecting site connectivity.
-
Contribute to root cause analysis and corrective actions after significant incidents
Vendor, Managed Service Provider, and Documentation Support
-
Work with vendors and managed service providers on implementation, escalation, and chronic issue remediation - principally Cisco Meraki support and the District’s network managed service provider; validating that delivered work meets District standards and tracking open cases to closure.
-
Contribute technical requirements, configuration details, and effort estimates to the ISA for RFPs/RFQs, evaluations, and proofs of concept.
-
Create and maintain technical documentation, standard configurations, runbooks, and knowledge transfer materials for ITOps and Customer Excellence staff.
-
Travel within the District as required; occasional out-of-District travel.
-
Other duties as assigned by the supervisor., * Regular evenings/weekends availability for maintenance windows and cutovers; flexibility in work hours contingent on District needs, including short notice and beyond school hours.
Requirements
- Bachelor’s degree in computer science, Information Technology, Engineering, or a related field, or equivalent work experience.
Work Experience
-
5 years of progressive experience engineering and operating enterprise-level network infrastructure in a multi-site environment.
-
3 years of hands-on experience with cloud infrastructure services, Azure preferred, including virtual networking and hybrid connectivity.
-
3 years’ experience with enterprise routing and switching, firewalls/UTM, and WAN or SD-WAN transport.
-
2 years’ experience administering virtualization and core Microsoft platform services (vSphere, Windows Server, Active Directory Domain Services, DNS).
-
2 years’ experience with enterprise wireless deployment, tuning, and RF troubleshooting, including use of survey tools (e.g., Ekahau).
-
1 year of exposure to endpoint/device management platforms in an operational or backup capacity.
-
Experience participating in after-hours incident response and major outage recovery.
-
K-12 or public sector experience, including E-Rate funded infrastructure, preferred.
Competency
- Works independently on complex technical problems; escalates with analysis, not just symptoms.
- Disciplined change practice - plans, tests, documents, and can back out cleanly.
-
Clear written and verbal communication with technical peers, District staff, and vendors.
-
Customer-focused and process-driven; protects instructional time in scheduling and execution.
- Collaborative across ITOps, Cybersecurity, Customer Excellence, and operational departments.
Technical Breadth
-
Cisco Meraki full stack and Cisco Catalyst/Nexus platforms.
-
Enterprise routing, switching, segmentation, QoS, VPN, and Network Access Control.
-
Cisco Catalyst wireless LAN controllers and Aironet access points in a legacy support and migration context.
-
SD-WAN and carrier WAN services, including circuit turn-up and fault isolation.
-
Azure IaaS, virtual networking, ExpressRoute, backup and site recovery; Entra ID fundamentals.
-
VMware vSphere, Windows Server, Active Directory Domain Services, DNS, file, print, and SMTP relay services.
-
Monitoring and observability tooling; scripting and Infrastructure-as-Code (PowerShell preferred).
-
Security fundamentals aligned to NIST and zero trust; familiarity with firewalls, IDS/IPS, NAC, and SIEM.
Preferred Certifications
-
CCNA required or obtainable within the first year; CCNP Enterprise preferred.
-
Cisco Meraki certification (CMNA/ECMS) preferred.
-
Microsoft Azure Administrator Associate (AZ-104) or Azure Network Engineer Associate (AZ-700) preferred.
-
Ekahau ECSE preferred.
-
VMware VCP, Microsoft Windows Server certifications, ITIL Foundation, CompTIA Network+/A+ are a plus but not required.
Benefits & conditions
The characteristics listed below represent the work environment typically encountered while performing the essential duties of this position. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential duties.
- While performing the duties of this job, the employee is regularly required to stand, walk, and sit; use hands to finger, handle, or feel; and reach with hands and arms.
- The employee is frequently required to talk and/or hear.
- Standard office, technical room, data center, and active school building environments; frequent travel between a large number of school sites.
- Work in telecom closets and above-ceiling spaces; occasional ladder use and lifting of equipment up to 50 pounds.
About the company
The Cleveland Metropolitan School District (CMSD) is Ohio’s third-largest public school system, serving more than 35,000 students.
CMSD strives to ensure that every child receives a high-quality education, regardless of the provider. To that end, CMSD lets families choose which District schools their children attend, with options that include STEM, the arts, single-gender education, International Baccalaureate, Montessori, and early college.
Our schools have autonomy over human and financial resources in exchange for accountability for performance. The principal has primary responsibility and accountability for establishing their school as a high-quality, high-expectation academic center focusing on personalized instruction, professional support for teachers, and school-wide practices that lead to measurable results.
CMSD ensures that students have access to technology and training to prepare them for the future. The District provides a free laptop or tablet for every student and connects every family that needs internet access. Graduating seniors leave commencement with not only a diploma but also a laptop.
In our pursuit of a more fair, just, and good system of education, we strive to ensure that all of our learners, both scholars and educators, to be challenged with academically and intellectually complex tasks that are worthy of their efforts and provide them opportunities to demonstrate their best work., The Cleveland Board of Education adopted the Building Brighter Futures (BBF) initiative on December 9, 2025. Building Brighter Futures is a strategic and data-driven plan shaped by more than a year of community engagement, information analysis, and thoughtful deliberation. The goal of this plan is to strengthen enrollment and ensure scholars attend a newer school building that offers more educational opportunities, including algebra in the eighth grade, more sports and extracurricular activities, and college credits and college and career pathways in high school. BBF is ensuring academic excellence so every CMSD scholar can thrive.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
Best Coding Boot Camps in Germany
Top Characteristics of a Software Engineer