Job Profile:
Senior Systems Engineer
Job Description Summary:
We are committed to providing a competitive and equitable total rewards package. The compensation for this role is designed to attract, retain, and motivate top talent.
The expected base salary range for this position is $125,000 to $145,000 annually.
Job Description:
What's the Role?The Senior Systems Engineer is a hands-on technical owner for enterprise infrastructure and platform services across on-premises and cloud environments. This role designs, automates, secures, and operates highly available systems; leads complex troubleshooting and root-cause analysis; and turns recurring operational work into reliable, supportable automation. The engineer owns work from discovery and design through implementation, documentation, operational handoff, and production support.
This is a senior individual-contributor role for someone who can balance deep Microsoft infrastructure expertise with cloud, automation, observability, security, and service-management practices. The successful candidate communicates clearly, makes sound risk-based decisions, and improves both the technology and the way the team operates it.
ResponsibilitiesInfrastructure Engineering and Architecture- Design, implement, and support resilient enterprise infrastructure across Windows Server, Active Directory, Group Policy, DNS, DHCP, PKI/certificates, virtualization, compute, storage, and related platform services.
- Engineer and operate Microsoft 365 and hybrid identity and messaging services, including Microsoft Entra ID, Exchange Online/Hybrid, Teams, SharePoint, and OneDrive, in partnership with service owners.
- Lead technical discovery, solution design, implementation planning, testing, deployment, and operational handoff for infrastructure initiatives.
- Develop standards, reference architectures, lifecycle plans, capacity forecasts, and technical-debt roadmaps that improve reliability, security, and supportability.
Automation and Platform Improvement- Develop production-quality automation primarily with PowerShell and, where appropriate, Python, shell scripting, REST APIs, Microsoft Graph, Git, and CI/CD practices.
- Apply infrastructure-as-code and configuration-management principles to improve consistency, peer review, recoverability, and deployment speed.
- Build validation, logging, audit trails, error handling, retry logic, safe failure behavior, and rollback paths into automation and operational tooling.
- Identify repetitive work and recurring failure patterns, then create measurable improvements that reduce manual effort, risk, and time to recover.
Reliability, Security, and Operations- Monitor service health, performance, capacity, configuration drift, and security posture; use telemetry to identify issues before they become business disruptions.
- Lead incident response for complex infrastructure events, perform root-cause analysis, and track corrective actions through completion.
- Partner with Security and Compliance teams to implement least privileged access controls, secure configuration baselines, vulnerability remediation, patching, logging, encryption, and evidence collection.
- Design, maintain, and regularly test backup, restore, disaster recovery, and business-continuity capabilities; document recovery objectives, dependencies, and runbooks.
- Plan and execute upgrades, migrations, patching, lifecycle refreshes, and changes using disciplined change management and risk assessment practices.
- Participate in an on-call rotation and support major changes or incidents outside normal business hours when required.
Service Ownership and Collaboration- Maintain accurate architecture diagrams, standards, configuration records, knowledge articles, operational procedures, and service ownership documentation.
- Create complete ServiceNow and Jira records that clearly capture scope, impact, implementation steps, validation, rollback, decisions, and outcomes.
- Serve as a senior escalation point, mentor other engineers, review technical work, and share knowledge through documentation and practical coaching.
- Work effectively with distributed teams, vendors, managed service providers, and business stakeholders; communicate technical risk, tradeoffs, status, and recommendations in clear language.
- Use cost, utilization, reliability, and support data to recommend platform consolidation, retirement, modernization, or optimization.
Required Qualifications- 5+ years of progressive, hands-on systems engineering or infrastructure administration experience in a medium-to-large enterprise environment.
- Demonstrated experience administering Windows Server, Active Directory, Group Policy, DNS, DHCP, and enterprise authentication and authorization services.
- Hands-on experience with Microsoft 365, Microsoft Entra ID, and Exchange Online or Exchange Hybrid administration.
- Hands-on experience with at least one public cloud platform (Azure preferred; AWS experience also valued) and with hybrid-cloud connectivity and operations.
- Strong PowerShell skills, including reusable functions, structured error handling, logging, secure credential handling, and integration with APIs or administrative modules.
- Experience with VMware vSphere, Hyper-V, or comparable virtualization platforms and with server, storage, backup, and recovery technologies.
- Working knowledge of TCP/IP, routing fundamentals, firewalls, load balancers, certificates, proxies, and other infrastructure dependencies needed for end-to-end troubleshooting.
- Working knowledge of enterprise security practices, including least privilege access, patch and vulnerability management, secure baselines, audit logging, and change control.
- Proven ability to diagnose complex incidents, coordinate recovery, document root causes, and deliver durable corrective actions.
- Clear written and verbal communication, strong operational judgment, and the ability to manage multiple priorities without sacrificing quality or control.
Preferred Qualifications- Infrastructure-as-code or configuration-management experience with Terraform, Bicep/ARM, Ansible, PowerShell Desired State Configuration, or similar tooling.
- Experience with Git-based workflows, CI/CD pipelines, automated testing, REST APIs, and Microsoft Graph.
- Experience with endpoint or server management platforms such as Microsoft Intune, Configuration Manager, Azure Arc, or comparable tools.
- Experience with observability, log analytics, SIEM, or endpoint security platforms such as Microsoft Sentinel, Defender, CrowdStrike, Splunk, or Logscale.
- Working knowledge of Linux administration, container platforms, and cloud-native operating practices.
- Experience in a regulated environment with formal audit, risk, compliance, data protection, or business-continuity requirements.
- Relevant Microsoft, Azure, AWS, VMware, security, or IT service management certification.
Other Useful Details Employee Type: Full-Time
Pay Range: annual pay + bonus and/or commissions
Location: Chicago (Hybrid)