Sr. IT Engineer - Systems & Cloud is responsible for the operation, administration, and continual improvement of the Group's Microsoft Azure environment, Windows and Linux systems, Azure Virtual Desktop, and Windows endpoint management platform.
The role ensures cloud infrastructure, systems, and managed endpoints remain secure, reliable, resilient, scalable, patched, compliant, and cost-effective through effective monitoring, automation, lifecycle management, and operational best practices.
The role operates within approved Group IT Operations standards and priorities, escalating significant risks, architecture changes, investments, and cross-functional decisions to the Sr.
IT Manager - Operations & Service Management.
1. Systems & Cloud Operations
• Administer and support Microsoft Azure infrastructure and related cloud services, including compute, storage, backup, monitoring, and related resources, coordinating with the Network team for Azure networking and connectivity.
• Administer and support Azure Virtual Desktop, including host pools, session hosts, application groups, FSLogix profiles, scaling, monitoring, user access, and troubleshooting.
• Administer Windows Server and Linux systems, including provisioning, configuration, monitoring, maintenance, troubleshooting, and service restoration.
• Manage OS patching and security updates for Windows and Linux servers, including deployment, monitoring, remediation, and compliance reporting.
• Maintain and periodically validate backup, recovery, and disaster recovery capabilities for critical systems and Azure workloads.
• Monitor and optimize system performance, capacity, resource utilization, and Azure costs using Azure Monitor, Log Analytics, Cost Management, alerts, and related tools.
• Manage Azure operational governance within approved standards, including RBAC, Azure Policy, resource organization, tagging, and least-privilege access within the assigned infrastructure scope.
• Develop and maintain automation and Infrastructure as Code (IaC) using Bicep, Terraform, or equivalent tools to improve consistency, reliability, scalability, and operational efficiency.
2. Endpoint Platform Management
• Administer Microsoft Intune and Windows Autopilot for corporate Windows device provisioning, enrollment, configuration, compliance, Windows Update management, reset, retirement, and troubleshooting.
• Manage endpoint configuration and technical security controls, including security baselines, BitLocker, device compliance, and local administrator controls.
• Monitor endpoint health, patching, configuration, and compliance status, and remediate recurring issues or configuration drift.
• Maintain endpoint policies, deployment profiles, and configuration standards to support consistent and scalable device management.
• Coordinate with M365, Service Desk, Onsite IT, and Information Security for application deployment, identity and access controls, endpoint security requirements, and user support.
3. Service Operations & Continual Improvement
• Manage infrastructure and endpoint incidents, service requests, problems, and changes in accordance with ITSM, SLA, security, and change management procedures.
• Troubleshoot complex cloud, server, AVD, and endpoint platform issues, perform root cause analysis, and coordinate with Microsoft, managed service providers, vendors, and internal IT teams for service restoration.
• Maintain system inventories, technical documentation, SOPs, operational procedures, and knowledge articles.
• Review technical implementation plans and provide guidance to IT teams for complex systems, cloud, and endpoint platform activities.
• Identify and implement opportunities to improve reliability, resilience, automation, capacity, patching, security, cost efficiency, and operational quality.
• Provide capacity, lifecycle, cost, risk, and technical recommendations to the Sr. IT Manager - Operations & Service Management to support prioritization, budgeting, investment, and technology decisions
• Diploma or Bachelor's degree in Information Technology, Computer Science, Information Systems, or a related field.
• Microsoft certifications such as Azure Administrator Associate (AZ-104) and Endpoint Administrator Associate (MD-102) are preferred.
• ITIL Foundation certification is an advantage.
• Strong hands-on experience administering Microsoft Azure infrastructure, Windows Server, and Linux systems in production environments.
• Hands-on experience administering Azure Virtual Desktop, including session hosts, FSLogix, monitoring, scaling, and troubleshooting.
• Strong hands-on experience with Microsoft Intune and Windows Autopilot for corporate Windows device provisioning, configuration, compliance, security baselines, and update management.
• Good experience with Azure monitoring, backup and recovery, RBAC, Azure Policy, capacity management, and cost optimization.
• Working knowledge of PowerShell, Bash, Azure CLI, automation, and IaC using Bicep, Terraform, or equivalent tools.
• Strong troubleshooting and problem-solving skills across cloud, systems, AVD, and endpoint environments.
• Good written and spoken English communication skills, with the ability to work effectively with IT teams, vendors, and service providers.
• 5+ years of experience in systems administration, cloud operations, infrastructure, or endpoint platform management.
• Hands-on experience supporting Microsoft Azure, Windows Server, Linux, AVD, Intune, and Windows Autopilot in production environments.
• Experience supporting enterprise or multi-site IT environments and working with cross-functional IT teams and service providers.
• Strong understanding of cloud infrastructure, Windows and Linux systems, virtualization, backup and recovery, monitoring, patching, capacity, and lifecycle management.
• Good understanding of Azure governance, RBAC, Azure Policy, tagging, resource organization, monitoring, and cost management.
• Good understanding of endpoint management, Windows security baselines, BitLocker, device compliance, Windows Update, and Windows device lifecycle.
• Good understanding of networking fundamentals required to deploy and troubleshoot Azure workloads, including TCP/IP, DNS, subnets, routing, firewalls, and private connectivity.
• Good understanding of security principles including least privilege, Zero Trust, secure administration, vulnerability remediation, and configuration compliance.
• Good understanding of ITSM processes including incident, problem, change, configuration, and knowledge management.
• Takes ownership of operational issues through resolution.
• Proactive, practical, reliable, and detail-focused when managing production systems and endpoints.
• Security-aware and disciplined when handling privileged access and production changes.
• Collaborative when working with IT teams, users, vendors, and service providers.
• Committed to continual improvement, automation, and keeping technical knowledge current.