Windows System Engineer
Job Summary
Syffer is an all-inclusive consulting company focused on talent tech and innovation. We exist to elevate companies and humans all around the world making change from the inside to the outside.
We believe that technology human kindness positively impacts every community around the world. Our approach is simple we see a world without borders and believe in equal opportunities. We are guided by our core principles of spreading positivity good energy and promote equality and care for others.
Our hiring process is unique! People are selected by their value education talent and personality. We dont present ethnicity religion national origin age gender sexual orientation or identity.
Its time to burst the bubble and we will do it together!
What Youll do:
-Administer multi-domain Active Directory environments including domain controllers GPOs cross-domain trusts LAPS security groups and JOINER/LEAVER workflows;
-Manage privileged access through CyberArk and Password Manager Plus;
-Maintain vaults onboard privileged accounts for Windows and Linux servers and connect privileged access workflows with authentication systems;
-Administer Windows Certificate Authority and PKI services;
-Manage the full SSL/TLS certificate lifecycle including certificate automation and renewal;
-Harden Windows Servers using CIS Benchmarks PingCastle ANSSI guidance NIST frameworks Microsoft recommendations and Group Policy enforcement;
-Secure remote access through RDP hardening Network Level Authentication Just-In-Time administration and VPN integration;
-Plan and execute Windows Server patching and software deployment with WSUS SCCM Patch Manager Plus and Ivanti;
-Write PowerShell scripts and deployment workflows for automated patching compliance reporting software distribution and emergency fixes;
-Support Citrix session-based and VDI environments including application publishing and troubleshooting;
-Maintain disaster recovery and business continuity procedures for production and DR environments;
-Participate in failover tests and backup validation;
-Monitor server performance capacity and operational health through tools such as LogicMonitor WhatsUP Gold PagerDuty Coralogix and Azure Log Analytics;
-Maintain accurate technical documentation and work with Network Security DevOps and IAM teams;
-Participate in incident response change management CAB processes and operational improvement activities;
- Predominantly on-site.
Who You Are:
-5 years of hands-on Windows Server administration experience;
-Strong experience with Windows Server 2019 and 2022 domain controllers clustering and enterprise infrastructure;
-Advanced Active Directory experience in multi-domain environments;
-Practical knowledge of GPOs LAPS security groups trusts and identity lifecycle workflows;
-Hands-on experience with CyberArk PAM Password Manager Plus privileged account onboarding and vault administration;
-Intermediate to advanced PowerShell scripting skills;
-Experience with Ansible Terraform and infrastructure-as-code practices for cross-platform automation;
-Strong understanding of Windows security hardening audit logging vulnerability management and compliance frameworks;
-Experience with RDP NLA Just-In-Time access VPNs TCP/IP DNS and Active Directory site topology;
-Experience with WSUS SCCM Patch Manager Plus Ivanti and automated software deployment;
-Experience with incident response technical documentation CAB procedures and change management;
-Ability to work with distributed teams across several countries and time zones;
- Fluency in English and Portuguese.
What youll get:
- Wage according to candidates professional experience;
- Remote Work whenever possible;
- Delivery of work equipment adjusted to the performance of functions;
- Benefits plan;
- And others.
Work together with expert teams on projects of large magnitude and intensity long term together with our clients all leaders in their industries.
Are you ready to step into a diverse and inclusive world with us
Together we will promote uniquess!