Sr Systems Engineer
Job Summary
- Deploys maintains upgrades and resolves issues with Active Directory Entra ID and Identity and Access Management Systems for HR System integration to include support for joiner mover & termination processes as well as role-based access and other automated processes.
- Supports Identity Management for 3rd party applications Azure Enterprise Applications to include securing access using conditional access and MFA (Multi Factor Authentication) systems.
- Designs and supports authentication methodologies including Radius LDAPS SAML Kerberos PAM (Privileged Access Management) and certificate-based authentication.
- Designs installs and maintains the enterprise certificate environment.
- Works with Information Security to implement proper controls and security measures to protect local and cloud-based data.
- Configures and supports Microsoft SaaS systems such as Exchange SharePoint and Teams.
- Architects the migration of on-premises files and data to SharePoint Online and OneDrive. Supports and secures data in SharePoint and OneDrive.
- Implements DLP (Data Loss Prevention) sensitivity and retention labeling to maintain integrity and security of data with guidance from Information Security.
- Serves as the senior administrator for one or more Microsoft 365 tenants with direct responsibility for tenant configuration security posture licensing management and service health across the M365 suite including Exchange Online SharePoint Online Teams OneDrive for Business and Intune.
- Manages M365 identity and access governance including role-based access control (RBAC) privileged identity management (PIM) guest/external access policies and cross-tenant collaboration settings.
- Oversees Exchange Online administration including mail flow rules connectors anti-spam/anti-phishing policies shared mailboxes distribution groups and hybrid mail routing where applicable.
- Administers Microsoft Teams governance including team lifecycle policies meeting configurations and compliance recording where required.
- Monitors tenant health service incidents and adoption metrics through the M365 Admin Center and Defender portals driving proactive resolution of issues and escalating with Microsoft Support as warranted.
- Supports System Administrators with Endpoint Management and Security solutions for Windows workstation and servers Android and iOS devices.
- Assists System Engineers in the design and implementation of systems to manage security at the server operating system level including hardening and patches.
- Responsible for Azure AWS and GCP Public Cloud platforms including identity security policy management and cost allocation.
- Designs implements and manages other cloud SaaS Systems to reduce enterprise costs & complexity while increasing reliability.
- Owns and administers the on-premises Active Directory environment including domain and forest architecture domain controller deployment and health AD sites and services replication topology and Group Policy infrastructure.
- Designs and maintains Group Policy Objects (GPOs) for security baselines software deployment user environment management and compliance enforcement across workstations and servers.
- Manages AD trust relationships organizational unit (OU) structure delegation of control and role-based administrative access in alignment with least-privilege principles.
- Administers and maintains Microsoft Entra ID (Azure AD) Connect overseeing hybrid identity synchronization password hash sync or pass-through authentication and seamless SSO configurations between on-premises AD and M365.
- Leads identity lifecycle management processes including provisioning de-provisioning access reviews and privileged account governance spanning both on-premises AD and Entra ID.
- Monitors AD health and security through tools such as Microsoft Defender for Identity ensuring detection and response to suspicious authentication activity lateral movement or privilege escalation attempts.
- Maintains AD disaster recovery capabilities including authoritative and non-authoritative restore procedures domain controller backup validation and documented recovery runbooks.
- Serves as the primary subject matter expert and administrator for a hybrid virtualized environment spanning both VMware vSphere/ESXi and Microsoft Hyper-V platforms ensuring high availability performance and security across all hypervisor hosts and guest workloads.
- Designs deploys and maintains VMware vSphere clusters including vCenter Server ESXi hosts vMotion High Availability (HA) Distributed Resource Scheduler (DRS) and Fault Tolerance configurations.
- Administers Microsoft Hyper-V environments including failover clustering Live Migration Hyper-V Replica and integration with System Center Virtual Machine Manager (SCVMM) where applicable.
- Leads capacity planning efforts across both platforms analyzing resource utilization trends and making recommendations for infrastructure scaling consolidation or refresh.
- Develops and enforces standards policies and procedures for VM provisioning template management snapshot governance and lifecycle management across VMware and Hyper-V environments.
- Architects deploys and administers VMware vSAN clusters including disk group configuration storage policies deduplication and compression settings fault domain design and health monitoring.
- Manages and maintains Fibre Channel SAN infrastructure end-to-end including zoning LUN provisioning and masking HBA configuration and fabric switch administration (Brocade/Cisco MDS).
- Oversees SAN connectivity for both VMware and Hyper-V hosts ensuring proper multipathing (VMware NMP/PSP policies and Windows MPIO) path redundancy and failover validation.
- Monitors SAN and vSAN performance diagnoses and resolves storage latency throughput and connectivity issues and coordinates with vendors on hardware support and firmware management.
- Maintains storage architecture documentation including SAN fabric topology zoning configurations LUN mappings and vSAN cluster layouts.
- Configures and manages virtual networking components within both VMware (vSphere Standard and Distributed Switches port groups uplink teaming policies) and Hyper-V (Virtual Switches NIC teaming SR-IOV) environments.
- Collaborates with network engineering teams on the integration of virtual infrastructure with physical switching routing and Fibre Channel fabric to ensure end-to-end connectivity and redundancy.
- Installs and troubleshoots TCP/IP support infrastructure including DHCP DNS (Domain Name System) and other IP-based technologies.
- Collaborates with operation staff to ensure smooth and reliable operation of software and systems for fulfilling business objectives and processes; works with executive team members decision makers and stakeholders to define business requirements and systems goals and to identify and resolve business systems issues.
- Builds and maintains complex real time monitoring systems to monitor critical business applications alert key personnel in the event of failure and perform trending and capacity analysis.
- Participates in Business Continuity and Disaster Recovery design implementation and testing.
- Creates and maintains documentation as it relates to system configuration mapping processes and service records.
- Maintains technical adherence to external compliance mandates and assists in the development of policies and procedures.
- Drives infrastructure automation and operational efficiency through scripting (PowerCLI PowerShell) and integration with infrastructure-as-code or orchestration toolsets.
- Mentors junior systems staff on virtualization best practices storage fundamentals and operational procedures.
- Knowledge of the practical application of engineering science and technology including applying principles techniques procedures and equipment to the design and production of technologies.
- Knowledge of applicable data privacy and security practices and laws.
- Ability to follow existing practices and develop new best practices and prescribed development methodologies in the performance of the above duties.
- Ability to conduct research into systems issues and products as required.
- Ability to communicate ideas in technical business-friendly and user-friendly language appropriate to both executive and managerial audiences.
- Strong customer service orientation.
- Ability to prioritize and execute tasks in a high-pressure team-oriented collaborative environment and to meet deadlines and multi-task while maintaining quality standards.
- High level of professionalism and interpersonal skills. Excellent critical thinking analytical and problem-solving skills.
- Ability to communicate in an articulate professional manner and to build and sustain successful professional relationships.
- General knowledge of network switches firewalls and routers.
- Excels in scripting languages such as PowerShell PowerCLI Java or .
- Minimum of 7 years of experience including systems administration administering Windows-based systems and AD RDP (Remote Desktop Protocol) Security and User Management Disaster Recovery and Documentation and experience in software configuration management and advanced troubleshooting required.
- Demonstrated hands-on experience administering VMware vSphere/ESXi and Microsoft Hyper-V environments in a production setting required..
- Experience managing Fibre Channel SAN infrastructure including zoning LUN management and HBA configuration required.
- Experience with VMware vSAN architecture configuration and administration required.
- On-call (continuously or rotationally) to provide support required.
- Bachelors degree in Computer Science Information Technology related field or equivalent preferred.
- Knowledge and experience with Identity and Access Management Systems preferred.
- Tenant Global Administrator for M365 experience preferred.
- VMware Certified Professional (VCP) or Microsoft Certified: Azure Administrator / Hybrid Administrator credentials preferred.
- Other Duties: This job description incorporates the essential functions and duties required for this position. However other duties may be required and assigned at times and as determined by a supervisor in order to meet the needs of the organization.
- Serves as a role model in carrying out activities and behaviors that reflect the values and principles of the Boys Town mission.
- Position is relatively sedentary in a normal office administrative environment involving minimum exposure to physical risks. Will use office equipment such as a computer/laptop monitor keyboard and a general workstation set-up.
Care and respect for others is more than a commitment at Boys Town it is the foundation of who we are and what we do.
At Boys Town we cultivate a culture of belonging for all employees that respects their individual strengths views and experiences. We believe that our differences enable us to be a better team one that makes better decisions drives innovation and delivers better business results.
About Boys Town:
Boys Town has been changing the way America cares for children and families since 1917. With over a century of service our employees have helped us grow from a small boardinghouse in downtown Omaha Nebraska into one of the largest national child and family care organizations in the country. With the addition of Boys Town National Research Hospital in 1977 our services branched out into the health care and research fields offering even more career opportunities to those looking to make a real difference.
Our employees are our #1 supporters when it comes to achieving Boys Towns mission which is why we are proud of their commitment to making the world a better place for children families patients and communities. A unique feature for employees and their dependents enrolled in medical benefits are reduced to no cost visits for services performed by a Boys Town provider at a Boys Town location. Additional costs savings for the employee and their dependents are found in our pharmacy benefits with low to zero-dollar co-pays on certain maintenance drugs. Boys Town takes your mental health seriously with no cost mental health visits to an in-network provider. We help our employees prepare for retirement with a generous match on their 401K or 401K Roth account. Additional benefits include tuition reimbursement parenting resources from our experts and professional development opportunities within the organization just to name a few. Working at Boys Town is more than just a job it is a way of life.
This advertisement describes the general nature of work to be performed and does not include an exhaustive list of all duties skills or abilities required. Boys Town is an equal employment opportunity employer and participates in the E-Verify program. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity and/or expression national origin age disability or veteran status. To request a disability-related accommodation in the application process contact us at 1-.
Required Experience:
Senior IC
About Company
Boys Town Hospital, a non-profit medical center, provides clinical and hospital care and is a leader in research, education and pediatric care.