SENIOR ENGINEER - Wintel Administration
Indexed description
Job Location
Abu Dhabi, UAE-M42 Healthcare facilities and data center environments, as required
Seniority Level
Senior - Subject Matter Expert (Tier 3 / L3)
Engagement Type
Full-time, on-site with on-call coverage
- Role Purpose
- Key Responsibilities
- Own the design, build, lifecycle management, and operational stability of the Windows Server estate (2016/2019/2022) supporting clinical and corporate workloads.
- Lead L3 incident response for Wintel, virtualization, and core Microsoft platform issues, including major incidents impacting clinical applications.
- Plan, schedule, and execute monthly OS patching cycles across production, DR, and non-production environments in alignment with the change advisory board (CAB) and clinical downtime windows.
- Perform root-cause analysis (RCA) for P1/P2 incidents, produce formal RCA documentation, and drive permanent corrective actions through the problem management process.
- Design and maintain virtualization platforms (VMware vSphere, Hyper-V, or Nutanix AHV), including cluster sizing, HA/DRS configuration, capacity planning, and host lifecycle management.
- Engineer and maintain Windows clustering (WSFC), file services (DFS, SMB, scale-out file servers), print services, and IIS/web hosting tiers.
- Oversee backup and recovery operations for Wintel workloads using Veeam, Commvault, or equivalent; validate recoverability through periodic restore drills and DR tests.
- Lead Windows Server hardening per CIS benchmarks, Microsoft Security Baseline, and ADHICS technical control requirements.
- Manage server capacity, performance tuning, and right-sizing for high-demand clinical workloads such as EMR database servers, imaging archives, and reporting services.
- Coordinate with application owners, OEM vendors, and Managed Service Provider (MSP) teams during deployments, upgrades, and major changes.
- Drive change management activities-author RFCs, present at CAB, execute approved changes within agreed maintenance windows, and produce post-implementation reviews.
- Maintain authoritative documentation: build sheets, runbooks, operational procedures, network/server topology, recovery procedures, and configuration baselines.
- Provide technical leadership during managed service transitions, including knowledge transfer, environment discovery, baseline verification, and cutover support.
- Support audit cycles (internal, external, ADHICS, DoH) by producing technical evidence, attending control walkthroughs, and remediating audit findings.
- Mentor L1/L2 Wintel engineers, review their technical output, and uplift the operational maturity of the team.
- Participate in 24x7 on-call rotation and respond to clinical-impacting incidents within agreed response SLAs.
- Technical Responsibilities
- Engineer and operate Windows Server 2016/2019/2022-installation, hardening, role configuration, lifecycle.
- Architect and operate VMware vSphere/ESXi clusters, Hyper-V, or Nutanix AHV environments.
- Manage SAN/NAS-attached storage on Windows hosts (iSCSI, FC, NFS, SMB3), MPIO, and storage spaces.
- Configure and troubleshoot Windows Server Failover Clustering (WSFC) for SQL AlwaysOn, file servers, and shared services.
- Implement and tune Windows performance-memory, CPU, paging, disk I/O, NUMA, and storage queue depth.
- Operate Microsoft WSUS / SCCM / Microsoft Endpoint Configuration Manager (MECM) / Intune for patch and configuration management.
- Perform PowerShell scripting and automation for build, configuration, reporting, and operational tasks.
- Manage backup and recovery using Veeam, Commvault, Rubrik, or equivalent enterprise-grade tools.
- Operate monitoring tooling (SCOM, SolarWinds, PRTG, Zabbix, Nagios, or Datadog) for proactive health management.
- Support hybrid integration with Azure (Azure Arc, Azure Backup, Azure Site Recovery, Update Manager, Azure AD/Entra Connect).
- Compliance and Governance Responsibilities
- Apply ADHICS v2 technical controls to all Windows builds, including hardening, logging, identity, and audit-trail requirements.
- Ensure all server logs are forwarded to the SIEM platform with the required retention and integrity controls.
- Maintain monthly patch compliance evidence aligned to DoH and ADHICS expectations and produce reports for cybersecurity governance forums.
- Maintain a complete and accurate Configuration Management Database (CMDB) entry for every Wintel asset, including ownership, classification, and criticality.
- Enforce least-privilege access to servers via tiered admin model and integrate with the Privileged Access Management (PAM) platform.
- Ensure backup, restore, and DR evidence is captured and retained for audit, including periodic restore test reports.
- Support vulnerability management cycles-review scan output, prioritize Wintel-related findings, remediate within agreed SLAs, and document closure evidence.
- Validate antivirus, EDR, file-integrity monitoring, and DLP agents on all Windows hosts; remediate non-compliant hosts.
- Ensure data classification, encryption (BitLocker, TLS), and protected-health-information (PHI) handling controls are applied to all hosts that touch clinical data.
- Provide audit evidence packs on demand for DoH inspections, internal audit, ISO 27001, and ADHICS reviews.
- Required Technical Skills
- Expert-level Windows Server 2016/2019/2022 administration
- Expert-level VMware vSphere/ESXi or Nutanix AHV
- Strong Hyper-V and failover clustering
- Active Directory integration, Group Policy, DNS, DHCP
- PowerShell scripting and automation
- Veeam / Commvault / Rubrik backup
- WSUS / SCCM / MECM patch management
- Performance tuning and capacity management
- SAN/NAS storage integration (iSCSI, FC, NFS, SMB3)
- Azure IaaS, Azure Arc, ASR, and hybrid identity
- Monitoring tools - OpsManager, SolarWinds, PRTG
- ITSM platforms-ServiceNow, BMC Remedy, or equivalent
- Required Experience
- Minimum 8 years of progressive experience in Windows Server engineering and virtualization.
- Minimum 3 years of L3-level operational experience in a complex, multi-site environment.
- Demonstrable experience supporting healthcare, banking, oil and gas, government, or other regulated, mission-critical environments.
- Hands-on experience with managed service models, vendor coordination, and 24x7 critical operations.
- Prior involvement in service transitions, take-over of brownfield environments, or large infrastructure migrations is strongly preferred.
- Required Certifications
- Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800/AZ-801) or MCSE: Core Infrastructure
- VMware VCP-DCV (if VMware-based environment) or Nutanix NCP-MCI (if Nutanix-based)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- ITIL 4 Foundation
- ISO 27001 Lead Implementer or ADHICS Implementer training
- Veeam Certified Engineer (VMCE) or equivalent backup certification
- Education Requirements
- Bachelor's degree in Computer Science, Information Technology, Computer Engineering, or related discipline.
- Equivalent combination of recognized diploma and significant relevant industry experience may be considered.
- Soft Skills and Behavioural Competencies
- Strong ownership and accountability for production stability
- Disciplined documentation and configuration hygiene
- Calm, structured incident handling under pressure
- Clear written and verbal communication with technical and non-technical stakeholders
- Stakeholder management with clinical and business teams
- Mentorship and knowledge-sharing mindset
- Compliance and audit awareness
- Readiness for rotational shifts, weekend changes, and on-call duty
- Customer-service orientation suited to a healthcare environment
- Key Interfaces
- Infrastructure Team (peers, junior engineers)
- Cloud Team-Azure / hybrid integration
- Database Team-SQL Server and Oracle DBAs
- Cybersecurity and Network Security Teams
- Service Desk / NOC / SOC
- Application and Clinical Systems Teams (EMR, PACS, LIS, RIS)
- Hospital Operations and Clinical Engineering
- OEM and platform vendors (Microsoft, Dell, HPE, VMware, Nutanix)
- Internal Audit, Risk, and Compliance teams
- Managed Service Provider (MSP) leadership during transition and steady-state
- Success Measures and KPIs
- Windows server platform availability = 99.9% for clinical-tier workloads
- Monthly patch compliance = 98% within agreed maintenance windows
- P1 incident response within 15 minutes; P1 resolution within agreed SLA
- Backup success rate = 99% with quarterly restore validation evidence
- Zero critical/high vulnerabilities open beyond agreed SLA
- 100% of major changes executed without rollback within the maintenance window
- RCA delivery within 5 business days for all P1 incidents
- Documentation completeness score = 95% (runbooks, build sheets, RCA library)
- Audit findings related to Wintel domain-zero repeat findings
- Tools and Technologies
VMware vSphere / ESXi
Hyper-V
Nutanix AHV
Active Directory, DNS, DHCP, GPO
PowerShell
WSUS / SCCM / MECM / Intune
Cohesity / Veeam / Commvault / Rubrik
Azure (IaaS, ASR, Arc, Backup)
SCOM / SolarWinds / PRTG / OpsManager
ServiceNow / Remedy / Manage Engine
SIEM (Splunk / Sentinel / QRadar)
PAM (CyberArk / Delinea / ManageEngine)
EDR (CrowdStrike / Defender for Endpoint / SentinelOne) Windows Server (2019), Windows, Virtualization Platform Administration
- Working Conditions
- On-site presence at M42 Healthcare facilities and primary/DR data centers in Abu Dhabi.
- Standard business hours with mandatory participation in 24x7 on-call rotation.
- Weekend and overnight maintenance windows for patching, upgrades, and DR tests.
- Emergency response for P1 incidents impacting clinical services.
- Adherence to hospital infection-control, hygiene, and access protocols when working in clinical zones.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search