Senior System Engineer
Indexed description
OBJECTIVE AND PURPOSE
The Tier 3 – Senior Systems Engineer is the final technical escalation point at SOS Technology Group — and the engineer responsible for making sure the same problem doesn’t come back twice. This role owns the issues Tier 1 and Tier 2 can’t close, and turns them into permanent fixes, better standards, and better documentation.
The role goes well beyond reactive work. The Senior Systems Engineer designs and delivers the infrastructure, cloud, and security projects that move our Partners forward, sets the technical standards our service team works to, mentors the engineers behind them, and works closely with the SysOps (Centralized Services) team to turn recurring fixes and new standards into proactive monitoring, patching, and maintenance. The Senior Systems Engineer also participates in technology roadmapping and Quarterly Business Reviews as a trusted advisor.
FUNCTIONS
• Serve as the final internal escalation point for complex incidents across server, network, cloud, identity, and security infrastructure
• Perform root cause analysis on recurring and major incidents, and implement systemic fixes that reduce future ticket volume
• Develop, maintain, and execute Incident Response Plans (IRPs) for Partner environments; lead containment, eradication, and recovery during security incidents and coordinate with the SOS security stack and MDR provider
• Design, scope, and lead infrastructure, cloud migration, and security projects from planning through post-implementation validation
• Architect solutions that are secure, scalable, standardized, and documented — not one-off
• Own SOS technical standards, build documentation, runbooks, SOPs, and network and architecture diagrams within IT Glue
• Audit undocumented or inherited Partner environments and deliver prioritized remediation recommendations
• Lead complex and high-risk change management, including maintenance windows and rollback planning
• Mentor, coach, and provide technical direction to Tier 1 and Tier 2 engineers; conduct technical training and knowledge transfer
• Manage vendor and manufacturer escalations on behalf of SOS and our Partners
• Partner closely with the SysOps / Centralized Services team — feeding root-cause fixes, standards, and automation into their patching, monitoring, and proactive-maintenance workflows, and supporting after-hours escalations they cannot resolve
• Participate in Quarterly Business Reviews, technology roadmap development, and project scoping alongside Partner Success Managers
• Identify automation opportunities and build scripted, repeatable solutions in place of manual work
• Contribute to onboarding of new Partners, including environment assessment, standardization, and stack deployment
• Additional duties as assigned by Management
TYPICAL WORK EXPECTATIONS
• Designing, deploying, and troubleshooting Nutanix (AHV / Prism), VMware vSphere, and Hyper-V virtualization environments, including host, storage, and cluster-level issues — most colocation / data-center workloads now run on Nutanix
• Architecting and administering Microsoft 365 and Entra ID environments — Conditional Access, MFA, hybrid identity, Exchange Online, SharePoint, Teams, and Purview and Defender policy
• Planning and executing Azure and Microsoft 365 migrations, including tenant-to-tenant and on-premises-to-cloud,
• Windows Server 2019/2022/2025 design and administration — Active Directory, DNS, DHCP, Group Policy, File Services, Certificate Services, and RDS
• Firewall, VLAN, routing, VPN, and wireless design and troubleshooting — SonicWall firewalls and access points, UniFi, and multi-vendor managed switches
• Backup, replication, and disaster recovery architecture, testing, and restoration — Datto BCDR for on-premise server backup and Veeam for data-center replication — including documented, tested recovery procedures
• Endpoint and mobile device management (MDM) and standardization through Microsoft Intune, Datto RMM, and ImmyBot — enrollment, compliance, configuration, and app-deployment policies across Windows, macOS, iOS, and Android
• Security stack deployment and tuning — Huntress MDR, Microsoft Defender, email security, Dark Web/Bullphish ID, and Cyrisma — responding to identified threats and executing Incident Response Plans (IRPs)
• Administering our Privileged Access Management (PAM) solution, CyberQP — securing, rotating, and auditing local admin and privileged credentials, and enforcing just-in-time / least-privilege access for the engineering team
• PowerShell scripting and automation to eliminate manual, repetitive work
• Supporting business-critical and clinical line-of-business applications, including Citrix-published EHR/EMR environments
• Executing server, network, and platform migrations, installations, and upgrades on schedule and within scope
REQUIREMENTS
• Sound technical judgment under pressure, with the discipline to find the actual cause rather than the fastest workaround
• Outstanding organizational and time management skills, with the ability to balance escalations against project commitments
• Excellent written and verbal communication skills, including the ability to explain technical risk and tradeoffs to non-technical business owners
• Confidence presenting solutions and recommendations to Partners and SOS staff by phone, chat, email, or in person
• Willingness to teach — a genuine interest in raising the capability of the engineers around you
• Strong documentation habits; work isn’t finished until it’s written down
• Dedicated to team building and camaraderie, and committed to seeing assigned work through to completion
• Alignment with the SOS core values: Invent Beyond Boundaries, Confidence with Humility, Guardians of Reputation, Built for the Long Haul, and Partners in Progress
EXPECTATIONS
• This is an on-site, office-based position at our Baltimore location
• Regular travel to Partner sites throughout the Baltimore metro area; occasional travel outside the local area with overnight accommodations
• Participation in an after-hours on-call escalation rotation. This is currently anticipated to cover a weekday evening window (approximately 5:00–8:00 PM), with each engineer taking a turn on a periodic basis (roughly one rotation every few weeks). The exact structure is still being finalized and may change.
• Willingness to work extended weekday and weekend hours as needed, including scheduled maintenance windows outside of business hours
• Participation in the SOS operating rhythm, including Level 10 meetings, quarterly Rocks, and Scorecard accountability
QUALIFICATIONS
Required
• 5+ years of progressive systems engineering experience, with time spent at a managed service provider strongly preferred
• Deep working knowledge of Windows Server 2019/2022/2025 and Windows 11 in production business environments
• Advanced Microsoft 365 and Entra ID administration, including Conditional Access, MFA, and hybrid identity
• Hands-on virtualization experience with Nutanix (AHV / Prism), VMware vSphere, and Hyper-V, including storage and cluster troubleshooting
• Advanced (high-level) networking knowledge is required — TCP/IP, DNS, DHCP, VLANs, inter-VLAN routing, VPN (site-to-site and SSL), Wi-Fi, and LAN/WAN — with the ability to design and diagnose issues across firewalls, managed switches, and wireless
• SonicWall firewall and wireless access point configuration and troubleshooting is required, along with hands-on experience configuring and troubleshooting managed switches (UniFi and other vendors) (experience with Fortinet, Meraki, or Sophos firewalls is a plus)
• Mobile Device Management (MDM) is required — hands-on administration of Microsoft Intune for device enrollment, compliance, configuration profiles, and application deployment
• Backup and disaster recovery design, testing, and restoration experience
• PowerShell scripting for administration and automation
• Working understanding of endpoint security, EDR/MDR, and zero-trust and MFA architecture
• Experience with a Privileged Access Management (PAM) solution — privileged credential vaulting, rotation, and just-in-time / least-privilege access control
Preferred
• Azure IaaS, hybrid cloud, and Azure Virtual Desktop experience
• Microsoft Entra Privileged Identity Management (PIM) experience — a plus; SOS plans to roll out PIM in the coming year
• Experience with the Kaseya suite and its additional modules — Autotask PSA, Datto RMM, IT Glue
• Practical familiarity with HIPAA Security Rule technical safeguards — access control, audit controls, integrity, authentication, and transmission security
• Familiarity with the FTC Safeguards Rule, IRS Publication 4557, and WISP requirements as they apply to accounting and financial services clients
• Working knowledge of the CIS Controls or NIST Cybersecurity Framework, and experience mapping a delivered security stack to them
• Experience supporting multi-location medical practices, Citrix-published clinical applications, and EHR/EMR platforms
• Experience coordinating with VoIP vendors and provisioning dedicated network access for voice services (SOS does limited hands-on VoIP work); 8x8 knowledge a plus
Certifications (Preferred, Not Required)
• Microsoft: AZ-104 (Azure Administrator), MS-102 (Microsoft 365 Administrator), MD-102 (Endpoint Administrator / Intune), Windows Server Hybrid Administrator (AZ-800/AZ-801 or successor AZ-802)
• CompTIA: Network+, Security+, or Server+
• Nutanix NCP (Certified Professional) and/or VMware VCP; Cisco CCNA a plus
• ITIL 4 Foundation
• SonicWall (SNSA), Datto, or other Kaseya product certifications
SOS supports and reimburses continued certification for our engineering team.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search