Senior Systems Engineer at Washington Commanders
Job Description
Overview
The Washington Commanders are seeking a Senior Systems Engineer to own the compute, cloud, and identity platform that every other technology lane builds on, across headquarters, the practice facility, and the stadium. This is the functional owner of systems and a keystone hire for the technology organization.
You will set the standards for servers and cloud, identity and access, backup and recovery, patching and hardening, and change control, and you will keep the platform secure, reliable, and ready for game day. This is a hands-on senior role that sets architecture and standards.
We are looking for a strong technical owner who is deliberate about standards, documents the work, and collaborates well across teams. The role will report to the Director of Technology Operations.
Key Responsibilities
● Design, operate, and maintain physical and virtual servers, storage, and the Microsoft 365 and Azure cloud environment.
● Administer core cloud services including Exchange Online, Teams, and SharePoint, with secure access and governance.
● Optimize, operate, and maintain our vSphere environment.
● Set server and cloud architecture standards and reference designs, and approve platform changes.
● Own directory and identity architecture and administration standards on Microsoft Entra ID.
● Implement single sign-on, multi-factor authentication, conditional access, and least-privilege access across business systems.
● Build and maintain automated user lifecycle processes for onboarding, offboarding, role changes, and access reviews.
● Administer Active Directory, including domain controllers, organizational units, DNS and DHCP integration, and directory hygiene, and maintain hybrid identity synchronization between Active Directory and Microsoft Entra ID.
● Design and maintain Group Policy for servers and endpoints.
● Manage the enterprise public key infrastructure and full certificate lifecycle, including issuance, renewal, revocation, and automated deployment of device, user, and TLS certificates.
● Own the certificate services and authentication backend that support 802.1x network access control and certificate-based device authentication, in partnership with the Network and IT Security lanes.
● Manage privileged and service accounts, enforcing least-privilege and strong authentication on all administrative access.
● Run backup, disaster recovery, and business-continuity testing, and maintain recovery standards.
● Validate recovery on a defined schedule so the club can restore quickly when it matters.
● Own patching standards, system hardening, and configuration baselines for servers and endpoints.
● Own the enterprise device management platform for Windows and macOS, including enrollment, configuration profiles, compliance policies, and disk encryption standards.
● Build and maintain standardized OS images and zero-touch provisioning so devices deploy consistently across all three sites.
● Own software packaging, application deployment, and update standards across the device fleet.
● Own platform-level data hygiene: directory and identity cleanup, storage and file-share management, and data retention and lifecycle enforcement.
● Enforce data classification, retention, and access-governance standards set by IT Security and Enterprise Applications, escalating gaps to the Director.
● Manage change control for platform changes and monitor systems health across all three sites.
● Automate administration and provisioning with scripting such as PowerShell.
● Create and maintain architecture diagrams, standard operating procedures, runbooks, and reference designs.
● Partner with IT Security on hardening, access governance, and compliance, and with Network on connectivity and identity during incidents.
● Serve as a senior escalation point for IT Operations on complex systems issues, and provide technical leadership on infrastructure projects, cloud migrations, and new-facility builds.
● Support events and game days where systems or identity are involved.
Qualifications
Required
● Eight or more years in systems administration, cloud infrastructure, or enterprise IT operations.
● Hands-on experience administering Microsoft 365 and Azure, including Exchange Online, Teams, and SharePoint.
● Strong identity and access management experience: directory services, single sign-on, multi-factor authentication, conditional access, and automated lifecycle provisioning, on Microsoft Entra ID or an equivalent platform.
● Experience owning backup, disaster recovery, and business-continuity testing.
● Experience with patching, hardening, configuration baselines, and change control for Windows and macOS environments.
● Scripting and automation experience such as PowerShell.
...