Cloud Server Engineer (Vancouver)

Cloud Server Engineer (Vancouver)

13 Sep
|
Affinity
|
Vancouver

13 Sep

Affinity

Vancouver

On behalf of our public sector client, Affinity is seeking a Cloud Server Engineer to support Technology Services in planning, executing, and operationalizing Windows Server engineering and Azure cloud infrastructure activities across on-premises, Azure IaaS, and hybrid environments. They will extend Microsoft Defender for Endpoint coverage across the server and endpoint estate in support of Technology Services modernization, resiliency, operational readiness, and cybersecurity.

Responsibilities

- Assess the current Windows Server estate, including operating system versions, workloads, roles/features, installed agents, dependencies, application owners, support models, and cloud and security onboarding readiness.
- Build, configure, harden, test, and validate Windows Server environments on-premises and in Azure IaaS in accordance with E-Comm standards, cybersecurity requirements, availability needs, and operational practices.
- Support Azure IaaS activities including Azure readiness, VM sizing, evaluation of Azure services, landing zone dependencies, hybrid connectivity, identity integration, monitoring, backup, and operational handoff.
- Deploy and configure Azure Arc-enabled servers at scale, including onboarding scripts and service principals, resource group and tagging conventions, agent health monitoring, Azure Policy and governance, and the Microsoft Defender for Servers integration path.
- Build and maintain SCCM/MECM collections, device groups, deployment packages, configuration items, and compliance baselines used for patching, agent distribution, and onboarding verification.
- Plan and execute onboarding of servers and endpoints to Microsoft Defender for Endpoint, including prerequisite validation (updates and servicing levels, Defender platform and engine versions, connectivity to required service endpoints, proxy and TLS configuration, licensing and tenant assignment), pilot, wave-based rollout, and post-deployment validation.
- Execute migration from third-party antivirus and endpoint protection products, including review and translation of existing exclusions, passive and active mode sequencing, uninstall or disablement procedures, and confirmation that protection is maintained throughout the transition.
- Configure and tune Microsoft Defender Antivirus, EDR, cloud-delivered protection, attack surface reduction rules, network protection, and tamper protection through Intune, Configuration Manager, or Group Policy as applicable.
- Triage and remediate onboarding failures, unhealthy or inactive sensors, misreported onboarding status, duplicate or stale device records, and servers requiring exception or alternative treatment.
- Implement or validate server hardening, vulnerability remediation, logging, monitoring, access control, local administrator controls, privileged access practices, and baseline configuration.
- Develop and maintain server inventories, onboarding trackers, wave plans, readiness reports, exception registers, technical risk registers, and reporting on onboarding coverage and sensor health.




- Support integration with Active Directory, Entra ID / Azure AD, DNS, DHCP, certificates, Intune and Configuration Manager, Microsoft Defender XDR, SIEM and log forwarding, monitoring tools, backup platforms, virtualization, storage, Azure services, ServiceNow, CMDB, and change management processes.
- Support resiliency and operational readiness for in-scope servers, including patching, backup/restore validation, recovery testing, and high availability considerations.
- Develop technical runbooks for server build and configuration, Arc and Defender onboarding and offboarding, exclusion request handling, agent and sensor troubleshooting, patching, monitoring, and operational support.
- Produce as-built documentation, configuration standards, implementation and rollout plans, validation evidence, rollback documentation, support procedures, and transition-to-operations materials.
- Coordinate with infrastructure, cybersecurity, application, cloud, identity, service desk, ServiceNow, vendor, and business teams to align deployment sequencing, change windows, testing, communications, and operational acceptance.
- Support change management, release readiness, hypercare, incident remediation, knowledge transfer, and sustainment following server and onboarding activities.

Education, Training and Experience
- Minimum of 10 years’ experience in Windows Server engineering, cloud infrastructure, or systems administration in complex, highly available environments.
- Degree in computer science, information systems, or a related field, or an equivalent combination of training and experience.
- Strong hands-on experience with Windows Server build, configuration, hardening, patching, and troubleshooting is required.
- Demonstrated hands-on Azure experience is required, including Azure IaaS and Azure Arc enabled servers; Azure certifications (for example AZ-800 or AZ-104) are robust assets.
- Demonstrated hands-on experience deploying and managing Microsoft Defender for Endpoint at enterprise scale is required, including onboarding, policy configuration, sensor health management, and troubleshooting of failed onboarding.
- Strong hands-on experience with Microsoft Configuration Manager (SCCM/MECM) for large scale deployment, collections, configuration baselines, and client health is required.
- Experience migrating from third-party antivirus and EDR products to Microsoft Defender, including exclusion migration and coexistence or passive mode handling, is a strong asset.
- Strong PowerShell scripting ability for at-scale deployment, validation, and reporting is required.
- Security certifications (for example SC-200, MD-102, or SC-100) are assets.
- Infrastructure as code (IaC)



experience is not required but is considered an asset.
- Experience working in highly available public safety environments is an asset.

Knowledge, Skills And Abilities

- Knowledge of Windows Server architecture, roles/features, lifecycle, patching, and hardening methods.
- Knowledge of Azure IaaS, VM sizing, hybrid connectivity, identity integration, and operational handoff.
- Knowledge of Azure Arc-enabled servers, at-scale agent deployment, governance, and Microsoft Defender for Servers plan and licensing considerations.
- Knowledge of Microsoft Defender for Endpoint architecture, onboarding methods, sensor health, device groups, and the Microsoft Defender XDR portal.
- Knowledge of Microsoft Configuration Manager (SCCM/MECM) collections, deployments, configuration baselines, and client health remediation.
- Knowledge of antivirus and EDR concepts, including exclusions, passive mode and coexistence, tamper protection, attack surface reduction, and detection tuning.
- Knowledge of server hardening, endpoint security baselines, vulnerability remediation, and baseline configuration.
- Knowledge of backup/restore validation, high availability, and disaster recovery considerations for server workloads.
- Proficiency with Active Directory, Entra ID, Group Policy, DNS, DHCP, certificates, proxy and network egress paths, monitoring tools, virtualization, storage, and PowerShell scripting.
- Knowledge of ITIL and ITSM related standards and practices, including CMDB and change management integration.
- Knowledge of MS Visio, Teams, PowerPoint, and SharePoint.
- Ability to respond to shifting priorities, demands, and timelines.
- Ability to investigate and resolve complex infrastructure, endpoint, agent, and connectivity issues across a large and varied estate.
- Ability to work effectively with multiple technical teams, vendors, and business stakeholders.
- Ability to communicate effectively orally and in writing and to prepare clear, concise, and complete documentation.
- Ability to maintain accurate records, decision logs, and technical documentation related to the work.

Affinity Earn Know someone who’s great for this, or any of our open roles? Earn up to $4,000/year for each successful referral through Affinity Earn. You can also earn up to $50,000 for helping us find new clients. Learn about our referral program at https://affinity-group.ca/earn/ or browse our jobs & follow us at https://www.linkedin.com/company/affinity-staffing/jobs/ About Affinity Affinity Group is a technology and business consulting and services company. We believe in creating long term relationships between clients and consultants that foster a mutually beneficial partnership. Affinity is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided on the basis of qualifications, merit and business need.

For more information on Affinity, please visit www.affinity-group.ca

Job Number: 13926

📌 Cloud Server Engineer (Vancouver)
🏢 Affinity
📍 Vancouver

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cloud server engineer (vancouver) / vancouver

Subscribe to this job alert:

Get the latest job offers by email for: cloud server engineer (vancouver) / vancouver