16 Sep
|
TEEMA
|
Vancouver
Assess the current Windows Server estate, including operating system versions, workloads, roles/features, installed agents, dependencies, application owners, support models, and cloudand security onboarding readiness.
Build, configure, harden, test, and validate Windows Server environments on-premises and in Azure IaaS in accordance with E-Comm standards, cybersecurity requirements, availability needs, and operational practices.
Support Azure IaaS activities including Azure readiness, VM sizing, evaluation of Azure services, landing zone dependencies, hybrid connectivity, identity integration, monitoring, backup, and operational handoff.
Deploy and configure Azure Arc-enabled servers at scale, including onboarding scripts and service principals, resource group and tagging conventions, agent health monitoring, Azure Policy and governance, and the Microsoft Defender for Servers integration path.
Build and maintain SCCM/MECM collections, device groups, deployment packages, configuration items, and compliance baselines used for patching, agent distribution, and onboarding verification.
Plan and execute onboarding of servers and endpoints to Microsoft Defender for Endpoint, including prerequisite validation (updates and servicing levels, Defender platform and engine versions, connectivity to required service endpoints, proxy and TLS configuration, licensing and tenant assignment), pilot, wave-based rollout, and post-deployment validation.
Execute migration from third-party antivirus and endpoint protection products, including review and translation of existing exclusions, passive and active mode sequencing, uninstall or disablement procedures, and confirmation that protection is maintained throughout the transition.
Configure and tune Microsoft Defender Antivirus, EDR, cloud-delivered protection, attack surface reduction rules, network protection, and tamper protection through Intune, Configuration Manager, or Group Policy as applicable.
Triage and remediate onboarding failures, unhealthy or inactive sensors, misreported onboarding status, duplicate or stale device records, and servers requiring exception or alternative treatment.
Implement or validate server hardening, vulnerability remediation, logging, monitoring, access control, local administrator controls, privileged access practices, and baseline configuration.
Develop and maintain server inventories, onboarding trackers, wave plans, readiness reports, exception registers, technical risk registers, and reporting on onboarding coverage and sensor health.
Support integration with Active Directory, Entra ID / Azure AD, DNS, DHCP, certificates, Intune and Configuration Manager, Microsoft Defender XDR,
SIEM and log forwarding, monitoring tools, backup platforms, virtualization, storage, Azure services, Service
Now, CMDB, and change management processes.
Support resiliency and operational readiness for in-scope servers, including patching, backup/restore validation, recovery testing, and high availability considerations.
Develop technical runbooks for server build and configuration, Arc and Defender onboarding and offboarding, exclusion request handling, agent and sensor troubleshooting, patching, monitoring, and operational support.
Produce as-built documentation, configuration standards, implementation and rollout plans, validation evidence, rollback documentation, support procedures, and transition-to-operations materials.
Coordinate with infrastructure, cybersecurity, application, cloud, identity, service desk, Service
Now, vendor, and business teams to align deployment sequencing, change windows, testing, communications, and operational acceptance.
Support change management, release readiness, hypercare, incident remediation, knowledge transfer, and sustainment following server and onboarding activities.
What you must have: Minimum of 10 years experience in Windows Server engineering, cloud infrastructure, or systems administration in complex, highly available environments.
Degree in computer science, information systems, or a related field, or an equivalent combination of training and experience.
Strong hands-on experience with Windows Server build, configuration, hardening, patching, and troubleshooting is required.
Demonstrated hands-on Azure experience is required, including Azure IaaS and Azure Arcenabled servers; Azure certifications (for example AZ-800 or AZ-104) are strong assets.
Demonstrated hands-on experience deploying and managing Microsoft Defender for Endpoint at enterprise scale is required, including onboarding, policy configuration, sensor health management, and troubleshooting of failed onboarding.
Robust hands-on experience with Microsoft Configuration Manager (SCCM/MECM) for largescale deployment, collections, configuration baselines, and client health is required.
Experience migrating from third-party antivirus and EDR products to Microsoft Defender, including exclusion migration and coexistence or passive mode handling,
is a robust asset.
Strong Power
Shell scripting ability for at-scale deployment, validation, and reporting is required.
Security certifications (for example SC-200, MD-102, or SC-100) are assets.
Infrastructure as code (IaC) experience is not required but is considered an asset.
Experience working in highly available public safety environments is an asset.
Knowledge, Skills and Abilities Knowledge of Windows Server architecture, roles/features, lifecycle, patching, and hardening methods.
Knowledge of Azure IaaS, VM sizing, hybrid connectivity, identity integration, and operational handoff.
Knowledge of Azure Arc-enabled servers, at-scale agent deployment, governance, and Microsoft Defender for Servers plan and licensing considerations.
Knowledge of Microsoft Defender for Endpoint architecture, onboarding methods, sensor health, device groups, and the Microsoft Defender XDR portal.
Knowledge of Microsoft Configuration Manager (SCCM/MECM) collections, deployments, configuration baselines, and client health remediation.
Knowledge of antivirus and EDR concepts, including exclusions, passive mode and coexistence, tamper protection, attack surface reduction, and detection tuning.
Knowledge of server hardening, endpoint security baselines, vulnerability remediation, and baseline configuration.
Knowledge of backup/restore validation, high availability, and disaster recovery considerations for server workloads.
Proficiency with Active Directory, Entra ID, Group Policy, DNS, DHCP, certificates, proxy and network egress paths, monitoring tools, virtualization, storage, and Power
Shell scripting.
Knowledge of ITIL and ITSM related standards and practices, including CMDB and change management integration.
Knowledge of MS Visio, Teams, Power
Point, and Share
Point.
Ability to respond to shifting priorities, demands, and timelines.
Ability to investigate and resolve complex infrastructure, endpoint, agent, and connectivity issues across a large and varied estate.
Ability to work effectively with multiple technical teams, vendors, and business stakeholders.
Ability to communicate effectively orally and in writing and to prepare clear, concise, and complete documentation.
Ability to maintain accurate records, decision logs, and technical documentation related to the work.
Salary/Rate: $70.00/ hour Thank you for your interest in this opportunity.
If you are selected to move forward in the process, we will contact you directly.
If you do not hear from us, we encourage you to continue visiting our website for other roles that may be a good fit.
📌 Cloud Server Engineer (Vancouver)
🏢 TEEMA
📍 Vancouver