Lead Infrastructure Engineer (Microsoft Cloud & Cybersecurity)
Job Description
The Lead Infrastructure Engineer role focuses on Microsoft cloud platforms and cybersecurity, based in Denver with hybrid work arrangements, responsible for designing, implementing, securing, and supporting complex client environments and mentoring engineers.
Compensation
Salary: USD 110,000 - 125,000 per year
Responsibilities
- Lead the design, deployment, and ongoing support of Microsoft 365 configurations
- Plan and implement Microsoft Azure infrastructure and cloud services
- Configure and manage Microsoft Entra ID and Microsoft Intune
- Oversee Microsoft 365 tenant migrations and cloud modernization initiatives
- Configure and administer Fortinet security platforms
- Design and maintain network infrastructure including VLANs, routing, switching, VPNs, wireless, and security
- Deploy and support security products such as SentinelOne and Check Point Harmony Email & Collaboration
- Architect cloud backup and disaster recovery strategies
- Develop PowerShell scripts and automation to improve operational efficiency
- Lead infrastructure projects from planning through implementation
- Troubleshoot and resolve complex Tier III infrastructure issues
- Mentor engineers and help establish technical standards
- Improve documentation and engineering processes within Hudu
- Collaborate with business owners and executive leadership on strategic technology initiatives
Requirements
- 7+ years of professional IT experience
- 5+ years working for a Managed Services Provider
- Proven experience leading Microsoft 365 migrations
- Advanced administration of Microsoft Azure
- Advanced administration of Fortinet security platforms
- Strong networking design and troubleshooting capabilities
- Experience leading infrastructure projects
- Excellent written and verbal communication skills
- Strong documentation practices
- Valid driver's license and reliable transportation; ability to travel across the Denver metro area as needed
- Educational background: Bachelor's degree in Computer Science or a related field
- Proficiency with Microsoft 365 suite: Exchange Online, SharePoint Online, Teams, OneDrive
- Experience with Microsoft Entra ID and Microsoft Intune
- Experience with Microsoft Azure, including Virtual Machines
- Knowledge of Conditional Access and Multi-Factor Authentication
- Experience with Microsoft Defender and security architectures
- Experience with Microsoft 365 Tenant Migrations and cloud backups
- Fortinet Firewalls, FortiSwitch, FortiAP
- Networking skills: VLAN design, routing, switching, VPN configuration, DNS, DHCP, wireless
- Windows Server, Active Directory, Group Policy
- Hyper-V and/or VMware; storage and virtualization; server migrations
- Experience with SentinelOne and Check Point Harmony Email & Collaboration (Avanan); EDR
- Security hardening, incident response, vulnerability remediation
- Backup and DR solutions: Cove Data Protection, Datto BCDR, Axcient, Veeam
- Microsoft 365 backup solutions and disaster recovery planning/testing
- PowerShell, Microsoft Graph, scripting, and process automation
- Terraform, Ansible, Puppet, Chef
- Databases: MySQL, PostgreSQL, Oracle, Microsoft SQL Server
- RESTful APIs and Web Services
- VMware, OpenStack, Citrix, Rackspace
- Docker and Kubernetes; Linux and Windows; Bash, Python, Go, Ruby
- Jenkins and CI/CD
- Halo PSA and NinjaOne are preferred tools
Technologies
Key platforms and tools used in this role include Microsoft 365 and related services (Exchange Online, SharePoint Online, Teams, OneDrive), Entra ID, Intune, and Azure (including VMs). Fortinet security appliances (Firewalls, FortiSwitch, FortiAP) support network security, while security and backup solutions such as SentinelOne, Cove Data Protection, Datto BCDR, Axcient, and Veeam enable comprehensive protection and recovery. The role also involves scripting and automation with PowerShell and Microsoft Graph, with infrastructure-as-code through Terraform and related configuration management tools. Virtualization and containerization encompass VMware, OpenStack, Docker, and Kubernetes, with operating systems across Windows and Linux. Databases include MySQL, PostgreSQL, Oracle, and SQL Server, and integration touches RESTful APIs and Web Services. Related management and monitoring tools include Halo PSA, NinjaOne, Hudu, ConnectWise Control, ConnectWise Manage, Datto RMM, AutoTask, and N-able.
Benefits
- Health insurance
- 401(k) plan with matching
- Flexible schedule
- Paid time off and holidays
- Tuition reimbursement
- Monthly healthcare reimbursement
- Company-provided equipment
- Company-funded certifications and professional development
- Hybrid work environment
Location and Work Arrangement
Location: Denver, Colorado 80202, United States
Work location: Hybrid remote in the Denver metro area, allowing a mix of on-site and remote work as required
Experience
Minimum of 5 years of experience delivering MSP services is required.
License and Certification
CDL is required for this role.
Application Questions
- How many M365 tenant migrations have you personally led?
- How many Fortinet firewall or network deployments have you personally completed?
- How would you rate your Microsoft Azure administration experience? (Intermediate, Advanced, Expert)
- How many years have you administered Microsoft Intune?
- Which PSA and RMM platforms have you used?
- Describe the most technically complex infrastructure project you personally designed and implemented (short answer is fine)
- Describe a PowerShell script or automation you've written that improved operations or eliminated manual work (short answer)
- What is your current compensation and desired compensation?