
Cloud Infrastructure Engineer, Windows
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in India.
• Lead the resolution of intricate Windows Server incidents across multi-client environments hosted on AWS, from initial triage to root cause analysis and remediation.
• Administer and reinforce Windows Server environments for versions 2019, 2022, and 2025.
• Oversee the design of Active Directory forests/domains, including replication, FSMO roles, Group Policy, trusts, DNS, DHCP, IIS, WSUS, AD CS, and file and print services.
• Manage hybrid identity solutions involving on-premises AD, AWS Managed Microsoft AD, Entra ID/Azure AD, AD FS, SAML, OIDC, OAuth, Kerberos, and MFA.
• Create and maintain PowerShell automation scripts for bulk administration, scheduled tasks, configuration drift correction, reporting, and Desired State Configuration (DSC) where applicable.
• Operate AWS hosting services tailored for Windows workloads, such as EC2, EBS, VPC, IAM, Route 53, CloudWatch, Systems Manager, Backup, and Directory Service.
• Manage IIS sites, application pools, bindings, ARR/URL Rewrite, SSL/TLS, failed request tracing, and performance optimization.
• Enhance observability through a strategic approach to event logging, performance baselines, CloudWatch metrics and alarms, and Grafana dashboards.
• Develop runbooks, standard operating procedures (SOPs), and knowledge-base articles.
• Engage in ITIL incident, problem, and change management processes.
• Serve as the senior on-call escalation point for major incidents.
• Function as a 100% individual contributor without team management responsibilities.
• Operate in alignment with New York business hours (08:30–17:30 ET).
• Over 7 years of experience in operating Windows Server in production environments, with extensive hands-on expertise in Windows Server 2019 and later versions.
• Profound understanding of Active Directory, including forest/domain design, replication, FSMO roles, trusts, sites and services, schema management, tombstone, and recovery processes.
• Experience in designing and troubleshooting Group Policy at scale, incorporating RSoP, gpresult, security baselines, and WMI filtering.
• In-depth knowledge of IIS, including configuration of sites and application pools, ARR, URL Rewrite, SSL/TLS, failed request tracing, and performance tuning.
• Operational proficiency with DNS, DHCP, WSUS, and Active Directory Certificate Services (AD CS).
• Advanced PowerShell capabilities, including scripting, module creation, remoting, error handling, automation patterns, and familiarity with DSC.
• Experience with large-scale Windows patching, including planning, deployment, rollback, and troubleshooting within regulated environments.
• Proficiency in Windows performance troubleshooting utilizing PerfMon, ETW, memory dump analysis, and IIS request diagnostics.
• Experience with hybrid identity solutions involving on-premises AD, cloud environments, Entra ID (Azure AD) Connect/federation, and AD FS.
• Practical experience in implementing and troubleshooting SAML 2.0, OIDC, OAuth 2.0, Kerberos, LDAP, and MFA.
• Knowledge of enterprise Windows certificate management and PKI.
• Daily operational competence with AWS Windows workloads, including EC2, EBS, VPC, IAM, Route 53, and CloudWatch.
• Familiarity with AWS Systems Manager for managing Windows fleets, including Patch Manager, Session Manager, Run Command, State Manager, and Parameter Store.
• Experience with AWS Directory Service, Managed Microsoft AD, or AD Connector.
• Strong foundation in ITIL practices concerning incident, problem, change, and service lifecycle management.
• Previous experience in an MSP or shared-services setting managing multiple client environments under service level agreements (SLAs).
• Advanced proficiency in professional English, both written and spoken.
• A reliable, distraction-free home office setup with stable broadband (recommended 100 Mbps+), dependable power, and a professional video conferencing arrangement.
• Consistent ability to work aligned with New York hours, remaining online, responsive, and engaged during core hours.
• Engagement through PJ (Pessoa Jurídica) or Employer of Record arrangements.
• Fully remote work opportunity.
• Compensation for senior escalation on-call participation in accordance with policy.
• Equipment and expenses will be discussed during the offer stage.
• Tax, invoicing, and benefits arrangements to be discussed at the time of the offer.
• Support for a quiet, ergonomic home-office setup as a work requirement.
• Requirements for stable broadband and reliable power for remote working conditions.
Kigen
Baker Hughes
Descript
Rocket Money (formerly Truebill)
Get handpicked remote jobs straight to your inbox weekly.