Remotery

Cloud Windows Infrastructure Engineer

Posted Jul 27

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Oversee the resolution of intricate Windows Server incidents across multi-client, AWS-hosted environments, managing the process from triage through to root cause analysis and remediation.

• Administer and enhance Windows Server versions 2019/2022/2025, focusing on Active Directory (including forest/domain design, replication, FSMO roles, GPOs, and trusts), DNS, DHCP, IIS, WSUS, AD CS, as well as file and print services.

• Manage hybrid identity solutions involving on-premises Active Directory linked with AWS Managed Microsoft AD, along with federation utilizing Entra ID (Azure AD), AD FS, SAML, OIDC, OAuth, Kerberos, and MFA.

• Create and uphold PowerShell automation scripts for bulk administration, scheduled tasks, configuration drift correction, reporting, and Desired State Configuration (DSC) where applicable.

• Operate the AWS infrastructure for Windows workloads, including EC2, EBS, VPC, IAM, Route 53, CloudWatch, and Systems Manager (covering Patch Manager, Session Manager, and Run Command), as well as backup and directory services.

• Manage IIS extensively, handling sites, application pools, bindings, ARR/URL Rewrite, SSL/TLS, failed request tracing, and performance optimization.

• Enhance the observability of the Windows environment by developing event log strategies, establishing performance baselines, and utilizing CloudWatch metrics and alarms, along with Grafana dashboards.

• Write runbooks, standard operating procedures (SOPs), and knowledge base articles to formalize operational standards.

• Engage in ITIL incident, problem, and change management processes, acting as a senior escalation point during on-call scenarios.


⛳️ Requirements

• A minimum of 7 years of experience in operating Windows Server in production, with in-depth hands-on expertise in Windows Server 2019 and later versions.

• Profound knowledge of Active Directory, including forest/domain design, replication, FSMO roles, trusts, sites and services, schema management, tombstone, and recovery processes.

• Extensive experience with Group Policy at scale, including design, troubleshooting (utilizing RSoP and gpresult), security baselines, and WMI filtering.

• In-depth knowledge of IIS, including configuration of sites and application pools, ARR, URL Rewrite, SSL/TLS management, failed request tracing, and performance tuning.

• Practical experience with DNS, DHCP, WSUS, and Active Directory Certificate Services (AD CS) in operational settings.

• Advanced proficiency in PowerShell, including scripting, module creation, remoting, error handling, automation patterns, and familiarity with DSC.

• Experience in Windows patch management at scale, including planning, deployment, rollback, and troubleshooting within regulated environments.

• Skills in Windows performance troubleshooting, utilizing tools such as PerfMon, ETW, memory dump analysis, and IIS request diagnostics.

• Knowledge of hybrid identity solutions involving on-premises Active Directory and cloud integration, including Entra ID (Azure AD) Connect/federation and AD FS.

• Experience with SAML 2.0, OIDC, OAuth 2.0, Kerberos, LDAP, and MFA, including practical implementation and troubleshooting.

• Familiarity with certificate management and PKI within enterprise Windows environments.

• Comfortable with day-to-day operations of Windows workloads in AWS, including EC2, EBS, VPC, IAM, and Route 53.

• Proficient in using AWS Systems Manager for managing Windows fleets, covering Patch Manager, Session Manager, Run Command, State Manager, and Parameter Store.

• Experience with AWS Directory Service, Managed Microsoft AD, and AD Connector.

• Strong grounding in ITIL principles, encompassing incident, problem, change, and service lifecycle management.

• Previous experience in a Managed Service Provider (MSP) or shared-services environment, managing multiple client estates under Service Level Agreements (SLAs).

• Advanced proficiency in professional English, both written and spoken.

• A reliable home office with stable broadband (recommended 100 Mbps+), dependable power supply, and a professional video setup.

• Ability to consistently work New York-aligned hours, maintaining the same presence and responsiveness as an in-office colleague.


🏝️ Benefits

• Competitive compensation package.

• Opportunities for professional development and growth.

• Flexible working hours and remote work options.

• Collaborative and inclusive work environment.

• Access to the latest tools and technologies.

People also viewed

Tailscale9 hours ago

Security Infrastructure Engineer

CA flagCanada, +1 more countryFull-timeInfrastructure EngineerC$218.4k – C$273.4k/year
ApplyView job
Adzuna10 hours ago

Infrastructure Engineer

GR flagGreece, +4 more countriesFull-timeInfrastructure Engineer€60k – €70k/year
ApplyView job
Webflow12 hours ago

Staff Software Engineer, Infrastructure

US flagUnited States, +1 more countryFull-timeInfrastructure Engineer$186.7k – $278k/year
ApplyView job
Coinbase13 hours ago

Staff Infrastructure Engineer – Trading

US flagUnited States OnlyFull-timeInfrastructure Engineer$218k – $256.5k/year
ApplyView job
Bishop Fox14 hours ago

Infrastructure Engineer

US flagUnited States OnlyFull-timeInfrastructure Engineer
ApplyView job
Tailscale14 hours ago

Security Infrastructure Engineer

US flagUnited States, +1 more countryFull-timeInfrastructure Engineer$163k – $204k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers