{"schemaVersion":"jobsearcher.job.v1","id":"1a14d6fc8fd6a283fba79361","url":"https://jobsearcher.com/jobs/1a14d6fc8fd6a283fba79361","canonicalUrl":"https://jobsearcher.com/jobs/1a14d6fc8fd6a283fba79361","title":"Systems Engineer","description":"About This Unique Opportunity\nWe're looking for a Systems Engineer with deep expertise in Microsoft cloud technologies to join our engineering team. This is a technical position for someone who lives in the Microsoft stack and wants to push the boundaries of what modern cloud security and management look like for a growing portfolio of business clients.\nAt neteffect technologies, you'll work across a diverse client base, architecting and managing solutions in Azure, Microsoft 365, Entra ID, and cloud security tooling. You'll be the subject matter expert our team and clients turn to when cloud governance, identity security, or AI risk questions arise.\nCompany Description\nFounded in 1991 and based in Charlotte, NC, neteffect technologies is an established Managed Service Provider delivering managed IT, cloud, security, virtualization, and telecom solutions to businesses across the region. We operate as a true technology partner — taking ownership of our clients' IT environments so they can focus on running their business. Our engineering team supports a diverse portfolio of clients, backed by strong leadership and a culture of accountability and continuous improvement.\nWhat Makes This Role Different\nOwn the Microsoft cloud stack — you'll be a cloud and security SME the team escalates to\nReal influence on security posture — from CA policy design to Shadow IT discovery to AI governance framework rollout\nWork across a varied client base — no two environments are the same; you'll see it all\nCollaborate with leadership on strategy — not just execution, but helping shape how we approach cloud and security as an MSP\nAccess to a fully resourced toolset across PSA, RMM, security, backup, and documentation platforms.\nJob Summary\nThis Systems Engineer role is responsible for the design, implementation, management, and continuous improvement of cloud and security solutions across the neteffect client portfolio. Primary focus areas include Microsoft Entra ID, Azure, Microsoft 365, cloud app security (CASB/MDCA), and emerging governance challenges around AI and Shadow IT.\nYou'll serve as a technical resource for escalations, handle complex project work, conduct security reviews, and help define standards and best practices for the broader engineering team.\nKey Responsibilities\nCloud Architecture & Administration\nDesign, implement, and manage Microsoft Azure environments including compute (VMs, scale sets), storage, networking (VNets, NSGs, DNS), and supporting infrastructure\nDeploy and manage Entra-joined devices using Kerberos Cloud Trust for seamless SSO to on-premises resources without requiring legacy domain join\nAdminister Microsoft 365 tenants across the client portfolio — Exchange Online, SharePoint, Teams, and OneDrive\nManage Entra ID including Conditional Access policies, Entra join, SSPR, and authentication methods\nImplement and maintain Windows Hello for Business and Entra-native MFA/phishing-resistant authentication\nDeploy and manage Intune/Autopilot for endpoint lifecycle management across Windows and macOS\nSecurity & Compliance\nArchitect and enforce Conditional Access policies with Authentication Strength, compliant device requirements, and named location controls\nDeploy and tune Microsoft Defender for Cloud Apps (MDCA) for Shadow IT discovery, OAuth app governance, and session/access policy enforcement\nInvestigate and respond to identity-based threats — AiTM attacks, BEC incidents, token replay, and suspicious sign-in activity — using UAL, Entra sign-in logs, and available XDR/SIEM tooling\nLead AI Governance efforts for client environments: govern Microsoft 365 Copilot deployment, assess shadow AI risk, classify sensitive data exposed to AI workloads, and implement Purview-based controls\nSupport compliance frameworks including PCI DSS, HIPAA, and NIST CSF as applicable\nCoordinate with third-party security vendors (Arctic Wolf, SentinelOne, ThreatLocker, Check Point Harmony/Avanan) on alert triage, investigation, and response\nIdentity & Access Management\nOwn the identity stack: Entra ID, Entra Connect (where legacy on-prem sync exists), ADCS, and PKI\nConduct periodic access reviews, privileged identity audits, and MFA posture assessments across the client base\nDrive adoption of zero-trust principles through policy, tooling, and client education\nSupport RBAC design in Azure and M365 for least-privilege access models\nShadow IT & Cloud App Governance\nDiscover and inventory unsanctioned cloud application usage using MDCA and network log integration\nClassify and assess risk of shadow applications; build remediation and sanctioning workflows with client stakeholders\nDefine and enforce cloud app policies, block high-risk apps, and configure real-time session controls\nBuild reporting dashboards and executive summaries on cloud app risk for client leadership\nEngineering Standards & Escalation\nServe as an escalation point for the engineering team on complex cloud, identity, and security issues\nDevelop and maintain runbooks, configuration standards, and decision frameworks for cloud and security domains\nConduct post-incident reviews and produce RCAs for significant security events or outages\nDeliver internal training on evolving Microsoft technologies and best practices\nClient Engagement & Strategy\nEngage directly with client IT leadership and executive stakeholders on security posture, roadmap planning, and risk\nProduce and present clear, actionable reports on security findings, cloud spend efficiency, and governance gaps\nParticipate in QBRs and strategic planning meetings as a technical advisor\nRequired Qualifications\nExperience:\n4–7 years of IT experience with at least 3 years focused on Microsoft cloud technologies\nMSP experience required — you understand multi-tenant management, client accountability, and the discipline of working across varied environments simultaneously\nDemonstrated hands-on experience with Entra ID, Azure, and Microsoft 365 administration at an engineering level\nExperience investigating security incidents involving identity compromise, BEC, or cloud-based threats\nTechnical Skills - Required:\nMicrosoft Entra ID: Conditional Access, cloud-native identity (Entra join), authentication methods, PIM, app registrations\nMicrosoft 365: Exchange Online, SharePoint, Teams, Intune, Autopilot\nAzure: compute, storage, networking, Azure Files, Entra Kerberos (Cloud Trust), core infrastructure fundamentals\nMicrosoft Defender for Cloud Apps: app discovery, OAuth governance, session policies, CASB functionality\nEndpoint management: Intune/Autopilot, Windows Hello for Business, compliance policies\nSecurity operations: UAL/audit log analysis, Entra sign-in log triage, identity threat investigation\nNetworking: TCP/IP, DNS, DHCP, VLANs, firewall concepts\nTechnical Skills - Preferred:\nMicrosoft Purview: sensitivity labels, DLP, communication compliance, AI hub governance\nEntra ID Governance / Identity Governance and Administration (IGA)\nMicrosoft Sentinel or other SIEM/SOAR platforms\nPowerShell scripting for automation, reporting, and bulk management tasks\nAzure cost management, resource optimization, and right-sizing\nPreferred Tool Experience\nFamiliarity with any of the following is a strong plus. You won't be expected to know all of them on day one, but comfort learning new platforms quickly is essential:\nPSA, RMM & Remote Access\nConnectWise Manage — ticketing, time entry, billing, and project management\nConnectWise RMM (Asio) — cloud-native RMM for endpoint monitoring, patching, and scripted automation\nConnectWise ScreenConnect — remote access and support sessions\nSecurity\nSentinelOne — EDR/XDR endpoint protection across the client portfolio\nArctic Wolf — managed detection and response (MDR) with SOC-as-a-service; you'll work directly with their team on alert triage and investigations\nThreatLocker — application allowlisting, storage control, and ringfencing; you'll manage policies and handle blocked application escalations\nCheck Point Harmony (Avanan) — cloud email security for Microsoft 365 and Google Workspace; phishing, BEC, and malware detection\nBreach Secure Now — security awareness training and dark web monitoring for end-user education across clients\nBackup & Disaster Recovery\nVeeam Backup & Replication — primary backup platform for on-premises and cloud workloads; experience with repository management, job design, and restore testing is valuable\nNetwork Monitoring & Documentation\nAuvik — network monitoring, topology mapping, and configuration backup; used for visibility across client network infrastructure\nIT Glue — documentation platform for network diagrams, credentials, SOPs, and asset records; keeping documentation accurate is a shared responsibility on the team\nCertifications (Preferred)\nMicrosoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)\nMicrosoft Certified: Identity and Access Administrator Associate (SC-300)\nMicrosoft Certified: Security Operations Analyst Associate (SC-200)\nMicrosoft Certified: Azure Administrator Associate (AZ-104)\nSoft Skills — Critical for Success\nAbility to communicate complex security and cloud concepts clearly to non-technical stakeholders\nStrong documentation discipline — you write things down so others can follow\nSelf-directed and capable of managing multiple concurrent workstreams without close supervision\nRoot cause mindset — you want to know why something happened, not just fix it and move on\nProfessional presence and ability to represent neteffect technologies at the client executive level\nWhat We Offer\nCompensation & Benefits\nCompetitive salary commensurate with experience\nComprehensive health and dental insurance\n401(k) with company matching\nPaid time off\nPerformance-based bonus opportunities\nProfessional Development\nCertification support and exam reimbursement\nAccess to Microsoft partner resources, labs, and early-access programs\nMentorship and collaboration with experienced MSP engineers and leadership\nMeaningful work that directly shapes client security posture and cloud maturity\nWork Environment\nSmall-company culture that values technical depth, accountability, and autonomy\nNo excessive bureaucracy — you'll have room to make decisions and move fast\nHybrid work model: time split between the neteffect technologies office in Charlotte and client site visits\nMonday–Friday, day shift, with occasional after-hours or on-call support as needed\nOther Requirements\nBachelor's degree in IT, Computer Science, or related field — OR equivalent professional experience\nValid driver's license with clean driving record and appropriate insurance coverage\nAbility to lift up to 50 pounds occasionally\nAbility to pass background check and drug screening upon offer\nWhy Join neteffect technologies?\nIf you've been doing deep Microsoft cloud and security work — managing Entra ID at scale, chasing down AiTM attacks, leading Shadow IT discovery efforts — and you're ready to bring that expertise to a role where it directly shapes client outcomes and company strategy, we'd like to talk.\nneteffect technologies is an equal opportunity employer.\nWork Location: Charlotte, NC (hybrid between neteffect technologies office in southwest Charlotte and client sites)\nJob Type: Full-time\nSchedule: Monday to Friday, day shift, with occasional on-call rotation\nJob Type: Full-time\nPay: $75,000.00 - $90,000.00 per year\nBenefits:\n401(k)\nDental insurance\nHealth insurance\nPaid time off\nWork Location: In person","company":"Neteffect Technologies","rawCompany":"neteffect technologies","city":"Charlotte","state":"NC","isRemote":false,"isActive":false,"createdAt":"2026-07-20T11:39:28.590Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1211.00","title":"Computer Systems Analysts","slug":"computer-systems-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Systems Engineer","description":"About This Unique Opportunity\nWe're looking for a Systems Engineer with deep expertise in Microsoft cloud technologies to join our engineering team. This is a technical position for someone who lives in the Microsoft stack and wants to push the boundaries of what modern cloud security and management look like for a growing portfolio of business clients.\nAt neteffect technologies, you'll work across a diverse client base, architecting and managing solutions in Azure, Microsoft 365, Entra ID, and cloud security tooling. You'll be the subject matter expert our team and clients turn to when cloud governance, identity security, or AI risk questions arise.\nCompany Description\nFounded in 1991 and based in Charlotte, NC, neteffect technologies is an established Managed Service Provider delivering managed IT, cloud, security, virtualization, and telecom solutions to businesses across the region. We operate as a true technology partner — taking ownership of our clients' IT environments so they can focus on running their business. Our engineering team supports a diverse portfolio of clients, backed by strong leadership and a culture of accountability and continuous improvement.\nWhat Makes This Role Different\nOwn the Microsoft cloud stack — you'll be a cloud and security SME the team escalates to\nReal influence on security posture — from CA policy design to Shadow IT discovery to AI governance framework rollout\nWork across a varied client base — no two environments are the same; you'll see it all\nCollaborate with leadership on strategy — not just execution, but helping shape how we approach cloud and security as an MSP\nAccess to a fully resourced toolset across PSA, RMM, security, backup, and documentation platforms.\nJob Summary\nThis Systems Engineer role is responsible for the design, implementation, management, and continuous improvement of cloud and security solutions across the neteffect client portfolio. Primary focus areas include Microsoft Entra ID, Azure, Microsoft 365, cloud app security (CASB/MDCA), and emerging governance challenges around AI and Shadow IT.\nYou'll serve as a technical resource for escalations, handle complex project work, conduct security reviews, and help define standards and best practices for the broader engineering team.\nKey Responsibilities\nCloud Architecture & Administration\nDesign, implement, and manage Microsoft Azure environments including compute (VMs, scale sets), storage, networking (VNets, NSGs, DNS), and supporting infrastructure\nDeploy and manage Entra-joined devices using Kerberos Cloud Trust for seamless SSO to on-premises resources without requiring legacy domain join\nAdminister Microsoft 365 tenants across the client portfolio — Exchange Online, SharePoint, Teams, and OneDrive\nManage Entra ID including Conditional Access policies, Entra join, SSPR, and authentication methods\nImplement and maintain Windows Hello for Business and Entra-native MFA/phishing-resistant authentication\nDeploy and manage Intune/Autopilot for endpoint lifecycle management across Windows and macOS\nSecurity & Compliance\nArchitect and enforce Conditional Access policies with Authentication Strength, compliant device requirements, and named location controls\nDeploy and tune Microsoft Defender for Cloud Apps (MDCA) for Shadow IT discovery, OAuth app governance, and session/access policy enforcement\nInvestigate and respond to identity-based threats — AiTM attacks, BEC incidents, token replay, and suspicious sign-in activity — using UAL, Entra sign-in logs, and available XDR/SIEM tooling\nLead AI Governance efforts for client environments: govern Microsoft 365 Copilot deployment, assess shadow AI risk, classify sensitive data exposed to AI workloads, and implement Purview-based controls\nSupport compliance frameworks including PCI DSS, HIPAA, and NIST CSF as applicable\nCoordinate with third-party security vendors (Arctic Wolf, SentinelOne, ThreatLocker, Check Point Harmony/Avanan) on alert triage, investigation, and response\nIdentity & Access Management\nOwn the identity stack: Entra ID, Entra Connect (where legacy on-prem sync exists), ADCS, and PKI\nConduct periodic access reviews, privileged identity audits, and MFA posture assessments across the client base\nDrive adoption of zero-trust principles through policy, tooling, and client education\nSupport RBAC design in Azure and M365 for least-privilege access models\nShadow IT & Cloud App Governance\nDiscover and inventory unsanctioned cloud application usage using MDCA and network log integration\nClassify and assess risk of shadow applications; build remediation and sanctioning workflows with client stakeholders\nDefine and enforce cloud app policies, block high-risk apps, and configure real-time session controls\nBuild reporting dashboards and executive summaries on cloud app risk for client leadership\nEngineering Standards & Escalation\nServe as an escalation point for the engineering team on complex cloud, identity, and security issues\nDevelop and maintain runbooks, configuration standards, and decision frameworks for cloud and security domains\nConduct post-incident reviews and produce RCAs for significant security events or outages\nDeliver internal training on evolving Microsoft technologies and best practices\nClient Engagement & Strategy\nEngage directly with client IT leadership and executive stakeholders on security posture, roadmap planning, and risk\nProduce and present clear, actionable reports on security findings, cloud spend efficiency, and governance gaps\nParticipate in QBRs and strategic planning meetings as a technical advisor\nRequired Qualifications\nExperience:\n4–7 years of IT experience with at least 3 years focused on Microsoft cloud technologies\nMSP experience required — you understand multi-tenant management, client accountability, and the discipline of working across varied environments simultaneously\nDemonstrated hands-on experience with Entra ID, Azure, and Microsoft 365 administration at an engineering level\nExperience investigating security incidents involving identity compromise, BEC, or cloud-based threats\nTechnical Skills - Required:\nMicrosoft Entra ID: Conditional Access, cloud-native identity (Entra join), authentication methods, PIM, app registrations\nMicrosoft 365: Exchange Online, SharePoint, Teams, Intune, Autopilot\nAzure: compute, storage, networking, Azure Files, Entra Kerberos (Cloud Trust), core infrastructure fundamentals\nMicrosoft Defender for Cloud Apps: app discovery, OAuth governance, session policies, CASB functionality\nEndpoint management: Intune/Autopilot, Windows Hello for Business, compliance policies\nSecurity operations: UAL/audit log analysis, Entra sign-in log triage, identity threat investigation\nNetworking: TCP/IP, DNS, DHCP, VLANs, firewall concepts\nTechnical Skills - Preferred:\nMicrosoft Purview: sensitivity labels, DLP, communication compliance, AI hub governance\nEntra ID Governance / Identity Governance and Administration (IGA)\nMicrosoft Sentinel or other SIEM/SOAR platforms\nPowerShell scripting for automation, reporting, and bulk management tasks\nAzure cost management, resource optimization, and right-sizing\nPreferred Tool Experience\nFamiliarity with any of the following is a strong plus. You won't be expected to know all of them on day one, but comfort learning new platforms quickly is essential:\nPSA, RMM & Remote Access\nConnectWise Manage — ticketing, time entry, billing, and project management\nConnectWise RMM (Asio) — cloud-native RMM for endpoint monitoring, patching, and scripted automation\nConnectWise ScreenConnect — remote access and support sessions\nSecurity\nSentinelOne — EDR/XDR endpoint protection across the client portfolio\nArctic Wolf — managed detection and response (MDR) with SOC-as-a-service; you'll work directly with their team on alert triage and investigations\nThreatLocker — application allowlisting, storage control, and ringfencing; you'll manage policies and handle blocked application escalations\nCheck Point Harmony (Avanan) — cloud email security for Microsoft 365 and Google Workspace; phishing, BEC, and malware detection\nBreach Secure Now — security awareness training and dark web monitoring for end-user education across clients\nBackup & Disaster Recovery\nVeeam Backup & Replication — primary backup platform for on-premises and cloud workloads; experience with repository management, job design, and restore testing is valuable\nNetwork Monitoring & Documentation\nAuvik — network monitoring, topology mapping, and configuration backup; used for visibility across client network infrastructure\nIT Glue — documentation platform for network diagrams, credentials, SOPs, and asset records; keeping documentation accurate is a shared responsibility on the team\nCertifications (Preferred)\nMicrosoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)\nMicrosoft Certified: Identity and Access Administrator Associate (SC-300)\nMicrosoft Certified: Security Operations Analyst Associate (SC-200)\nMicrosoft Certified: Azure Administrator Associate (AZ-104)\nSoft Skills — Critical for Success\nAbility to communicate complex security and cloud concepts clearly to non-technical stakeholders\nStrong documentation discipline — you write things down so others can follow\nSelf-directed and capable of managing multiple concurrent workstreams without close supervision\nRoot cause mindset — you want to know why something happened, not just fix it and move on\nProfessional presence and ability to represent neteffect technologies at the client executive level\nWhat We Offer\nCompensation & Benefits\nCompetitive salary commensurate with experience\nComprehensive health and dental insurance\n401(k) with company matching\nPaid time off\nPerformance-based bonus opportunities\nProfessional Development\nCertification support and exam reimbursement\nAccess to Microsoft partner resources, labs, and early-access programs\nMentorship and collaboration with experienced MSP engineers and leadership\nMeaningful work that directly shapes client security posture and cloud maturity\nWork Environment\nSmall-company culture that values technical depth, accountability, and autonomy\nNo excessive bureaucracy — you'll have room to make decisions and move fast\nHybrid work model: time split between the neteffect technologies office in Charlotte and client site visits\nMonday–Friday, day shift, with occasional after-hours or on-call support as needed\nOther Requirements\nBachelor's degree in IT, Computer Science, or related field — OR equivalent professional experience\nValid driver's license with clean driving record and appropriate insurance coverage\nAbility to lift up to 50 pounds occasionally\nAbility to pass background check and drug screening upon offer\nWhy Join neteffect technologies?\nIf you've been doing deep Microsoft cloud and security work — managing Entra ID at scale, chasing down AiTM attacks, leading Shadow IT discovery efforts — and you're ready to bring that expertise to a role where it directly shapes client outcomes and company strategy, we'd like to talk.\nneteffect technologies is an equal opportunity employer.\nWork Location: Charlotte, NC (hybrid between neteffect technologies office in southwest Charlotte and client sites)\nJob Type: Full-time\nSchedule: Monday to Friday, day shift, with occasional on-call rotation\nJob Type: Full-time\nPay: $75,000.00 - $90,000.00 per year\nBenefits:\n401(k)\nDental insurance\nHealth insurance\nPaid time off\nWork Location: In person","datePosted":"2026-07-20T11:39:28.590Z","dateModified":"2026-07-20T11:39:28.590Z","hiringOrganization":{"@type":"Organization","name":"Neteffect Technologies","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Charlotte","addressRegion":"NC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"1a14d6fc8fd6a283fba79361"},"url":"https://jobsearcher.com/jobs/1a14d6fc8fd6a283fba79361"}}