{"schemaVersion":"jobsearcher.job.v1","id":"4f873a28f17924cd14e0b23d","url":"https://jobsearcher.com/jobs/4f873a28f17924cd14e0b23d","canonicalUrl":"https://jobsearcher.com/jobs/4f873a28f17924cd14e0b23d","title":"Lead Systems Engineer (Microsoft Cloud)","description":"Lead Systems Engineer (Microsoft Cloud Engineer)\nPrecisesource, a national search firm is currently recruiting for a Lead Systems Engineer (Microsoft Cloud Engineer) to join for our client, a global multi-strategy private equity firm in Miami, FL (zip code 33134). In this role, the Lead Engineer will serve as a technical leader responsible for the architecture, administration, and ongoing optimization of the firm's core Microsoft cloud and hybrid infrastructure, spanning endpoint management, identity, messaging, and virtualization. The ideal candidate needs exceptional communication skills and is equally comfortable collaborating with line employees, cross-functional IT teams, and executive leadership. This individual is an independent, organized self-starter with a proven ability to manage complex, concurrent initiatives, lead projects to completion, and influence technical direction within defined deadlines. This role is weighted toward cloud and identity engineering rather than on-premises server administration; working knowledge of virtual server environments is expected, but deep physical or virtual server build-out is a minor, not primary, part of the job.\nThis is a full-time position that requires the candidate to be onsite Monday – Friday to start before moving into a hybrid schedule. This is a level 2 service desk position in a Microsoft/Windows environment. Our client is offering a competitive base salary and annual bonus ranging in the $200k to $300k range, great benefits and career growth. Must be eligible to work for any US Employer unrestricted.\nRole Responsibilities:\nOwn the Microsoft endpoint estate across Intune and SCCM in co-management, including workload transition, compliance and configuration profiles, and Proactive Remediations.\nLead Windows provisioning through Autopilot, including White Glove pre-provisioning, and maintain endpoint security baselines and GPO-to-CSP migration.\nAdminister Entra ID and hybrid Active Directory, including hybrid join, Windows Hello for Business, and device registration.\nDesign and maintain Conditional Access architecture, including guest access, device filters, and session controls, balancing security with usability.\nGovern directory RBAC, license posture, dynamic group membership, and Multi-Geo data residency.\nAdminister Exchange Online and hybrid mail flow, distribution list lifecycle, and mobile mail via Exchange ActiveSync.\nHold primary responsibility for SharePoint and Microsoft Teams drive administration, including site/team creation, documentation, access review, and governance.\nOperate the Citrix DaaS environment (VDA configuration, licensing, and Cloud Connector) and NetScaler gateway, and support ongoing evaluation and adoption of Azure Virtual Desktop and Microsoft Cloud PC / Windows 365 as the team's virtualization footprint shifts further toward the cloud.\nDeploy and maintain endpoint protection (for example, CrowdStrike) and drive hardening initiatives such as TLS deprecation, SMB signing, and logon banners in response to vulnerability findings.\nBuild and maintain PowerShell tooling to established coding standards, and Power Platform integrations (Power Automate, Power Apps) with Microsoft Graph, including HR-driven provisioning from Workday to Active Directory.\nCollaborate with the teams that administer Power BI services, workspaces, and governance policies, providing identity and infrastructure support as needed.\nServe as a Tier 3 escalation point for the Service Desk Engineers (Tier 2), providing advanced troubleshooting and resolution for issues that fall outside standard Tier 2 scope.\nAuthor change controls and lead CAB submissions; maintain SOPs, runbooks, and the IT knowledge base with disciplined, audience-aware documentation.\nMaintain internal tooling and governance artifacts that standardize team workflows.\nExperience and Professional Background:\nEight or more years in enterprise IT infrastructure or systems engineering, including three or more at a senior or lead level.\nProven ability to manage multiple concurrent projects and shifting priorities, paired with a generalist range across identity, endpoint, messaging, virtualization, and cloud infrastructure rather than deep specialization in a single domain.\nDeep expertise in Microsoft endpoint management (Intune and SCCM co-management, Autopilot) and Microsoft identity (Entra ID, Active Directory, Conditional Access, and Windows Hello for Business).\nStrong Exchange Online and hybrid administration, and broad Microsoft 365 experience.\nAdvanced PowerShell scripting and automation, including Microsoft Graph.\nWorking knowledge of virtualization and server fundamentals (for example Hyper-V or VMware, Windows Server roles) sufficient to support a hybrid environment; this is not a hands-on server build/rebuild role.\nStrong working knowledge of enterprise networking fundamentals (DNS, DHCP, routing and firewall concepts, VPN, SSL/TLS) sufficient to troubleshoot cross-stack issues and partner effectively with the network engineering team; this is not a network engineering role.\nDemonstrated change-control discipline and clear technical writing.\nExperience operating in a security-conscious, regulated, or financial-services environment with least-privilege practices.\nProfessional Certifications and Technical Focus:\nCitrix DaaS and NetScaler, and/or Azure Virtual Desktop experience.\nIntegration of HR systems (Workday) with identity provisioning.\nMimecast administration experience is a plus.\nRelevant certifications, for example Microsoft MD-102, SC-300, MS-102, or AZ-104; Citrix CCA-V; and recognized security certifications.\nFamiliarity with IT service management frameworks such as ITIL is beneficial.\nJob Type: Full-time\nBase Pay: $200,000.00 - $300,000.00 per year\nBenefits:\n401(k)\nDental insurance\nHealth insurance\nPaid time off\nVision insurance\nExperience:\nMicrosoft Endpoint Management: 4 years (Preferred)\nMicrosoft Identity: 4 years (Preferred)\nAbility to Commute:\nCoral Gables, FL 33134 (Preferred)\nWork Location: Hybrid remote in Coral Gables, FL 33134","company":"Precisesource","rawCompany":"precisesource","city":"Coral Gables","state":"FL","isRemote":false,"isActive":false,"createdAt":"2026-08-06T14:23:11.720Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1231.00","title":"Computer Network Support Specialists","slug":"computer-network-support-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Systems Engineer (Microsoft Cloud)","description":"Lead Systems Engineer (Microsoft Cloud Engineer)\nPrecisesource, a national search firm is currently recruiting for a Lead Systems Engineer (Microsoft Cloud Engineer) to join for our client, a global multi-strategy private equity firm in Miami, FL (zip code 33134). In this role, the Lead Engineer will serve as a technical leader responsible for the architecture, administration, and ongoing optimization of the firm's core Microsoft cloud and hybrid infrastructure, spanning endpoint management, identity, messaging, and virtualization. The ideal candidate needs exceptional communication skills and is equally comfortable collaborating with line employees, cross-functional IT teams, and executive leadership. This individual is an independent, organized self-starter with a proven ability to manage complex, concurrent initiatives, lead projects to completion, and influence technical direction within defined deadlines. This role is weighted toward cloud and identity engineering rather than on-premises server administration; working knowledge of virtual server environments is expected, but deep physical or virtual server build-out is a minor, not primary, part of the job.\nThis is a full-time position that requires the candidate to be onsite Monday – Friday to start before moving into a hybrid schedule. This is a level 2 service desk position in a Microsoft/Windows environment. Our client is offering a competitive base salary and annual bonus ranging in the $200k to $300k range, great benefits and career growth. Must be eligible to work for any US Employer unrestricted.\nRole Responsibilities:\nOwn the Microsoft endpoint estate across Intune and SCCM in co-management, including workload transition, compliance and configuration profiles, and Proactive Remediations.\nLead Windows provisioning through Autopilot, including White Glove pre-provisioning, and maintain endpoint security baselines and GPO-to-CSP migration.\nAdminister Entra ID and hybrid Active Directory, including hybrid join, Windows Hello for Business, and device registration.\nDesign and maintain Conditional Access architecture, including guest access, device filters, and session controls, balancing security with usability.\nGovern directory RBAC, license posture, dynamic group membership, and Multi-Geo data residency.\nAdminister Exchange Online and hybrid mail flow, distribution list lifecycle, and mobile mail via Exchange ActiveSync.\nHold primary responsibility for SharePoint and Microsoft Teams drive administration, including site/team creation, documentation, access review, and governance.\nOperate the Citrix DaaS environment (VDA configuration, licensing, and Cloud Connector) and NetScaler gateway, and support ongoing evaluation and adoption of Azure Virtual Desktop and Microsoft Cloud PC / Windows 365 as the team's virtualization footprint shifts further toward the cloud.\nDeploy and maintain endpoint protection (for example, CrowdStrike) and drive hardening initiatives such as TLS deprecation, SMB signing, and logon banners in response to vulnerability findings.\nBuild and maintain PowerShell tooling to established coding standards, and Power Platform integrations (Power Automate, Power Apps) with Microsoft Graph, including HR-driven provisioning from Workday to Active Directory.\nCollaborate with the teams that administer Power BI services, workspaces, and governance policies, providing identity and infrastructure support as needed.\nServe as a Tier 3 escalation point for the Service Desk Engineers (Tier 2), providing advanced troubleshooting and resolution for issues that fall outside standard Tier 2 scope.\nAuthor change controls and lead CAB submissions; maintain SOPs, runbooks, and the IT knowledge base with disciplined, audience-aware documentation.\nMaintain internal tooling and governance artifacts that standardize team workflows.\nExperience and Professional Background:\nEight or more years in enterprise IT infrastructure or systems engineering, including three or more at a senior or lead level.\nProven ability to manage multiple concurrent projects and shifting priorities, paired with a generalist range across identity, endpoint, messaging, virtualization, and cloud infrastructure rather than deep specialization in a single domain.\nDeep expertise in Microsoft endpoint management (Intune and SCCM co-management, Autopilot) and Microsoft identity (Entra ID, Active Directory, Conditional Access, and Windows Hello for Business).\nStrong Exchange Online and hybrid administration, and broad Microsoft 365 experience.\nAdvanced PowerShell scripting and automation, including Microsoft Graph.\nWorking knowledge of virtualization and server fundamentals (for example Hyper-V or VMware, Windows Server roles) sufficient to support a hybrid environment; this is not a hands-on server build/rebuild role.\nStrong working knowledge of enterprise networking fundamentals (DNS, DHCP, routing and firewall concepts, VPN, SSL/TLS) sufficient to troubleshoot cross-stack issues and partner effectively with the network engineering team; this is not a network engineering role.\nDemonstrated change-control discipline and clear technical writing.\nExperience operating in a security-conscious, regulated, or financial-services environment with least-privilege practices.\nProfessional Certifications and Technical Focus:\nCitrix DaaS and NetScaler, and/or Azure Virtual Desktop experience.\nIntegration of HR systems (Workday) with identity provisioning.\nMimecast administration experience is a plus.\nRelevant certifications, for example Microsoft MD-102, SC-300, MS-102, or AZ-104; Citrix CCA-V; and recognized security certifications.\nFamiliarity with IT service management frameworks such as ITIL is beneficial.\nJob Type: Full-time\nBase Pay: $200,000.00 - $300,000.00 per year\nBenefits:\n401(k)\nDental insurance\nHealth insurance\nPaid time off\nVision insurance\nExperience:\nMicrosoft Endpoint Management: 4 years (Preferred)\nMicrosoft Identity: 4 years (Preferred)\nAbility to Commute:\nCoral Gables, FL 33134 (Preferred)\nWork Location: Hybrid remote in Coral Gables, FL 33134","datePosted":"2026-08-06T14:23:11.720Z","dateModified":"2026-08-06T14:23:11.720Z","hiringOrganization":{"@type":"Organization","name":"Precisesource","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Coral Gables","addressRegion":"FL","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"4f873a28f17924cd14e0b23d"},"url":"https://jobsearcher.com/jobs/4f873a28f17924cd14e0b23d"}}