Lead Engineer (Level 3)
Position: Lead Engineer (Level 3)
Department: Service and Support
General Summary:
Lead Engineers are strong in all the most common and popular technologies as well as some of the more mature ones. In addition to strong technical aptitudes, backed by at least 5 years of hard core in the trenches experience, this person is a powerful communicator and a person who can manage well when the client is in a pickle and really needs strong guidance. The pace and demands in this environment are usually much greater than an "in-house" position. This person should be prompt and/or know the importance of communicating ETA's to clients. This person should be skillful at pre-project/work-briefings with each client on each project. This person should then be able to execute with a high degree of success in integrating and/or solving problems in environments rich in Microsoft365, Server, Exchange, SQL, IIS, VPNs, firewalls, backups, Linux, UNIX and more.
Position Responsibilities:
DAILY time entry accounting for at least 7 hours in the form of Resolution Notes in Service Tickets
Adherence to SLA requirements for ticket resolution and related KPIs
Respond to customer support tickets, on the service board, especially escalations, communicating clear updates and ETAs, troubleshooting and resolving issues to completion, documenting work performed and time accurately.
Act as Project Lead for large projects and deployments
Provide guidance and backup coverage for junior Engineers
T&M service requests
Participate in on-call support rotations as needed
Administer/oversee Professional Services Automation (PSA) and Remote Monitoring and Management (RMM) software for consistent asset accuracy, alerting, patching, and reporting; drive problem investigations and RCAs for major incidents.
Act as a resource for ticket escalation and mentor for engineers; perform advanced diagnostics and remediation across Microsoft 365/Entra ID, Exchange/Teams/SharePoint, Windows Server/AD/DNS/DHCP, virtualization (Hyper‑V/VMware), email platforms, SAN/backup/HA, and network/firewall scenarios.
Pre‑Sales / Quote Support:
Provide operational input for quotes and statements of work for both projects and managed services. This includes labor models, onboarding effort, standard stack requirements, delivery risks, etc.
Personnel Management and Supervisory Responsibilities:
Supervise, lead, mentor and evaluate junior engineers. Coach and train junior engineers with an emphasis on retaining high quality personnel and increasing their capabilities.
Assist in the hiring process of additional staff members as needed, assuming significant responsibility for final decision on potential candidates.
Onboard newly hired engineers and operational staff.
Assist with training plans and career paths for junior engineers.
Maintain high standards for documentation, communication, and professionalism.
Business and Operational Management:
Develop and report on operational KPIs; improve utilization, reduce rework, align labor to demand, and contribute to the services P&L.
Implement improvements that scale reliably and securely; maintain strategic vendor relationships. Vendor management includes building relationships with vendors to drive improvements to utilization and working with billing/licensing platforms.
Provide operational input for quotes and statements of work for both projects and managed services. This includes labor models, onboarding effort, standard stack requirements, delivery risks, etc.
Experience:
Engineer with minimum five years’ experience
Minimum 4 years’ experience – Active Directory Support, Microsoft Windows and Windows Server Support, Microsoft Exchange Support
Minimum 4 years’ experience – Microsoft 365/Azure Active Directory
Minimum 4 years’ experience - Switching/VLAN/Routing/Firewalling Support
Minimum 4 years’ experience - Server Hardware Technologies (CPU/RAID/SCSI) Support
Minimum 4 years’ experience - Data Backup and Recovery Support, EDR Antivirus Support, VPN Connectivity Support
Credentials:
1. Microsoft 365 / Entra ID (expert practitioner):
Tenant admin at scale, Conditional Access design, MFA/Self-Service, break-glass strategy, Identity Protection signals.
Exchange Online, SharePoint/OneDrive, Teams admin & troubleshooting (mail flow, hybrid basics, sharing boundaries).
Intune/Endpoint Manager: Autopilot, compliance, configuration profiles, app deployment, BitLocker policy, Windows Update for Business; baseline macOS MDM familiarity.
2. Security:
Defender for Endpoint/M365 deployment & tuning (exclusions, suppression, ASR), incident triage; basic KQL for investigation; coordinate with SOC/EDR vendors.
Practical Zero Trust enforcement: least-privilege, device compliance gates, privileged access segmentation.
3. Windows Server/AD:
AD health/DNS/DHCP/GPO, Entra Connect cloud sync concepts, certificate services basics; backup/restore/tested runbooks.
4. Virtualization & DR:
VMware or Hyper-V at advanced admin level; Veeam (or equivalent) for VM & M365 backup; tested BC/DR playbooks.
5. Networking:
VLANs, routing, VPN (site-to-site/remote), QoS, NAC/Wi-Fi fundamentals; hands-on with at least two MSP-common firewalls (Fortinet/Meraki/WatchGuard/SonicWall) and switch stacks.
6. Automation & Tooling:
Strong PowerShell 7 (Graph modules), scripting for tenant and endpoint automation; PSA & RMM policy hygiene and reporting leadership.
7. Additional Preferred Experience:
Azure: landing zone-lite for SMB workloads (naming/ RBAC/ Policy), IaaS (VMs, managed disks, availability options), Private Link, site-to-site VPN, Azure Files/ADFSL patterns; Azure Backup and ASR.
Identity & governance: PIM, access reviews, basic Purview DLP/labels exposure for SMB; 3rd-party SSO app integrations.
Data Loss Protection (DLP): Deployment and management of process and technologies to protect sensitive information, experience with WISPs or SOC certifications.
SD-WAN/SASE concepts, DNS filtering, email security gateways, secure remote access brokers.
Certifications:
Microsoft Certifications or equivalent experience:
1. Required: MS-102: Microsoft 365 Administrator Expert
2. Additional Preferred:
SC-100: Microsoft Cybersecurity Architect Expert
SC-200: Security Operations Analyst Associate
SC-300: Identity and Access Administrator Associate
SC-401: Information Security Administrator Associate
AZ-104 Azure Administrator Associate
AZ-305: Azure Solutions Architect Expert
AZ-500: Azure Security Engineer Associate
PL-600: Microsoft Power Platform Solution Architect
MD-102: Endpoint Administrator Associate
Vendor Certifications or equivalent experience:
Sonicwall
VMWare / Hyper-V
Threatlocker
Kaseya Certified Technician in Datto Backup
Kaseya Certified Technician in K365 Endpoint
Kaseya Certified Technician in RocketCyber
Benefits:
Dental insurance
Health insurance
Paid time off
Vision insurance
Ability to Commute:
Reston, VA 20190 (Required)
Work Location: In person