وصف الوظيفة
نحن نبحث عن مهندس دعم بنية تحتية ذو خبرة من المستوى L3 لتقديم الإدارة المتقدمة والدعم وحل المشكلات لمنصة بنية تحتية للمؤسسات من مايكروسوفت، الرسائل، الافتراضية، إدارة نقاط النهاية، وأمن الأنظمة.
يتطلب الدور خبرة عملية في مايكروسوفت إكسچينج وتكنولوجيا خادم ويندوز، الدليل النشط، خدمات أزور، التعافي من الكوارث، الافتراضية، إصلاح الثغرات، وحلول الأمن المؤسسي.
سيكون المرشح المثالي مسؤولاً عن ضمان التوافر العالي، والأمن، والأداء، والامتثال للبنية التحتية المؤسسية مع التعاون مع فرق تكنولوجيا المعلومات وأمن السيبران المتعددة الوظائف.
المسؤوليات الرئيسية توفير إدارة ودعم المستوى L3 لخادم مايكروسوفت إكسچينج (إكسچينج 2019 SE) في بيئات هجينة مع مايكروسوفت 365.
إدارة وصيانة واستكشاف بنية خادم ويندوز، الدليل النشط، DNS، DHCP، سياسات المجموعة (GPO)، ADFS، وتزامن Entra Connect.
إدارة إكسچينج بما في ذلك إدارة صناديق البريد، مراقبة صحة DAG، استكشاف مشاكل النقل، تدفق البريد الهجين، وتكامل Enterprise Vault.
إدارة منصات أمان البريد الإلكتروني المؤسسي بما في ذلك Cisco IronPort ESA، Trellix FireEye Mail Security، CodeTwo لحلول التوقيع البريدي.
إدارة حلول DDI بما في ذلك EfficientIP و Infoblox لـ DNS و DHCP وIPAM.
تخطيط وتنفيذ والتحقق وتوثيق تمارين التعافي من الكوارث لئإكسچينج والدليل النشط وخوادم ويندوز والبنية التحتية الداعمة لضمان استمرارية الأعمال.
إدارة بنية افتراضية بما في ذلك VMware vSphere و ESXi و VxRail و Nutanix HCI، بما في ذلك التزويد والترحيل وتحسين الأداء واستكشاف الأخطاء وإسقاط النُظم.
إدارة Microsoft Entra ID (Azure AD)، Azure PIM، الوصول الشرطي، RBAC، التطبيقات المؤسسية، تسجيل التطبيقات، وتسجيل الدخول الأحادي (SSO).
إدارة Microsoft Intune (MDM/MAM) لامتثال الأجهزة، ونشر التطبيقات، وتكوين نقاط النهاية.
إدارة حلول أمان Microsoft Defender والتعاون مع فرق الأمن السيبراني بشأن مبادرات الأمن ومتطلبات الامتثال.
إدارة تثبيت تصحيحات خادم Windows، ونشر التطبيقات، ودورة حياة نقطة النهاية باستخدام ManageEngine Endpoint Central وPDQ Deploy.
إدارة حلول ManageEngine بما في ذلك ADManager Plus وAD360 وExchange Reporter Plus وOpManager لإدارة الهوية والتقارير والمراقبة والصحة التشغيلية.
إجراء تقوية أمان خادم Windows باستخدام قواعد الأمان من Microsoft وأفضل ممارسات سياسات المجموعة.
تحديد وتحليل وأولوية ومعالجة الثغرات في بنية Windows التحتية باستخدام تقارير إدارة الثغرات Qualys وتوصيات أمان Microsoft.
التنسيق مع فرق الأمن السيبراني لتنفيذ ضوابط الأمان ومعايير الامتثال وأنشطة معالجة الثغرات.
مراقبة أداء الخادم والسعة والتوفر والصحة التشغيلية عبر البنية التحتية المؤسسية.
دعم حلول النسخ الاحتياطي والاسترداد واستمرارية الأعمال إلى جانب فريق Veeam Backup.
إدارة أدوات أمان المؤسسات بما في ذلك حلول أمان الطرف النهائي من Trend Micro و McAfee.
إنشاء نصوص أتمتة باستخدام PowerShell لتبسيط الإدارة الروتينية والمراقبة والتقارير والمهام التشغيلية.
دعم عمليات مركز البيانات وتنسيق الموردين والترقيات والهجرات وأنشطة إدارة التغيير.
إعداد الوثائق الفنية والإجراءات التشغيلية القياسية (SOPs) ومقالات المعرفة ودفاتر التشغيل.
المشاركة في إدارة الحوادث الكبرى وتحليل السبب الجذري (RCA) وإدارة المشكلات ومبادرات التحسين المستمر للخدمة.
بنية Windows و Microsoft Exchange Server 2019 SE وMicrosoft 365 Hybrid Exchange وإدارة خادم Windows وخدمات الدليل النشط وسياسات المجموعة (GPO) وDNS وDHCP وADFS وMicrosoft Entra ID (Azure AD) و Entra Connect وAzure PIM والتحكم بالوصول الشرطي والRBAC والتطبيقات المؤسسية وتسجيل التطبيقات وتسجيل الدخول الأحادي ونظام أمن البريد الإلكتروني - Cisco IronPort ESA وTrellix FireEye Email Security وEnterprise Vault لـ Exchange وإدارة الأجهزة وتحديثها وMicrosoft Intune (MDM/MAM) وإدارة Defender وManageEngine Endpoint Central والافتراضية والبنية التحتية - VMware vSphere وNutanix HCI وت provisioning دورة حياة الخادم وأدوات إدارة الهوية وتخطيط التهجئة وإدارة الثغرات، والتقييم والاسترداد من الكوارث، وضبط الأداء والسعة، والأتمتة عبر PowerShell.
Job description
We are seeking an experienced Infrastructure L3 Support Engineer to provide advanced administration, support, and troubleshooting for enterprise Microsoft infrastructure, messaging, virtualization, endpoint management, and security platforms.
The role requires hands-on expertise in Microsoft Exchange, Windows Server technologies, Active Directory, Azure services, disaster recovery, virtualization, vulnerability remediation, and enterprise security solutions.
The ideal candidate will be responsible for ensuring high availability, security, performance, and compliance of enterprise infrastructure while collaborating with cross-functional IT and Cyber Security teams.
Key Responsibilities Provide L3 administration and support for Microsoft Exchange Server (Exchange 2019 SE) in hybrid environments with Microsoft 365.
Administer, maintain, and troubleshoot Windows Server infrastructure, Active Directory, DNS, DHCP, Group Policies (GPO), ADFS, and Entra Connect synchronization.
Exchange administration including mailbox management, DAG health monitoring, transport troubleshooting, hybrid mail flow, and Enterprise Vault integration.
Manage enterprise email security platforms including Cisco IronPort Email Security Appliance (ESA), Trellix FireEye Email Security, CodeTwo email signature solutions.
Administer DDI solutions including EfficientIP and Infoblox for DNS, DHCP, and IP Address Management (IPAM).
Plan, execute, validate, and document Disaster Recovery (DR) drills for Exchange, Active Directory, Windows Servers, and supporting infrastructure to ensure business continuity.
Manage virtualization infrastructure including VMware vSphere, ESXi, VxRail, and Nutanix HCI, including provisioning, migrations, performance tuning, troubleshooting, and decommissioning.
Administer Microsoft Entra ID (Azure AD), Azure PIM, Conditional Access, RBAC, Enterprise Applications, App Registrations, and Single Sign-On (SSO).
Manage Microsoft Intune (MDM/MAM) for device compliance, application deployment, and endpoint configuration.
Administer Microsoft Defender security solutions and collaborate with Cyber Security teams on security initiatives and compliance requirements.
Manage Windows Server patching, application deployment, and endpoint lifecycle using ManageEngine Endpoint Central and PDQ Deploy.
Administer ManageEngine solutions including ADManager Plus, AD360, Exchange Reporter Plus, and OpManager for identity management, reporting, monitoring, and operational health.
Perform Windows Server hardening using Microsoft security baselines and Group Policy best practices.
Identify, analyze, prioritize, and remediate Windows infrastructure vulnerabilities using Qualys Vulnerability Management reports and Microsoft security recommendations.
Coordinate with Cyber Security teams to implement security controls, compliance standards, and vulnerability remediation activities.
Monitor server performance, capacity, availability, and operational health across enterprise infrastructure.
Support backup, recovery, and business continuity solutions along with Veeam Backup team.
Administer enterprise security tools including Trend Micro and McAfee endpoint security solutions.
Create automation scripts using PowerShell to streamline routine administration, monitoring, reporting, and operational tasks.
Support data center operations, vendor coordination, infrastructure upgrades, migrations, and change management activities.
Prepare technical documentation, standard operating procedures (SOPs), knowledge articles, and operational runbooks.
Participate in major incident management, root cause analysis (RCA), problem management, and continuous service improvement initiatives.
Microsoft Windows Infrastructure Microsoft Exchange Server 2019 SE and Microsoft 365 Hybrid Exchange Windows Server Administration Active Directory Domain Services and Group Policy (GPO) DNS, DHCP, ADFS Microsoft Entra ID (Azure AD) and Entra Connect Azure PIM, Conditional Access and RBAC Enterprise Applications & App Registrations Messaging & Email Security - Cisco IronPort Email Security Appliance (ESA) & Trellix FireEye Email Security Enterprise Vault for Exchange Endpoint & Patch Management Microsoft Intune (MDM/MAM) Microsoft Defender ManageEngine Endpoint Central Virtualization & Infrastructure - VMware vSphere & Nutanix HCI Server Provisioning & Lifecycle Management Identity & Management Tools - ManageEngine Tools Security & Vulnerability Management, Windows Server Hardening & Microsoft Security Baselines Vulnerability Assessment & Remediation Disaster Recovery Planning & Testing Performance Tuning and Capacity Management Scripting and PowerShell Automation