…

Systems Engineer (Wintel) - Swing Shift

GIA

  • GIA Services Private Limited (Navi, Mumbai)
  • On-site
  • Posted yesterday
  • Core Engineering

About the job

The Systems Engineer (Wintel) is an end-to-end infrastructure engineer responsible for the configuration, patching and day-to-day operation of the Windows Server estate and the on-premises platforms that run it. Scope spans traditional server and hardware, VMware vSphere, Nutanix hyperconverged infrastructure, HPE GreenLake consumption-based infrastructure, Dell Isilon scale-out NAS and enterprise SAN and NAS storage, together with Active Directory and the wider Windows & Linux platform services the organization depends on.

Strong Active Directory and domain knowledge is central rather than incidental. The role administers forest and domain structure, domain controllers, FSMO roles, replication, Group Policy, DNS, DHCP, certificate services and directory hygiene, and supports Entra ID hybrid identity including directory synchronization and hybrid device join in coordination with the engineer who owns tenant identity. The role also carries working knowledge of cloud infrastructure, administering Windows and Linux infrastructure-as-a-service workloads in AWS and Azure alongside the on-premises estate and applying the same build, hardening, patching and monitoring standards in both.

The engineer manages recurring patching cycles and the remediation activity supporting the enterprise vulnerability management program, with structured pre- and post-change validation, documented rollback and enforced change control. Working an assigned shift within a multidisciplinary infrastructure team in Navi Mumbai and reporting to the Manager IT Infrastructure for that shift, the role ensures the performance, security, availability and recoverability of business-critical systems, acts as second and third level escalation, hands over open work cleanly at shift boundaries, and provides technical guidance to less experienced engineers.

Key Responsibilities / Deliverables

Windows Server Estate and Compute Infrastructure

Provision, configure, harden and maintain Windows Server across the lifecycle from build through decommission, working to standardized images and documented build standards.
Administer physical compute and server hardware, including OEM servers, firmware and BIOS currency, out-of-band management, racking and cabling, and OEM support status.
Maintain and monitor system health through automated monitoring and manual checks, responding to alerts, capacity constraints and performance degradation before they become incidents.
Support the design and implement resilient on-premises infrastructure that meets performance, availability and scalability requirements.

Virtualization and Hyperconverged Infrastructure – Nutanix, VMware and HPE GreenLake

Administer Nutanix hyperconverged clusters, including cluster and node health, capacity, node addition and removal, and Life Cycle Manager firmware and software upgrades.
Administer VMware vSphere, including hosts, clusters, HA and DRS, vCenter, datastores, resource pools, virtual machine lifecycle, templates, snapshots and host maintenance.
Administer HPE GreenLake consumption-based infrastructure, including capacity and usage monitoring against contracted commitment and buffer, and coordination with HPE on capacity release, support and lifecycle.
Plan and execute cluster and hypervisor upgrades with validated rollback, and maintain interoperability across firmware, hypervisor and guest operating system levels.
Monitor virtualization capacity and performance, right-size workloads, and forecast growth against on-premises and contracted capacity ahead of constraint.

Enterprise Storage – Dell Isilon, SAN and NAS

Administer Dell Isilon and PowerScale scale-out NAS, including node and cluster health, access zones, SMB and NFS shares, quotas, snapshots and replication.
Administer SAN and NAS arrays, including volume and LUN provisioning, masking and zoning support, snapshots, replication and tiering.
Manage storage capacity planning and performance troubleshooting for the platforms in scope, and manage array firmware, lifecycle and support contracts.
Coordinate with the Storage and Backup Engineer on protection policy, restore and disaster recovery for the, so that new systems are protected at build rather than afterwards.

Active Directory, Domain and Windows Platform Services

Administer Active Directory, including forest and domain structure, domain controllers, FSMO roles, sites and services, replication health, organizational unit and group structure, and schema-affecting change.
Administer Group Policy, DNS and DHCP, including GPO design, testing and change control, DNS zones, records and conditional forwarders, and DHCP scopes, reservations and failover.
Maintain directory hygiene and privileged access, including tiering, service account governance, cleanup of stale and orphaned objects, and support for privileged access management and access reviews.
Support Microsoft Entra ID hybrid identity, including Entra Connect directory synchronization, sync error resolution, device registration and hybrid join, in coordination with the engineer who owns tenant identity.
Administer Active Directory Certificate Services, file and print services, shares, permissions and quotas, and Windows-based application and management services in coordination with application owners.
Execute domain lifecycle activity, including domain controller promotion and demotion, functional level raises, and domain or forest migration and consolidation.

Patching, Vulnerability Remediation and Change Control

Manage and execute recurring patching cycles for Windows Server, hypervisors, firmware and supporting on-premises infrastructure, in line with security and compliance timelines.
Remediate findings raised by the enterprise vulnerability management program, tracking items through to closure and reporting remediation status, risk acceptance and exceptions with agreed remediation dates.
Maintain hardening baselines such as CIS or equivalent, and detect and remediate configuration drift from baseline.
Perform structured pre-patch and post-patch validation covering services, applications and dependencies, and document the outcome of every cycle.
Follow and enforce change control, risk and impact assessment, tested rollback planning and coordination of maintenance windows with application owners and business stakeholders.
Author, maintain and improve detailed runbooks for patching, builds, upgrades, failovers and recovery so that work is repeatable, auditable and transferable across shifts.

Cloud Infrastructure – AWS and Azure

Administer infrastructure-as-a-service workloads in AWS and Microsoft Azure alongside the on-premises estate, including compute instances, disks and images, virtual networking, security groups and resource tagging.
Extend Windows Server and Active Directory practice into cloud, including domain-joined cloud servers, cloud-hosted domain controllers or managed directory services where deployed, DNS resolution across environments, and hybrid connectivity over VPN, Direct Connect or ExpressRoute.
Apply the same build, hardening, patching and monitoring standards to cloud servers as to on-premises servers, using Azure Update Manager, AWS Systems Manager or the enterprise tooling in use.
Support assessment, migration and rollback of workloads between on-premises and cloud, including the identity, network and protection consequences.
Monitor cloud consumption for the infrastructure in scope, and remove orphaned instances, disks and snapshots.

Resilience, Automation, Support and Shift Handover

Support backup, replication and disaster recovery for the platforms this role administers and participate in DR drills and restore testing with the Storage and Backup Engineer to confirm recoverability rather than assume it.
Develop PowerShell automation and infrastructure-as-code to eliminate repetitive administration and reduce configuration drift across the estate.
Act as second and third level support for complex Windows, virtualization, storage and cloud issues, troubleshooting through to root cause and liaising with vendors for problem resolution.
Work the assigned shift, complete a documented handover at shift end covering open incidents, in-flight changes, running maintenance and pending actions, and verify the handover received at shift start.
Provide technical guidance and mentoring to less experienced engineers, and maintain comprehensive documentation for procedures, configurations and technical workflows.

JOB COMPETENCIES (Skills & Abilities)

Windows Server depth: Advanced, practical administration covering build, configuration, hardening, performance tuning, clustering and troubleshooting across current and legacy Windows Server versions.
Directory services expertise: Strong hands-on Active Directory administration, including forest and domain design, domain controllers and FSMO roles, replication, Group Policy, DNS, DHCP and certificate services, with sound privileged access hygiene.
Hybrid identity understanding: Working command of Entra Connect synchronization, hybrid device join and the boundary between on-premises directory and cloud tenant identity.
Virtualization and HCI capability: Hands-on command of VMware vSphere and Nutanix, including cluster operations, upgrades and capacity, and of consumption-based infrastructure such as HPE GreenLake.
Storage capability: Practical administration of Dell Isilon or PowerScale and of enterprise SAN and NAS, including provisioning, replication, quotas and capacity.
Cloud infrastructure knowledge: Working command of AWS and Azure infrastructure-as-a-service, including compute, disks, virtual networking, security groups, hybrid connectivity and cloud server patching.
Hybrid judgement: Understands where a workload should sit, and can weigh performance, resilience, licensing and cost across on-premises, HCI, consumption-based and cloud infrastructure rather than defaulting to one.
Security orientation: Consistent patching and vulnerability remediation aligned to enterprise security and compliance requirements, including CIS hardening, drift remediation and exception handling with documented risk acceptance.
Operational discipline: Runbook-driven execution, adherence to change control, and thorough pre and post change validation with a tested rollback path.
Resilience focus: Treats recoverability as something proven by testing rather than assumed from a backup job that reports success and builds protection in at provisioning rather than after.
Automation mindset: Strong PowerShell proficiency, extended to infrastructure-as-code, used to eliminate repetitive administration and reduce configuration drift.
Capacity and cost discipline: Forecasts growth across computing, storage, HCI and cloud, and raises procurement or capacity release requirements ahead of constraint rather than at it.
Problem solving: Strong analytical skills with proven ability to identify root cause for complex issues spanning Windows, directory, virtualization, storage, cloud and network layers.
Vendor management: Holds OEM, HPE GreenLake, hypervisor and cloud vendors to support commitments, and escalates effectively on genuine platform defects.
Shift and handover discipline: Works effectively within a shift-based operating model and transfers ownership of open incidents, in-flight changes and running maintenance explicitly at shift boundaries.
Documentation and knowledge transfer: Clear, maintainable runbooks and technical documentation that reduce single-person dependency across shifts.
Communication: Excellent written and verbal communication in English, with the ability to coordinate maintenance windows and explain risk to application owners and business stakeholders.
Accountability and autonomy: Manages systems end to end, prioritizes across a broad surface, and makes sound technical decisions with limited information.
Leadership and mentoring: Provides guidance and technical leadership to less experienced engineers without holding formal authority.

MINIMUM QUALIFICATIONS (Knowledge & Experience)

Information Technology, Engineering or a closely related field, or equivalent professional experience. (Required)
7+ years of experience in systems engineering or systems administration, including substantial hands-on responsibility for a production Windows Server estate. (Required)
Demonstrated hands-on administration of Active Directory and related directory services, including forest and domain structure, domain controllers and FSMO roles, replication, Group Policy, DNS, DHCP and certificate services. (Required)
Demonstrated experience of domain lifecycle activity, such as domain controller promotion and demotion, functional level raises, or domain or forest migration and consolidation. (Required)
Demonstrated experience supporting Entra ID hybrid identity, including Entra Connect synchronization, sync error resolution and hybrid device join. (Required)
Demonstrated hands-on administration of VMware vSphere, including hosts, clusters, vCenter, datastores and host maintenance and upgrades. (Required)
Demonstrated hands-on administration of Nutanix hyperconverged infrastructure, including cluster health, capacity and Life Cycle Manager upgrades. (Required)
Demonstrated hands-on administration of enterprise storage, including Dell Isilon or PowerScale and SAN or NAS arrays, covering provisioning, replication, quotas and capacity management. (Required)
Experience operating consumption-based or as-a-service infrastructure such as HPE GreenLake, including capacity monitoring against contracted commitment. (Preferred)
Demonstrated hands-on experience administering infrastructure-as-a-service workloads in AWS or Microsoft Azure, including compute, storage, virtual networking and hybrid connectivity. (Required)
Demonstrated experience extending Windows Server and Active Directory practice into cloud, including domain-joined cloud servers, DNS resolution across environments and cloud server patching. (Required)
Demonstrated ownership of a recurring server patching cycle, including validation, exception governance and compliance reporting against defined standards. (Required)
Demonstrated experience remediating findings from an enterprise vulnerability management program, including tracking to closure and documented risk acceptance. (Required)
Experience with configuration hardening baselines such as CIS, and with detection and remediation of configuration drift. (Required)
Demonstrated experience operating within a formal change management process, including Change Advisory Board submission, rollback planning and post-implementation review. (Required)
Experience supporting backup, replication and disaster recovery, and participating in DR drills and restore testing. (Required)
Strong PowerShell scripting ability, with practical use of automation or infrastructure-as-code to reduce manual administration and configuration drift. (Required)
Experience working within a shift-based infrastructure team, including structured handover of open incidents and in-flight change. (Required)
Professional proficiency in spoken and written English, sufficient to coordinate with global infrastructure teams and to communicate with senior stakeholders. (Required)
Certification such as Microsoft Certified: Windows Server Hybrid Administrator Associate, VMware VCP-DCV, Nutanix NCP, or an AWS or Azure associate-level credential. (Preferred)
ITIL 4 Foundation, or equivalent demonstrated knowledge of incident, change and problem practice. (Preferred)

Disclaimer: This job description indicates in general terms, the type and level of work performed as well as the typical responsibilities of employees in this classification and it may be changed by management at any time. Other duties may also apply. Nothing in this job description changes the at-will employment relationship existing between the Company and its employees.