Systems Engineer
Systems Engineer
Lane H - J Contract and Benefits
250 Day Contract
Starting Date: 7/1/2027
Hours a day: 8
Hourly rate: $42.59 - $51.19
Contact Information:
- Name: Marc Porter
- Phone: 801-610-8014
- Email: marcporter@aspenpeaks.org
Position Summary
The Systems Engineer owns the design, security, and administration of the district's identity, endpoint, email security, and cloud collaboration platforms. This role administers Active Directory and domain security, manages hybrid identity across the district's cloud collaboration and productivity platforms (such as Google Workspace and Microsoft 365/Azure), runs user provisioning through the district's identity/access management platform (such as RapidIdentity), secures email through the district's email security platform (such as Proofpoint), and manages endpoint security and device management via platforms such as JAMF and SCCM. The Systems Engineer also supports public records requests, investigations, and litigation holds in coordination with district administration and legal counsel, and shares server/virtualization (such as VMware) responsibilities with the Network Engineering team. This position works closely with the Security Engineer and Network Engineer to maintain compliance with district IT standards and may assist the Network Architect on systems architecture planning.
Reports to: Director of Innovative Engineering | FLSA Status: Exempt
Key Responsibilities
Identity & Directory Services
- Administer Active Directory domain services, including organizational units, Group Policy Objects, delegation, trusts, replication, and DNS/DHCP integration.
- Design, implement, and audit domain security controls — Group Policy hardening, privileged access management, security baselines, and periodic access reviews.
- Administer user provisioning and identity lifecycle management through the district's identity/access management platform (such as RapidIdentity), including automated account creation, role-based access, deprovisioning, and password policy enforcement.
Cloud & Collaboration Platforms
- Administer the district's cloud collaboration platform (such as Google Workspace), including organizational units, groups, admin console policies, and data-sharing controls.
- Administer the district's cloud identity and productivity platform (such as Microsoft 365 and Azure/Entra ID), including hybrid identity, conditional access, and licensing — primarily as an authentication source and for web-based productivity app access.
- Implement and maintain single sign-on (SSO) federation with the district's cloud collaboration platform and third-party applications via SAML.
Email & Endpoint Security
- Configure, monitor, and maintain the district's email security and threat protection platform (such as Proofpoint) to prevent phishing, malware, and data loss.
- Administer endpoint security and device management platforms (such as JAMF and Microsoft Endpoint Configuration Manager/SCCM) to keep devices patched, compliant, and protected.
- Investigate security incidents involving user accounts, endpoints, or cloud services — account compromise, data exfiltration, and policy violations — and lead containment and remediation.
Records, Investigations & Compliance
- Support public records requests, investigations, and litigation holds, preserving and producing electronic records in coordination with district administration and legal counsel.
- Ensure identity, endpoint, and communication systems remain compliant with GRAMA and other applicable records retention and disclosure requirements.
Infrastructure
- Assist with district server and virtualization administration (such as VMware vSphere/vCenter), storage, alongside the Network Engineering team.
- Support backup and disaster recovery operations and testing using the district's backup platform (such as Veeam).
- Monitor domain controllers, identity services, email security, and endpoint management platforms for availability and performance.
Documentation, Support & Training
- Develop and maintain internal documentation, standard operating procedures, and system diagrams for supported platforms.
- Provide training and technical guidance to staff on identity, endpoint, and collaboration systems.
- Respond to help desk requests and escalations across ticketing, email, and chat channels.
- Research emerging technologies in identity, endpoint, and cloud security, and recommend infrastructure improvements.
- Prepare technical documentation, procedures, and reports as needed.
- Perform other related duties as assigned.
Qualifications
Education & Experience
- Bachelor's degree in Information Technology, Computer Science, or a related field preferred.
- Equivalent professional experience in systems, identity, or endpoint administration will be considered in lieu of a degree.
- Hands-on experience administering Active Directory, Microsoft 365/Azure, and Google Workspace in an enterprise or district environment.
- Experience with identity/access management platforms, email security gateways, and endpoint management/MDM tools.
Preferred Certifications (examples — one or more relevant to the role)
- CompTIA Security+
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft 365 Certified: Administrator Expert (MS-102)
- JAMF Certified Admin
- Google Workspace Administrator Certification
Work Environment
- Primarily office-based work: approximately 80% sitting, 10% walking, 10% standing.
- Occasional lifting, carrying, and equipment handling; fine finger dexterity required for hardware and workstation support.
- Clean, climate-controlled office and server room environments.
Additional Requirements
- Valid driver's license and evidence of insurability.
- Annual district technology training.
- Criminal justice fingerprint/background clearance.
- Maintenance of required certifications and licenses.