CDIPorto, Portugal

Windows System Engineer

Hybride
Contexte de la mission

⚠️ Hybrid 4x/week in Office, Porto

We are looking for a Windows Systems Engineer to operate and secure large, multi-domain Windows Server environments supporting financial market infrastructure.

The role combines Windows Server administration, Active Directory, privileged access management, PKI, server hardening, patching, Citrix, disaster recovery, monitoring, and PowerShell automation. The engineer will work across Network, Security, DevOps, and IAM teams in a multi-geography environment.

The profile must bring at least 5 years of advanced Windows Server experience, strong multi-domain Active Directory knowledge, hands-on CyberArk experience, and practical expertise with patching, security controls, remote access, and infrastructure automation.

Objectifs et livrables

- Administer multi-domain Active Directory environments, including domain controllers, GPOs, cross-domain trusts, LAPS, security groups, and JOINER/LEAVER workflows.
- Manage privileged access through CyberArk and Password Manager Plus.
- Maintain vaults, onboard privileged accounts for Windows and Linux servers, and connect privileged access workflows with authentication systems.
- Administer Windows Certificate Authority and PKI services.
- Manage the full SSL/TLS certificate lifecycle, including certificate automation and renewal.
- Harden Windows Servers using CIS Benchmarks, PingCastle, ANSSI guidance, NIST frameworks, Microsoft recommendations, and Group Policy enforcement.
- Secure remote access through RDP hardening, Network Level Authentication, Just-In-Time administration, and VPN integration.
- Plan and execute Windows Server patching and software deployment with WSUS, SCCM, Patch Manager Plus, and Ivanti.
- Write PowerShell scripts and deployment workflows for automated patching, compliance reporting, software distribution, and emergency fixes.
- Support Citrix session-based and VDI environments, including application publishing and troubleshooting.
- Maintain disaster recovery and business continuity procedures for production and DR environments.
- Participate in failover tests and backup validation.
- Monitor server performance, capacity, and operational health through tools such as LogicMonitor, WhatsUP Gold, PagerDuty, Coralogix, and Azure Log Analytics.
- Maintain accurate technical documentation and work with Network, Security, DevOps, and IAM teams.
- Participate in incident response, change management, CAB processes, and operational improvement activities.

Experience Required

- 5+ years of hands-on Windows Server administration experience.
- Strong experience with Windows Server 2019 and 2022, domain controllers, clustering, and enterprise infrastructure.
- Advanced Active Directory experience in multi-domain environments.
- Practical knowledge of GPOs, LAPS, security groups, trusts, and identity lifecycle workflows.
- Hands-on experience with CyberArk PAM, Password Manager Plus, privileged account onboarding, and vault administration.
- Intermediate to advanced PowerShell scripting skills.
- Experience with Ansible, Terraform, and infrastructure-as-code practices for cross-platform automation.
- Strong understanding of Windows security hardening, audit logging, vulnerability management, and compliance frameworks.
- Experience with RDP, NLA, Just-In-Time access, VPNs, TCP/IP, DNS, and Active Directory site topology.
- Experience with WSUS, SCCM, Patch Manager Plus, Ivanti, and automated software deployment.
- Experience with incident response, technical documentation, CAB procedures, and change management.
- Ability to work with distributed teams across several countries and time zones.

Contact

- costa.neto@littlebigconnection.com
- +351 21 020 9908 (Tel. & WhatsApp)

Informations de la mission :
  • Début de mission : 29/07/2026
  • Durée : 6 mois
  • Date de publication : 29/07/2026
  • Date limite de candidature : 28/08/2026

Compétences recherchées

Windows Server (Indispensable)Active Directory (Indispensable)CyberArk (Indispensable)Password Manager Plus (Indispensable)PowerShell (Indispensable)Citrix (Indispensable)PKI (Indispensable)SSL/TLS (Indispensable)LAPS (Indispensable)GPO (Indispensable)WSUS (Indispensable)SCCM (Indispensable)Patch Manager Plus (Indispensable)Ivanti (Indispensable)Ansible (Indispensable)Terraform (Indispensable)LogicMonitor (Indispensable)WhatsUP Gold (Indispensable)PagerDuty (Indispensable)Coralogix (Indispensable)Azure Log Analytics (Indispensable)Git (Indispensable)YAML (Indispensable)Python (Indispensable)RDP (Indispensable)NLA (Indispensable)VPN (Indispensable)TCP/IP (Indispensable)DNS (Indispensable)CIS Benchmarks (Indispensable)PingCastle (Indispensable)ANSSI (Indispensable)NIST (Indispensable)PowerShell scripting and automation (Indispensable)Windows Server hardening and security compliance (Indispensable)Infrastructure AS Code Terraform And Ansible (Indispensable)Citrix administration and VDI support (Apprécié)and Azure Log Analytics (Apprécié)and Python scripting (Apprécié)CyberArk PAM and Password Manager Plus (Indispensable)Financial services or other regulated environments (Apprécié)Disaster recovery (Apprécié)failover testing (Apprécié)and backup validation (Indispensable)Windows Server 2019/2022 administration (Indispensable)multi-domain environments (Apprécié)trusts (Apprécié)and LAPS (Indispensable)Windows Certificate Authority and PKI (Indispensable)and Ivanti (Indispensable)SSL/TLS certificate lifecycle management (Indispensable)Just-In-Time access (Apprécié)and DNS (Indispensable)and Microsoft security guidance (Indispensable)English (Apprécié)Portuguese (Apprécié)

Intéressé(e) ?

Rejoignez l'équipe et participez à nos projets ambitieux.