Position:
Windows Systems Engineer (Windows Server/Active Directory/CyberArk) - Hybrid Porto (4 days/week office)
Company:
Not specified
Location:
Portugal, Porto
Employment type:
Not specified
Work Arrangement:
Hybrid (4 days/week office)
Short Summary:
Our client, a well-established organization operating critical financial market infrastructure, is looking for a Senior Windows Systems Engineer to join its Infrastructure & Security organization. This is a hands-on role operating and securing large, multi-domain Windows Server environments that underpin mission-critical financial systems.
Responsibilities:
- Ownership of multi-domain Active Directory environments, privileged access management, PKI services, server hardening, patching, and disaster recovery for production and DR environments.
- Day-to-day operations (domain controllers, GPOs, CyberArk vaults, certificate lifecycle, RDP/remote access security).
- Automation and continuous improvement through PowerShell, Ansible, and Terraform.
- Support Citrix session-based and VDI environments, participate in incident response and CAB processes, and monitor infrastructure health across a distributed, multi-country team.
Requirement:
- 5+ years of hands-on Windows Server administration, including Windows Server 2019 and 2022, domain controllers, clustering, and enterprise infrastructure.
- Advanced Active Directory experience in multi-domain environments: GPOs, LAPS, security groups, trusts, and identity lifecycle (JOINER/LEAVER) workflows.
- Hands-on CyberArk PAM and Password Manager Plus experience, including privileged account onboarding and vault administration.
- Intermediate to advanced PowerShell scripting skills.
- Experience with Ansible, Terraform, and infrastructure-as-code practices for cross-platform automation.
- Strong understanding of Windows security hardening, audit logging, vulnerability management, and compliance frameworks (CIS Benchmarks, NIST, etc.).
- Experience with RDP, NLA, Just-In-Time access, VPNs, TCP/IP, DNS, and Active Directory site topology.
- Experience with WSUS, SCCM, Patch Manager Plus, Ivanti, and automated software deployment.
- Experience with incident response, technical documentation, CAB procedures, and change management.
- Ability to work effectively with distributed teams across multiple countries and time zones.
- Minimum B2 (Upper Intermediate) English.
Benefits:
Not specified