Principal Enterprise Systems and Security Engineer

University of Colorado•Hybrid, CO
•$93,208 - $124,899•Hybrid

About The Position

The Colorado Clinical and Translational Sciences Institute (CCTSI), a clinical research institute located on the Anschutz Medical Campus, has an opening for a full-time Senior Enterprise Systems and Security Engineer. The Principal Enterprise Systems and Security Engineer is a hands-on individual contributor and senior technical lead responsible for directly administering, securing, troubleshooting, and improving CCTSI’s enterprise infrastructure. This position does not supervise staff and is not responsible for delegating the technical work described below. Reporting to the IT Manager, the position independently performs complex systems administration and security work, while serving as a subject matter expert and technical partner to ensure CCTSI systems are secure, reliable, scalable, and aligned with best practices for research and academic environments. We are seeking a collaborative, hands-on technology professional with expertise in enterprise systems administration and an interest in contributing to human health in an academic environment. The successful candidate will communicate effectively, share technical knowledge, maintain detailed documentation, develop a thorough understanding of CCTSI processes, and contribute practical solutions to a high-performing Informatics Services team. This position requires occasional evening, weekend, and on-call work and reports to the IT Manager of the CCTSI Informatics Services team.

Requirements

  • A bachelor’s degree in computer science, management/computer information systems, computer engineering, information technology, or a directly related field from an accredited institution and 3-5 years of professional experience in systems administration or infrastructure engineering
  • Experience directly administering and supporting enterprise server environments (Windows and/or Linux)
  • Experience with virtualization platforms (VMware, vSphere, ESXi)
  • Experience with system patching, monitoring, and data protection
  • Applicants must meet minimum qualifications at the time of hire.
  • Applicants must be legally authorized to work in the United States without requiring sponsorship. We are unable to provide work visa sponsorship and employment authorization for this position now or in the future.
  • Diplomatic disposition and customer service orientation with excellent written and verbal communication skills in the English language
  • Advanced understanding of enterprise infrastructure, security principles, and system architecture
  • Ability to assess risk and implement proactive mitigation strategies
  • Strong troubleshooting and problem-solving skills for complex environments
  • Ability to organize and execute multiple priorities in a fast-paced environment
  • Strong communication skills with both technical and non-technical stakeholders
  • Ability to develop documentation, standards, and best practices
  • Ability to travel between campus locations, including distances of up to one mile.
  • Ability to communicate effectively, both in writing and orally.
  • Ability to establish and maintain effective working relationships with employees at all levels throughout the institution.
  • Outstanding customer service skills.

Nice To Haves

  • 7+ years of experience in enterprise systems administration or engineering
  • Strong experience with: Security vulnerability management and remediation
  • System hardening and configuration standards
  • Network architecture, including segmentation and secure design
  • Identity and access management (LDAP, MFA integration)
  • Experience with database environments (SQL Server, MariaDB)
  • Experience with backup and recovery solutions (e.g., Veeam)
  • Experience working in regulated or research environments

Responsibilities

  • Configure, administer, patch, monitor, troubleshoot, and maintain enterprise infrastructure across Windows, Linux, and virtual environments
  • Build, configure, upgrade, and optimize VMware, ESXi, vCenter, and physical server infrastructure
  • Perform system performance tuning, capacity analysis, scalability planning, and high-availability configuration
  • Provide day-to-day administration and technical support for multi-datacenter infrastructure and hybrid environments
  • Perform vulnerability scanning, analyze findings, apply system hardening standards, and complete or coordinate remediation across all environments
  • Configure and maintain secure infrastructure controls, including network segmentation (ACI), DMZ configurations, firewall and access-control requirements, and least privilege permissions
  • Implement, test, troubleshoot, and maintain security controls, including MFA, TLS encryption, certificates, and secure authentication systems
  • Documentation for meeting or exceeding industry standards for environments containing Protected Health Information (PHI)
  • Partner with CU Anschutz OIT/ISS to ensure alignment with institutional security standards, audits, and compliance requirements
  • Monitor security alerts and emerging threats; investigate events, implement mitigations, and support incident response and recovery activities
  • Migrate away from unsupported and legacy platforms
  • Develop, document, apply, and maintain standards for system configuration, deployment, patching, monitoring, and security
  • Research, recommend, prototype, and implement infrastructure modernization improvements in coordination with the IT Manager
  • Provide technical analysis, recommendations, and hands-on implementation support to the IT Manager and Informatics leadership
  • Mentor and train staff and provide escalation support for complex system issues
  • Work alongside development teams to configure environments, diagnose application-infrastructure issues, and align application requirements with infrastructure and security standards
  • Work directly with external IT teams and vendors to implement, test, troubleshoot, and document infrastructure and security solutions
  • Perform occasional evening, weekend, and on-call work, including hands-on outage response, troubleshooting, and service restoration
  • Other duties as assigned
  • Maintain a four-day-per-week onsite work schedule

Benefits

  • health insurance
  • life insurance
  • retirement plans
  • tuition benefits
  • ECO pass
  • paid time off – vacation, sick, and holidays
  • Medical: Multiple plan options
  • Dental: Multiple plan options
  • Additional Insurance: Disability, Life, Vision
  • Retirement 401(a) Plan: Employer contributes 10% of your gross pay
  • Paid Time Off: Accruals over the year
  • Vacation Days: 22/year (maximum accrual 352 hours)
  • Sick Days: 15/year (unlimited maximum accrual)
  • Holiday Days: 15/year
  • Tuition Benefit: Employees have access to this benefit on all CU campuses
  • ECO Pass: Reduced rate RTD Bus and light rail service
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service