Sr. System Engineer

Nexus Technologies
•Remote

About The Position

The L3 Systems Engineer is a hands-on senior engineering role within the NexusTek Engineering Center, the company's dedicated L3 Center of Excellence for the hybrid cloud stack. This role carries a deep, hire-in specialization in AWS, with Azure and GCP experience preferred and expected to grow on the job as the engineer supports environments across all three public clouds, plus on-premises infrastructure, for mid-market and enterprise managed services clients as well as internal projects and initiatives. As a member of the Engineering Center, this engineer owns the hardest problems alongside other L3 peers for the accounts they support: final-tier escalation resolution, root cause ownership, and platform-grade automation and standards across hybrid cloud environments. This is a fully remote position with limited travel.

Requirements

  • AWS specialization
  • Azure and GCP experience preferred and expected to grow on the job
  • Experience supporting environments across AWS, Azure, GCP, and on-premises infrastructure
  • Final-tier escalation resolution
  • Root cause ownership
  • Platform-grade automation and standards across hybrid cloud environments
  • Infrastructure as code experience is a plus
  • Support of containerized and serverless workloads (Amazon EKS, AWS Lambda) as part of modern, cloud-native platform delivery is a plus
  • Configure and maintain identity and access management controls (IAM, Active Directory/Entra ID, SSO, MFA) across cloud and hybrid environments.
  • Perform vulnerability remediation, audits, and compliance/audit-readiness activities relevant to client environments (e.g., CMMC 2.0, SOC 2, HIPAA).
  • Apply cloud security best practices, including encryption, centralized logging, and threat-detection tooling.
  • Monitor platform health, ticket SLAs, and service metrics; proactively identify and remediate issues before they escalate.
  • Build and maintain automated health checks, remediation playbooks, and DR/backup validation routines that reduce manual intervention over time.
  • Create and maintain runbooks, technical documentation, and procedure guides so knowledge is documented and shared, not single-threaded.
  • Review and perform cost optimization and rightsizing across managed cloud environments.
  • Serve as primary or secondary engineer on project work, including cloud migrations, infrastructure modernization, onboarding/offboarding, and lifecycle/EOL upgrades.
  • Participate in customer-facing calls and technical reviews as a senior engineer/subject-matter expert, including project SOW reviews and solutioning discussions.
  • Assist with customer onboarding and managed services transitions, including technical assessments, discovery, and project scoping.
  • Identify and submit new opportunities uncovered during the course of engineering engagements.
  • Contribute to the certification roadmap and internal Skill Builder Workshop program by building and delivering technical content that raises team-wide capability.
  • Provide mentorship and technical guidance to L1/L2 engineers — supporting them well is core to this team's mission.
  • Take ownership of improving processes, tools, and documentation; when something isn't working, take point on fixing it.
  • Communicate early and often on progress, blockers, and risk, and own mistakes quickly so the whole team can learn from them.
  • Participate in a rotational on-call schedule as an escalation engineer, engaged on P1/P2 incidents outside standard business hours when 24x7 L1/L2 cannot resolve them.
  • Acknowledge and respond to after-hours escalations per team SLA commitments, and hand off active incidents with full documentation at the close of the on-call window.
  • EC2, Auto Scaling & Compute Services
  • VPC & Hybrid/Cloud Networking
  • EKS & Container Orchestration
  • Lambda & Serverless (API Gateway / Step Functions)
  • S3 & Storage
  • Organizations / Multi-Account Architecture
  • CloudWatch
  • Microsoft Azure: core compute, storage, networking, and identity (Active Directory/Entra ID, SSO, MFA).
  • Google Cloud Platform: core compute, storage, and networking fundamentals.
  • Linux & Windows Server Administration
  • Hybrid Networking, Firewalls & VPN
  • Terraform / Infrastructure as Code
  • Ansible / Configuration Management
  • CI/CD Pipelines (Jenkins, GitLab CI, AWS CodePipeline)
  • Kubernetes & Docker
  • Monitoring & Observability (CloudWatch, LogicMonitor, N-Able, SIEM)
  • Backup & Disaster Recovery (Veeam/Commvault, replication, failover testing)
  • Scripting & Automation (Python, Bash, PowerShell)
  • Security & Compliance Frameworks (CMMC 2.0, SOC 2, HIPAA)

Nice To Haves

  • Azure and GCP experience
  • Infrastructure as code experience
  • Support of containerized and serverless workloads (Amazon EKS, AWS Lambda)
  • AWS Certified Solutions Architect – Associate or Professional
  • AWS Certified SysOps Administrator – Associate
  • AWS Certified DevOps Engineer
  • Microsoft Certified: Azure Administrator Associate (or equivalent)
  • Google Cloud Associate Cloud Engineer (or equivalent)

Responsibilities

  • Own resolution of escalated incident, service request, and alert tickets across SLA-bound and non-SLA queues.
  • Serve as the L3 escalation point for issues that exceed L1/L2 capability, taking ownership from intake through resolution and RCA closure as needed.
  • Handle direct engineer-to-engineer escalations and mentorship as they arise.
  • Partner with customer technical contacts on long-term solutions, lifecycle planning, and infrastructure health/remediation reviews — remotely, with no on-site presence required.
  • Design, deploy, and support scalable, secure, and highly available architectures across AWS, with growing scope across Azure, GCP, and on-premises compute infrastructure.
  • Support of containerized and serverless workloads (Amazon EKS, AWS Lambda) as part of modern, cloud-native platform delivery is a plus.
  • Streamline infrastructure delivery and reduce manual repetitive work.
  • Extend engineering depth into on-premises/hybrid infrastructure and secondary clouds (Azure, GCP) as client environments require — all delivered remotely.
  • Configure and maintain identity and access management controls (IAM, Active Directory/Entra ID, SSO, MFA) across cloud and hybrid environments.
  • Perform vulnerability remediation, audits, and compliance/audit-readiness activities relevant to client environments (e.g., CMMC 2.0, SOC 2, HIPAA).
  • Apply cloud security best practices, including encryption, centralized logging, and threat-detection tooling.
  • Monitor platform health, ticket SLAs, and service metrics; proactively identify and remediate issues before they escalate.
  • Build and maintain automated health checks, remediation playbooks, and DR/backup validation routines that reduce manual intervention over time.
  • Create and maintain runbooks, technical documentation, and procedure guides so knowledge is documented and shared, not single-threaded.
  • Review and perform cost optimization and rightsizing across managed cloud environments.
  • Serve as primary or secondary engineer on project work, including cloud migrations, infrastructure modernization, onboarding/offboarding, and lifecycle/EOL upgrades.
  • Participate in customer-facing calls and technical reviews as a senior engineer/subject-matter expert, including project SOW reviews and solutioning discussions.
  • Assist with customer onboarding and managed services transitions, including technical assessments, discovery, and project scoping.
  • Identify and submit new opportunities uncovered during the course of engineering engagements.
  • Contribute to the certification roadmap and internal Skill Builder Workshop program by building and delivering technical content that raises team-wide capability.
  • Provide mentorship and technical guidance to L1/L2 engineers — supporting them well is core to this team's mission.
  • Take ownership of improving processes, tools, and documentation; when something isn't working, take point on fixing it.
  • Communicate early and often on progress, blockers, and risk, and own mistakes quickly so the whole team can learn from them.
  • Participate in a rotational on-call schedule as an escalation engineer, engaged on P1/P2 incidents outside standard business hours when 24x7 L1/L2 cannot resolve them.
  • Acknowledge and respond to after-hours escalations per team SLA commitments, and hand off active incidents with full documentation at the close of the on-call window.

Benefits

  • Four weeks of annual accrued PTO
  • Seven paid national holidays
  • Medical, dental, vision options
  • Company-paid life insurance, short and long-term disability
  • Voluntary benefits such as critical illness and accident
  • Voluntary Legal Shield and identity theft protection
  • Discretionary annual 401k match plan
  • Generous employee referral bonus plan
  • Employee Assistance Program
  • Access to over 90,000+ courses in ADP My Learning
  • StandOut employee engagement tools
  • Eligible to apply for a Pluralsight license
  • Eligible to apply for NexusTek Technical Academy or Leadership Academy
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service