Cloud Server Engineer

TEEMA

Vancouver

On-site

CAD 83,000 - 110,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

TEEMA seeks a Cloud Server Engineer in Vancouver, BC to lead Windows Server builds, Azure IaaS, Arc deployment, Defender onboarding, and SCCM/MECM management. The role emphasizes security, governance, and proactive remediation across on‑premises and cloud platforms.

Ideal candidates bring 10+ years in Windows Server engineering, strong Azure experience, and PowerShell scripting skills, plus ITIL/ITSM awareness and enterprise scale deployment expertise.

Qualifications

  • 10+ years’ experience in Windows Server engineering, cloud infrastructure, or systems administration in complex environments.
  • Strong hands-on experience with Windows Server build, configuration, hardening, patching, and troubleshooting.
  • Hands-on Azure experience including Azure IaaS and Arc-enabled servers; Azure certifications (AZ-800 / AZ-104) are assets.
  • Experience deploying and managing Defender for Endpoint at enterprise scale, including onboarding, policy config, and troubleshooting.
  • Hands-on with SCCM/MECM for large-scale deployment, baselines, and client health.
  • PowerShell scripting for at-scale deployment, validation, and reporting.
  • Experience migrating antivirus/EDR products to Defender is a plus.
  • Knowledge of backup/restore, HA, and disaster recovery considerations.
  • Familiarity with ITIL/ITSM standards and CMDB practices.

Responsibilities

  • Assess the Windows Server estate, workloads, roles/features, and security onboarding readiness.
  • Build, configure, harden, test, and validate Windows Server environments on-premises and in Azure IaaS.
  • Support Azure IaaS activities including readiness, VM sizing, service evaluation, and hybrid connectivity.
  • Deploy and configure Azure Arc-enabled servers at scale with governance, policy, and Defender integration.
  • Maintain SCCM/MECM collections, device groups, deployment packages, and compliance baselines.
  • Plan onboarding to Microsoft Defender for Endpoint, including pilot and rollout, post-deployment validation.
  • Migrate from third-party antivirus/EDR to Defender, including exclusions and sequencing.
  • Configure Defender Antivirus, EDR, and related policies via Intune/MDM or Group Policy.
  • Triage onboarding issues, sensor health, and onboarding exceptions as needed.
  • Develop runbooks, onboarding plans, reports, and transition-to-operations materials.
  • Coordinate with multiple teams to align deployment sequencing, changes, and communications.

Skills

Windows Server engineering
Azure IaaS
Defender for Endpoint
SCCM/MECM
PowerShell scripting
ITIL/ ITSM

Education

Degree in computer science / information systems

Tools

Azure Arc
Intune
Configuration Manager (SCCM/MECM)
Microsoft Defender for Endpoint

Job description

Job Title: Cloud Server Engineer


Job ID: 90317


Location: Vancouver, British Columbia



What you will be doing: The consultant will support server build, configuration and hardening, Azure IaaS and hybrid platform work, Azure Arc deployment and governance, SCCM/MECM enrolment, Defender onboarding and policy configuration, antivirus and EDR migration, vulnerability remediation, monitoring, backup/restore validation, and transition support for critical Technology Services infrastructure.




  • Assess the current Windows Server estate, including operating system versions, workloads,roles/features, installed agents, dependencies, application owners, support models, and cloudand security onboarding readiness.


  • Build, configure, harden, test, and validate Windows Server environments on-premises and in


  • Azure IaaS in accordance with E-Comm standards, cybersecurity requirements, availability needs, and operational practices.


  • Support Azure IaaS activities including Azure readiness, VM sizing, evaluation of Azure services,landing zone dependencies, hybrid connectivity, identity integration, monitoring, backup, andoperational handoff.


  • Deploy and configure Azure Arc-enabled servers at scale, including onboarding scripts andservice principals, resource group and tagging conventions, agent health monitoring, AzurePolicy and governance, and the Microsoft Defender for Servers integration path.


  • Build and maintain SCCM/MECM collections, device groups, deployment packages,configuration items, and compliance baselines used for patching, agent distribution, andonboarding verification.


  • Plan and execute onboarding of servers and endpoints to Microsoft Defender for Endpoint,including prerequisite validation (updates and servicing levels, Defender platform and engineversions, connectivity to required service endpoints, proxy and TLS configuration, licensing andtenant assignment), pilot, wave-based rollout, and post-deployment validation.


  • Execute migration from third-party antivirus and endpoint protection products, including reviewand translation of existing exclusions, passive and active mode sequencing, uninstall ordisablement procedures, and confirmation that protection is maintained throughout thetransition.


  • Configure and tune Microsoft Defender Antivirus, EDR, cloud-delivered protection, attacksurface reduction rules, network protection, and tamper protection through Intune,Configuration Manager, or Group Policy as applicable.


  • Triage and remediate onboarding failures, unhealthy or inactive sensors, misreportedonboarding status, duplicate or stale device records, and servers requiring exception oralternative treatment.


  • Implement or validate server hardening, vulnerability remediation, logging, monitoring, accesscontrol, local administrator controls, privileged access practices, and baseline configuration.


  • Develop and maintain server inventories, onboarding trackers, wave plans, readiness reports,exception registers, technical risk registers, and reporting on onboarding coverage and sensorhealth.


  • Support integration with Active Directory, Entra ID / Azure AD, DNS, DHCP, certificates, Intuneand Configuration Manager, Microsoft Defender XDR, SIEM and log forwarding, monitoringtools, backup platforms, virtualization, storage, Azure services, ServiceNow, CMDB, and changemanagement processes.


  • Support resiliency and operational readiness for in-scope servers, including patching,backup/restore validation, recovery testing, and high availability considerations.


  • Develop technical runbooks for server build and configuration, Arc and Defender onboardingand offboarding, exclusion request handling, agent and sensor troubleshooting, patching,monitoring, and operational support.


  • Produce as-built documentation, configuration standards, implementation and rollout plans,validation evidence, rollback documentation, support procedures, and transition-to-operationsmaterials.


  • Coordinate with infrastructure, cybersecurity, application, cloud, identity, service desk,ServiceNow, vendor, and business teams to align deployment sequencing, change windows,testing, communications, and operational acceptance.


  • Support change management, release readiness, hypercare, incident remediation, knowledgetransfer, and sustainment following server and onboarding activities.




What you must have:



  • Minimum of 10 years’ experience in Windows Server engineering, cloud infrastructure, orsystems administration in complex, highly available environments.

  • Degree in computer science, information systems, or a related field, or an equivalentcombination of training and experience.

  • Strong hands-on experience with Windows Server build, configuration, hardening, patching, andtroubleshooting is required.

  • Demonstrated hands-on Azure experience is required, including Azure IaaS and Azure Arcenabled servers; Azure certifications (for example AZ-800 or AZ-104) are strong assets.

  • Demonstrated hands-on experience deploying and managing Microsoft Defender for Endpointat enterprise scale is required, including onboarding, policy configuration, sensor healthmanagement, and troubleshooting of failed onboarding.

  • Strong hands-on experience with Microsoft Configuration Manager (SCCM/MECM) for largescale deployment, collections, configuration baselines, and client health is required.

  • Experience migrating from third-party antivirus and EDR products to Microsoft Defender,including exclusion migration and coexistence or passive mode handling, is a strong asset.

  • Strong PowerShell scripting ability for at-scale deployment, validation, and reporting is required.

  • Security certifications (for example SC-200, MD-102, or SC-100) are assets.

  • Infrastructure as code (IaC) experience is not required but is considered an asset.

  • Experience working in highly available public safety environments is an asset.



Knowledge, Skills and Abilities



  • Knowledge of Windows Server architecture, roles/features, lifecycle, patching, and hardeningmethods.

  • Knowledge of Azure IaaS, VM sizing, hybrid connectivity, identity integration, and operationalhandoff.

  • Knowledge of Azure Arc-enabled servers, at-scale agent deployment, governance, and MicrosoftDefender for Servers plan and licensing considerations.

  • Knowledge of Microsoft Defender for Endpoint architecture, onboarding methods, sensorhealth, device groups, and the Microsoft Defender XDR portal.

  • Knowledge of Microsoft Configuration Manager (SCCM/MECM) collections, deployments,configuration baselines, and client health remediation.

  • Knowledge of antivirus and EDR concepts, including exclusions, passive mode and coexistence,tamper protection, attack surface reduction, and detection tuning.

  • Knowledge of server hardening, endpoint security baselines, vulnerability remediation, andbaseline configuration.

  • Knowledge of backup/restore validation, high availability, and disaster recovery considerationsfor server workloads.

  • Proficiency with Active Directory, Entra ID, Group Policy, DNS, DHCP, certificates, proxy andnetwork egress paths, monitoring tools, virtualization, storage, and PowerShell scripting.

  • Knowledge of ITIL and ITSM related standards and practices, including CMDB and changemanagement integration.

  • Knowledge of MS Visio, Teams, PowerPoint, and SharePoint.

  • Ability to respond to shifting priorities, demands, and timelines.

  • Ability to investigate and resolve complex infrastructure, endpoint, agent, and connectivityissues across a large and varied estate.

  • Ability to work effectively with multiple technical teams, vendors, and business stakeholders.

  • Ability to communicate effectively orally and in writing and to prepare clear, concise, andcomplete documentation.

  • Ability to maintain accurate records, decision logs, and technical documentation related to thework.



Salary/Rate: $70.00/ hour



Thank you for your interest in this opportunity. If you are selected to move forward in the process, we will contact you directly. If you do not hear from us, we encourage you to continue visiting our website for other roles that may be a good fit.



For more information about TEEMA and to consider other career opportunities, please visit our website at www.teemagroup.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Systems Administrator III (Windows)
Systems Administrator III (Windows)

Quantum Management Services Ltd. • Toronto

On-site
CAD 90,000 - 110,000
Systems Engineer - Managed Services
Systems Engineer - Managed Services

Triton Environmental Consultants, Ltd. • Winnipeg

On-site
CAD 90,000 - 120,000
Windows L3 Admin-5
Windows L3 Admin-5

Realign Llc • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Hybrid work arrangement
Cloud Engineer
Cloud Engineer

Northland Properties • Vancouver

On-site
CAD 90,000 - 110,000
Health/Dental/Vision
RRSP
Paid Time Off
+1
Senior Technical Analyst
Senior Technical Analyst

About Staffing • Calgary

On-site
CAD 75,000 - 100,000
Health benefits
Professional development support
Performance-based incentives
Windows Specialist
Windows Specialist

TechDoQuest • Toronto

On-site
CAD 90,000 - 120,000
Cloud Systems Administrator
Cloud Systems Administrator

Systematix • Vaughan

On-site
Confidential
Senior System Administrator
Senior System Administrator

Torus Talent • Vancouver

Hybrid
CAD 90,000 - 120,000
Senior Engineer- Software
Senior Engineer- Software

Marmon Technologies India Pvt Ltd • White Valley No. 49

On-site
CAD 120,000 - 160,000
System Administrator - Cloud
System Administrator - Cloud

NDT Global GmbH & Co. • Quebec

On-site
CAD 90,000 - 130,000