Sr Systems Engineer

Father-Flanagan

Omaha (NE)

On-site

USD 95,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401K match
Tuition reimbursement
Professional development opportunities
Low-cost medical benefits

Job summary

Boys Town in Omaha, NE seeks a senior IT Systems Administrator to architect and operate IAM, M365, and hybrid cloud solutions across on‑prem and cloud environments.

You will manage Active Directory and Entra ID, RBAC and PIM, deploy MFA, support Exchange Online, SharePoint Online, OneDrive, and lead migrations to SharePoint Online, while safeguarding data with DLP and retention labeling.

Qualifications

  • 7+ years of enterprise IT systems administration experience.
  • Strong expertise in AD/Entra ID and MFA deployments.
  • Experience with M365 tenant administration and security.
  • Experience with on-prem and cloud identity and access management.

Responsibilities

  • Administers Active Directory, Entra ID, and IAM for HR system integration.
  • Configures security controls, MFA, conditional access for external partners.
  • Maintains Microsoft 365 tenants including Exchange Online, SharePoint, Teams.
  • Migrates data from on-prem to SharePoint Online/OneDrive.
  • Manages VMware vSphere/ESXi and Hyper‑V environments.
  • Configures SAN storage (Fibre Channel) and vSAN.

Skills

Active Directory
Entra ID
Microsoft 365
PIM
RBAC
PowerShell
VMware vSphere/ESXi
Hyper-V
vSAN
Fibre Channel SAN

Education

Bachelor's degree in IT or related field

Tools

VMware vSphere/ESXi
Microsoft Hyper-V
SCVMM
Azure AD Connect

Job description

Architects, engineers, and administrates cloud and on-premises system solutions. Primary responsibilities will be supporting identity and access management (IAM) systems, Microsoft 365 solutions, virtualized server infrastructure, storage area network (SAN) environments, and operating systems.MAJOR RESPONSIBILITIES & DUTIES:Supports and Ensures Integrity and Security for Identity Management and Security SystemsDeploys, maintains, upgrades, and resolves issues with Active Directory, Entra ID, and Identity and Access Management Systems for HR System integration to include support for joiner, mover, & termination processes, as well as role-based access and other automated processes.Supports Identity Management for 3rd party applications, Azure Enterprise Applications, to include securing access using conditional access and MFA (Multi Factor Authentication) systems.Designs and supports authentication methodologies including Radius, LDAPS, SAML, Kerberos, PAM (Privileged Access Management), and certificate-based authentication.Designs, installs, and maintains the enterprise certificate environment.Works with Information Security to implement proper controls and security measures to protect local and cloud-based data.Deploys and Supports Microsoft 365, MS Modern Desktop, and Other SaaS SolutionsConfigures and supports Microsoft SaaS systems such as Exchange, SharePoint, and Teams.Architects the migration of on-premises files and data to SharePoint Online and OneDrive. Supports and secures data in SharePoint and OneDrive.Implements DLP (Data Loss Prevention), sensitivity, and retention labeling to maintain integrity and security of data with guidance from Information Security.Serves as the senior administrator for one or more Microsoft 365 tenants, with direct responsibility for tenant configuration, security posture, licensing management, and service health across the M365 suite including Exchange Online, SharePoint Online, Teams, OneDrive for Business, and Intune.Manages M365 identity and access governance including role-based access control (RBAC), privileged identity management (PIM), guest/external access policies, and cross-tenant collaboration settings.Oversees Exchange Online administration including mail flow rules, connectors, anti-spam/anti-phishing policies, shared mailboxes, distribution groups, and hybrid mail routing where applicable.Administers Microsoft Teams governance including team lifecycle policies, meeting configurations and compliance recording where required.Monitors tenant health, service incidents, and adoption metrics through the M365 Admin Center and Defender portals, driving proactive resolution of issues and escalating with Microsoft Support as warranted.Supports System Administrators with Endpoint Management and Security solutions for Windows workstation and servers, Android, and iOS devices.Assists System Engineers in the design and implementation of systems to manage security at the server operating system level, including hardening and patches.Responsible for Azure, AWS, and GCP Public Cloud platforms including identity, security, policy management, and cost allocation.Designs, implements, and manages other cloud SaaS Systems to reduce enterprise costs & complexity, while increasing reliability.Manages Active Directory and On-Premises Identity InfrastructureOwns and administers the on-premises Active Directory environment, including domain and forest architecture, domain controller deployment and health, AD sites and services, replication topology, and Group Policy infrastructure.Designs and maintains Group Policy Objects (GPOs) for security baselines, software deployment, user environment management, and compliance enforcement across workstations and servers.Manages AD trust relationships, organizational unit (OU) structure, delegation of control, and role-based administrative access in alignment with least-privilege principles.Administers and maintains Microsoft Entra ID (Azure AD) Connect, overseeing hybrid identity synchronization, password hash sync or pass-through authentication, and seamless SSO configurations between on-premises AD and M365.Leads identity lifecycle management processes including provisioning, de-provisioning, access reviews, and privileged account governance spanning both on-premises AD and Entra ID.Monitors AD health and security through tools such as Microsoft Defender for Identity, ensuring detection and response to suspicious authentication activity, lateral movement, or privilege escalation attempts.Maintains AD disaster recovery capabilities including authoritative and non-authoritative restore procedures, domain controller backup validation, and documented recovery runbooks.Manages and Supports Virtualized Server EnvironmentServes as the primary subject matter expert and administrator for a hybrid virtualized environment spanning both VMware vSphere/ESXi and Microsoft Hyper-V platforms, ensuring high availability, performance, and security across all hypervisor hosts and guest workloads.Designs, deploys, and maintains VMware vSphere clusters including vCenter Server, ESXi hosts, vMotion, High Availability (HA), Distributed Resource Scheduler (DRS), and Fault Tolerance configurations.Administers Microsoft Hyper-V environments including failover clustering, Live Migration, Hyper-V Replica, and integration with System Center Virtual Machine Manager (SCVMM) where applicable.Leads capacity planning efforts across both platforms, analyzing resource utilization trends and making recommendations for infrastructure scaling, consolidation, or refresh.Develops and enforces standards, policies, and procedures for VM provisioning, template management, snapshot governance, and lifecycle management across VMware and Hyper-V environments.Administers vSAN and Fibre Channel SAN Storage InfrastructureArchitects, deploys, and administers VMware vSAN clusters, including disk group configuration, storage policies, deduplication and compression settings, fault domain design, and health monitoring.Manages and maintains Fibre Channel SAN infrastructure end-to-end, including zoning, LUN provisioning and masking, HBA configuration, and fabric switch administration (Brocade/Cisco MDS).Oversees SAN connectivity for both VMware and Hyper-V hosts, ensuring proper multipathing (VMware NMP/PSP policies and Windows MPIO), path redundancy, and failover validation.Monitors SAN and vSAN performance, diagnoses and resolves storage latency, throughput, and connectivity issues, and coordinates with vendors on hardware support and firmware management.Maintains storage architecture documentation including SAN fabric topology, zoning configurations, LUN mappings, and vSAN cluster layouts.Configures and Maintains Base Network Infrastructure for Virtualized EnvironmentsConfigures and manages virtual networking components within both VMware (vSphere Standard and Distributed Switches, port groups, uplink teaming policies) and Hyper-V (Virtual Switches, NIC teaming, SR-IOV) environments.Collaborates with network engineering teams on the integration of virtual infrastructure with physical switching, routing, and Fibre Channel fabric to ensure end-to-end connectivity and redundancy.Installs and troubleshoots TCP/IP support infrastructure including DHCP, DNS (Domain Name System), and other IP-based technologies.Designs and Implements System SolutionsCollaborates with operation staff to ensure smooth and reliable operation of software and systems for fulfilling business objectives and processes; works with executive team members, decision makers, and stakeholders to define business requirements and systems goals, and to identify and resolve business systems issues.Builds and maintains complex real time monitoring systems to monitor critical business applications, alert key personnel in the event of failure, and perform trending and capacity analysis.Participates in Business Continuity and Disaster Recovery design, implementation, and testing.Creates and maintains documentation as it relates to system configuration, mapping, processes, and service records.Maintains technical adherence to external compliance mandates and assists in the development of policies and procedures.Drives infrastructure automation and operational efficiency through scripting (PowerCLI, PowerShell) and integration with infrastructure-as-code or orchestration toolsets.Mentors junior systems staff on virtualization best practices, storage fundamentals, and operational procedures.KNOWLEDGE, SKILLS & ABILITIES:Knowledge of the practical application of engineering science and technology, including applying principles, techniques, procedures, and equipment to the design and production of technologies.Knowledge of applicable data privacy and security practices and laws.Ability to follow existing practices and develop new best practices and prescribed development methodologies in the performance of the above duties.Ability to conduct research into systems issues and products as required.Ability to communicate ideas in technical, business-friendly, and user-friendly language appropriate to both executive and managerial audiences.Strong customer service orientation.Ability to prioritize and execute tasks in a high-pressure, team-oriented, collaborative environment and to meet deadlines and multi-task while maintaining quality standards.High level of professionalism and interpersonal skills. Excellent critical thinking, analytical, and problem-solving skills.Ability to communicate in an articulate, professional manner and to build and sustain successful, professional relationships.General knowledge of network switches, firewalls, and routers.Excels in scripting languages such as PowerShell, PowerCLI, Java, or asp.net.REQUIRED QUALIFICATIONS:Minimum of 7 years of experience including systems administration, administering Windows-based systems and AD, RDP (Remote Desktop Protocol), Security and User Management, Disaster Recovery, and Documentation, and experience in software configuration management and advanced troubleshooting required.Demonstrated hands-on experience administering VMware vSphere/ESXi and Microsoft Hyper-V environments in a production setting required..Experience managing Fibre Channel SAN infrastructure including zoning, LUN management, and HBA configuration required.Experience with VMware vSAN architecture, configuration, and administration required.On-call (continuously or rotationally) to provide support required.PREFERRED QUALIFICATIONS:Bachelor's degree in Computer Science, Information Technology, related field, or equivalent preferred.Knowledge and experience with Identity and Access Management Systems preferred.Tenant Global Administrator for M365 experience preferred.VMware Certified Professional (VCP) or Microsoft Certified: Azure Administrator / Hybrid Administrator credentials preferred.Other Duties: This job description incorporates the essential functions and duties required for this position. However, other duties may be required and assigned at times and as determined by a supervisor in order to meet the needs of the organization.Serves as a role model in carrying out activities and behaviors that reflect the values and principles of the Boys Town mission.PHYSICAL REQUIREMENTS, EQUIPMENT USAGE, WORK ENVIRONMENT:Position is relatively sedentary in a normal office administrative environment involving minimum exposure to physical risks. Will use office equipment such as a computer/laptop, monitor, keyboard, and a general workstation set-up.Care and respect for others is more than a commitment at Boys Town – it is the foundation of who we are and what we do.At Boys Town, we cultivate a culture of belonging for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation, and delivers better business results.About Boys Town:Boys Town has been changing the way America cares for children and families since 1917. With over a century of service, our employees have helped us grow from a small boardinghouse in downtown Omaha, Nebraska, into one of the largest national child and family care organizations in the country. With the addition of Boys Town National Research Hospital in 1977, our services branched out into the health care and research fields, offering even more career opportunities to those looking to make a real difference.Our employees are our #1 supporters when it comes to achieving Boys Town's mission, which is why we are proud of their commitment to making the world a better place for children, families, patients, and communities. A unique feature for employees and their dependents enrolled in medical benefits are reduced to no cost visits for services performed by a Boys Town provider at a Boys Town location. Additional costs savings for the employee and their dependents are found in our pharmacy benefits with low to zero-dollar co-pays on certain maintenance drugs. Boys Town takes your mental health seriously with no cost mental health visits to an in-network provider. We help our employees prepare for retirement with a generous match on their 401K or 401K Roth account. Additional benefits include tuition reimbursement, parenting resources from our experts and professional development opportunities within the organization, just to name a few. Working at Boys Town is more than just a job, it is a way of life.This advertisement describes the general nature of work to be performed and does not include an exhaustive list of all duties, skills, or abilities required. Boys Town is an equal employment opportunity employer and participates in the E-Verify program. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and/or expression, national origin, age, disability, or veteran status. To request a disability-related accommodation in the application process, contact us at 1-877-639-6003.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Systems Engineer
Sr Systems Engineer

Father Flanagan's Boys' Home • United States

On-site
USD 100,000 - 140,000
Tuition reimbursement
401K match
Free visits to Boys Town physicians
Sr Systems Engineer
Sr Systems Engineer

Boys Town • Omaha (NE)

On-site
USD 85,000 - 120,000
Cloud Architect
Cloud Architect

Boys Town • Omaha (NE)

On-site
USD 120,000 - 180,000
Cloud Architect
Cloud Architect

Father Flanagan's Boys' Home • United States

On-site
USD 140,000 - 190,000
Mental health benefits
Tuition reimbursement
401K match
+2
Donor Relations Associate
Donor Relations Associate

Father-Flanagan • Omaha (NE)

On-site
USD 42,000 - 54,000
Tuition reimbursement
401(k) match
No-cost mental health visits
+1
Assistant Family Teacher
Assistant Family Teacher

Boys Town • Town of Florida (NY)

On-site
USD 40,000 - 55,000
401K with a generous match
Tuition reimbursement
Mental health visits at no cost
+1
Administrative Assistant - Early Education Programs
Administrative Assistant - Early Education Programs

Father Flanagan's Boys' Home • United States

On-site
USD 38,000 - 62,000
Tuition reimbursement
401K match
No-cost health visits with Boys Town
Development Project Specialist (On Site)
Development Project Specialist (On Site)

Boys Town • Omaha (NE)

Hybrid
USD 52,000 - 68,000
Contract System Administrator
Contract System Administrator

Father-Flanagan • Omaha (NE)

On-site
USD 70,000 - 95,000
401K match
Tuition reimbursement
Medical benefits
+1
IT Systems Administrator
IT Systems Administrator

Union-Community-Care • Lancaster

On-site
USD 90,000 - 120,000