Island Capital Group LLC

IT - Network Operations - Senior Systems Administrator

Island Capital Group LLC Irving, Texas, United States

Real Estate · 51-200 employees

2 d ago
Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Systems Administrator manages enterprise infrastructure, including security operations, cloud platforms, network routing, and server maintenance. The role involves hands-on administration, incident triage, vendor coordination, and the creation of technical documentation for repeatable operational tasks.

What they look for

Azure Cisco Routing Network Security Microsoft Sentinel Microsoft Defender DNS Management Server Patching Aruba Networking Firewall Administration VPN Services Infrastructure Monitoring Vendor Management Technical Documentation Incident Triage Certificate Management System Administration

Requirements

Candidates must have at least 10 years of previous server or network administration experience. Proficiency in at least five core infrastructure areas such as Windows Server, VMWare, Cisco networking, or cloud security is required.

Full description

Role Summary

The Senior Systems Administrator / Senior Network Administrator manages enterprise infrastructure across security operations, cloud platforms, network routing, firewall and VPN services, monitoring systems, server patching, certificate and DNS workflows, and vendor support operations. The role combines hands-on administration with incident triage, technical documentation, support-case ownership, procurement and renewal coordination, and recurring maintenance execution. Recent activity shows direct ownership or active participation in Microsoft Sentinel and Defender monitoring, Cisco router and contract support, Constellix DNS changes, Aruba/HPE networking, Azure infrastructure, Equinix network-edge notices, GoAnywhere renewal support, printer security standards, and monthly server patching processes.

Core Duties and Responsibilities

Security Operations, Sentinel, and Defender

  • Investigate and triage security alerts: Review high-severity Sentinel and Microsoft Defender notifications, validate legitimacy, document response status, and close or monitor recurring alerts as appropriate.
  • Maintain security analytics and reporting: Create, refine, and run KQL queries and workbooks for sign-in, identity, retention, ingestion, lockout, vulnerability, and operational monitoring use cases.
  • Support retention and cost decisions: Analyze Log Analytics retention options, analytics retention versus long-term retention, ingestion volume, and cost impacts for security data storage.

Cloud Infrastructure and Network Security Administration

  • Administer Azure-hosted infrastructure: Support Azure infrastructure advisories, network security group policy compliance, virtual firewall dependencies, flow logging, and cloud network remediation tasks.
  • Coordinate firewall and VPN-impacting changes: Plan and communicate maintenance windows that may affect VPN connectivity, file-share access, and routing availability.
  • Maintain operational resilience: Review vendor maintenance notices and assess network impact for Equinix Network Edge and related infrastructure assets.

Cisco Routing, Licensing, Support, and Contracts

  • Manage Cisco routing platforms: Perform IOS XE image upgrades, validate install-mode boot state, confirm packages.conf/boot variables, collect show outputs, and coordinate with Cisco TAC or support assistants.
  • Resolve Cisco portal and entitlement issues: Work through Cisco Smart Account, contract access, CCW-Renewals, support case visibility, and software entitlement issues needed to obtain required IOS images or manage support records.
  • Support Cisco procurement/renewal lifecycle: Review Cisco order fulfillment and contract notification details, validate Smart Account assignment, track Cisco Catalyst 8200 service coverage, and coordinate with resellers such as GDT when contract visibility or device association is incorrect.
  • Maintain Cisco network service awareness: Support router, switch, VPLS data circuit, device, and subscription records as part of broader enterprise network administration.

Constellix DNS and Certificate Validation Management

  • Administer external DNS records: Use Constellix DNS as the company external DNS management platform, including domain and record updates when business, website, certificate, or redirect changes require DNS action.
  • Perform DigiCert DCV revalidation: Maintain and execute the DigiCert domain certificate revalidation procedure, including retrieving DCV tokens and updating _dnsauth CNAME records in Constellix.
  • Coordinate DNS changes with stakeholders: Schedule and perform CNAME changes with application or website owners, confirm timing, notify stakeholders when records are created or committed, and support post-change validation.
  • Document DNS procedures: Create or maintain KB documentation for Constellix and DigiCert workflows to support repeatable operations and reduce DNS change risk.

Network, Wireless, and Infrastructure Monitoring

  • Administer Aruba/HPE networking: Work with HPE/Aruba support on AP/certificate issues, update captive portal certificate usage, review Aruba advisories, and coordinate HPE support/contract follow-up.
  • Monitor and respond to infrastructure alerts: Use monitoring tools to detect certificate, device, network, and system alarms; suppress or validate alerts during maintenance; and confirm health after changes.
  • Support telecom and legacy network services: Maintain awareness of DNS, firewall, and service dependencies for Cisco Expressway/voice and other infrastructure services documented in KBs.

Server Operations, Patching, and Endpoint/Printer Security

  • Execute recurring server patching: Participate in monthly patch deployment work, including SCCM update group maintenance, Thursday-before-UAT update additions, pre/post checks, monitoring suppression, validation, and reporting.
  • Maintain secure endpoint and printer standards: Update printer hardening procedures, including protocols, TLS settings, SNMP communities, and scan-to-email behavior.
  • Track vulnerability remediation: Review vendor advisories and Defender vulnerability findings, and coordinate remediation paths across affected devices and platforms.

Vendor, Renewal, and Operational Coordination

  • Manage support cases and renewals: Coordinate with Cisco, HPE/Aruba, CDW, GDT, Fortra/GoAnywhere, Equinix, DigiCert, and other vendors to resolve support, licensing, portal, renewal, and maintenance issues.
  • Assist business and finance stakeholders: Support invoice/portal-access issues or operational requests that affect IT services and vendor account access.
  • Create and update KBs and runbooks: Develop practical documentation for repeatable administration, security, patching, DNS, certificate, and infrastructure tasks.

Recurring Task Matrix

Cadence

Recurring task

Outcome / deliverable

Representative evidence

Daily / ongoing

Review Sentinel, Defender, and infrastructure notifications.

Valid incident status, triaged alerts, monitoring notes, and closed or watched items.

Sentinel retention/cost messages; Defender/Sentinel monitoring threads.

Daily / ongoing

Monitor network, certificate, wireless, router, firewall, and service health.

Cleared alarms, validated devices, corrected certificate usage, or escalated support cases.

Aruba certificate case; Equinix maintenance notices; Cisco router boot case.

Weekly / as needed

Manage Cisco support, router software, contract, and entitlement issues.

Resolved TAC/support cases, software access, Smart Account visibility, and router upgrade validation.

Cisco service contract, IOS download, SR 700963971, order fulfillment, and contract notification emails.

Weekly / as needed

Perform or coordinate DNS changes in Constellix.

Committed DNS records, updated CNAME/DCV tokens, and stakeholder confirmation for post-change testing.

NAI/api CNAME requests and commits; DigiCert/Constellix KB.

Monthly

Support monthly server patching process.

Updated schedules, added newly released patches, monitored maintenance, validated post-patch health.

Monthly Server Patching Process and Procedures KB.

Monthly / periodic

Review Sentinel retention, ingestion, workspace usage, and long-term retention/search jobs.

Retention settings, cost estimates, workbook reporting, and operational recommendations.

Sentinel Data and Sentinel Data Retention threads.

Quarterly / renewal cycle

Review vendor renewals, contract coverage, support entitlements, and maintenance status.

Renewal input, contract coverage validation, and vendor follow-up until support records are correct.

Cisco contract notifications; Aruba maintenance renewal; GoAnywhere renewal quote.

As needed

Update operational KBs and security standards.

Current runbooks and procedures for printers, DNS/DCV, patching, and support workflows.

Printer hardening update; Constellix/DigiCert KB; patching KB.

Cisco and Constellix/DNS Emphasis

Cisco

  • Router upgrade and boot validation: Recent Cisco support work involved upgrading a router through install mode, confirming the device booted correctly, validating BOOT variable and packages.conf, and providing requested outputs before asking Cisco to close the case.
  • Contracts and Smart Account administration: Recent activity included troubleshooting Cisco contract access, CCW-Renewals visibility, Smart Account assignment, software entitlement, order fulfillment, and service coverage for Catalyst 8200-related purchases.
  • Vendor coordination: Cisco support work required coordination with Cisco support channels and GDT personnel to address portal access, contract mapping, support visibility, and required software-image availability.

Constellix DNS Management

  • External DNS platform ownership: FileShare KB evidence identifies Constellix DNS as the company platform for external DNS records, with individual administrator credentials and a warning to document and verify changes because DNS mistakes can affect websites or mail flow.
  • DigiCert DCV procedure ownership: DigiCert revalidation documentation describes retrieving a new token in DigiCert CertCentral, updating the _dnsauth CNAME record in Constellix, applying and committing changes.
  • Operational DNS execution: Recent email evidence shows business-driven CNAME work for api.naiglobal.com, including scheduling the change, creating or committing the record, and validating with requesters after the DNS entry was in place.
  • The term Senior Systems Administrator / Senior Network Administrator reflects the role titles visible in recent messages and the provided work profile context.

Qualifications

Senior IT Infrastructure Engineer must have proven experience to implement and operate a minimum of five of the following:

  • Windows Server 2012 R2 Active Directory (Users/Computers/DNS/DHCP/Group Policy)
  • Server Management (physical server builds from scratch, cluster configuration, virtual machine deployment from template, hardware parts replacement / upgrades)
  • VMWare Virtualization (build and deploy VMWare hosts, vCenter, vSwitching and HA connectivity to SAN and Network)
  • Communications (SIP Lines, Cisco Call Manager, Cisco Unity, Cisco Jabber, Contact Call Center Express)
  • Backup and Recovery (Veeam Backup and Replication, Backup Exec and iScalar 500 Library)
  • Networking- Firewalls and Switching (VLAN, DMZ, Interface Tagging, Interface Configuration, Network Address Translation, Firewall Rules, VPN, Access Lists, Load Balancers)
  • Storage Area Network (Array configuration, Storage Pool creation and management, attach hosts to SAN and provision storage, fiber switch configuration, disk replacement, NAS management, recover point appliances)
  • Messaging Exchange 2013 / 2010 (SMTP connectors, DAG, mailbox database policies, Proof Point, Global Relay, Blackberry Work
  • System Center Configuration Manager (serve and desktop patching, image deployment, software deployment, MBAM integration, Distribution Points)
  • Security Systems (Palo Alto, PGP Encryption, Sophos Encryption, Symantec Antivirus / DLP, Cisco Fire Power, Cyber Ark Identity Management, MBAM)
  • IT Controls (Change Management, Incident Management, Audits)

Education/Certifications

  • 10 years of previous server administration and / or network administration experience.