Lead System Administrator & Infrastructure
Apparel Group Dubai, Dubai, United Arab Emirates
Retail Apparel and Fashion · 1,001-5,000 employees
About the role
The Lead System Administrator is responsible for the availability, security, and performance of a large-scale enterprise infrastructure, including virtualisation, storage, and cloud environments. The role also serves as a Level 3 technical escalation point and leads critical infrastructure upgrade projects.
What they look for
Requirements
Candidates must have at least 8-10 years of experience in IT infrastructure or systems administration with proven expertise in managing large-scale SAN, Active Directory, and M365 environments. A Bachelor's degree in Electronics and Communication Engineering is required, along with hands-on experience in enterprise backup and endpoint security.
Full description
KEY RESPONSIBILITIES 1. Virtualisation & Server Infrastructure (VMware)
- Administer VMware vCenter and ESXi infrastructure (v7.x and v8.x) across the 9-host server fleet — cluster management, vSphere HA/DRS configuration, resource pool management, and host patching within approved maintenance windows.
- Provision new virtual machines aligned to workload requirements; monitor VM resource utilisation and implement right-sizing recommendations to optimise cluster performance and capacity.
- Monitor physical host hardware health via iLO/iDRAC and vCenter hardware status; coordinate firmware and driver updates; manage hardware failures and vendor RMA processes.
- Configure and maintain on-premises servers for both physical and virtualised workloads; diagnose server-level OS and application issues; apply security patches within approved windows.
2. SAN Storage Management (HPE MSA 2060/2050, EMC VNX, Huawei Dorado)
- Administer the HPE MSA 2060 and MSA 2050 arrays — manage disk groups, virtual pools, volumes, and host mappings; monitor health and I/O performance; coordinate drive replacements and firmware updates.
- Administer the Dell EMC VNX unified storage platform — manage storage pools, LUNs, file systems, and CIFS/NFS shares; coordinate with Dell EMC support for firmware and fault resolution.
- Administer the Huawei Dorado all-flash array — manage storage pools, LUNs, host groups, and replication; monitor NVMe performance and capacity; coordinate Huawei support for upgrades.
- Configure and manage SAN switch zoning, ISL links, and port assignments supporting the fibre channel fabric; monitor fabric health and resolve path failures between hosts and LUNs.
- Monitor storage capacity trends across all arrays; forecast growth requirements and raise procurement proposals before capacity thresholds are reached.
3. Active Directory — Identity & Access Management (25,000+ Objects)
- Administer Active Directory for 25,000+ user accounts — manage user lifecycle, group memberships, OU structure, and attribute management; conduct regular AD hygiene reviews for stale accounts and empty groups.
- Design, configure, and maintain Group Policy Objects across all OUs — security settings, software deployment, desktop restrictions, and drive mapping; conduct regular GPO audits for conflicts and misconfigured inheritance.
- Manage workstation, laptop, and server domain join; troubleshoot join failures and ensure correct OU placement and GPO application for all newly joined systems.
- Manage and maintain the Azure AD Connect server — monitor sync cycles, diagnose and resolve synchronisation errors (object conflicts, attribute mismatches, connector failures), and manage password hash sync to O365.
- Manage the AD audit framework — user activity logging, AD object change tracking, and file access audit logs; review audit reports for anomalies and produce compliance reports for management.
- Administer enterprise DHCP servers — manage scopes, reservations, and exclusion ranges across all network segments; monitor utilisation, resolve IP conflicts, and maintain IPAM documentation.
- Administer enterprise DNS servers — manage forward and reverse lookup zones, all record types, and conditional forwarders; troubleshoot resolution failures affecting authentication, applications, and internet access.
4. Print & File Server Management
- Administer the enterprise print server — manage queues, share permissions, driver deployments, and print spooler health; deploy printers via Group Policy; resolve print failures and driver conflicts.
- Manage the MyQ print management platform — configure AD integration, quota management, pull-print queues, and cost reporting; troubleshoot MyQ agent and authentication failures.
- Administer the Head Office and Bur Dubai file servers — manage shared folder structures, NTFS and share-level permissions, and ACL inheritance; conduct regular permissions audits for least-privilege compliance.
- Configure and maintain DFS Replication between HO and Bur Dubai file servers; monitor replication health, resolve backlogs and conflicts, and validate data consistency between namespaces.
- Manage file-level recovery from Shadow Copies, VSS snapshots, and Commvault restore jobs; validate restored data integrity and document recovery actions.
5. Patch & Application Management (7,500 Systems)
- Manage ManageEngine Patch Manager Plus for OS and third-party application patching across 7,500 systems spanning all regions — define approval workflows, test in pilot groups, schedule deployment windows, and report compliance.
- Configure and manage PDQ Deploy for remote application deployments and patch packages — build packages, define target collections, schedule deployments, and investigate failed deployment root causes.
- Generate patch compliance reports from ManageEngine and PDQ; identify and remediate non-compliant systems; report monthly compliance status to IT management.
6. Monitoring, Environmental Sensors & Alerts
- Deploy and maintain NTI (Network Technologies Inc.) environmental sensors across datacentre and server rooms; monitor temperature, humidity, and power conditions; configure alert thresholds and notification policies.
- Manage the EcoStruxure gateway for proactive monitoring of 2 UPS units and 2 cooling units; configure real-time incident notifications and coordinate with Facilities for physical event remediation.
- Maintain holistic infrastructure monitoring across VMware, storage, AD, backup, and network; review dashboards daily, investigate flagged events, and implement root-cause fixes to reduce recurring alert noise.
7. Backup & Disaster Recovery
- Administer the Commvault data protection platform covering server backup, storage management, and tape library integration; configure plans, retention policies, and schedules; monitor jobs and validate integrity via restore tests.
- Manage Druva InSync endpoint backup for senior/higher-level employees; administer enrolment, backup policies, retention, and restore requests; investigate missed backups and failed sync events.
- Manage cloud-to-cloud O365 backup (mailboxes, SharePoint, OneDrive, Teams) for Grade 8 and above employees; configure schedules and retention; monitor job health and process restore requests.
- Manage TigerBridge cloud replication for file server data; configure policies, monitor sync health, and validate consistency between on-premises file servers and the cloud target.
- Maintain and test disaster recovery procedures for critical infrastructure; document RTO/RPO targets, validate runbooks, and conduct periodic DR tests to confirm recoverability.
8. Microsoft 365 Administration (11,000+ Users)
- Administer the enterprise M365 tenant for 11,000+ users across all regions — tenant-level settings, security and compliance policies, service health monitoring, and administrative role assignments.
- Manage individual user mailboxes — archive policies, litigation hold, quotas, forwarding, and delegation; assign and reclaim licences based on role requirements and licence budgets.
- Create and manage shared mailboxes, meeting room mailboxes with booking policies, distribution lists, mail-enabled security groups, and Microsoft 365 Groups including lifecycle and ownership management.
- Administer Microsoft Entra ID — user identities, app registrations, enterprise applications, guest access, Conditional Access policies, MFA enforcement, and sign-in risk monitoring.
- Administer SharePoint Online and Microsoft Teams — site collections, permissions, storage quotas, external sharing policies, Teams governance, and meeting settings; support escalated site and team owner issues.
- Manage licence allocation, Conditional Access policy configuration, and brand-specific M365 policies across all brands and regions. Administer CodeTwo Cloud Signature for centralised email signature management.
9. Email & Endpoint Security
- Administer Mimecast email security — configure and tune email filtering, anti-spam, impersonation defence, URL scanning, and attachment sandboxing; manage quarantine, allow/block lists, and investigate blocked legitimate email.
- Monitor Mimecast threat intelligence dashboards; investigate impersonation attempts, phishing campaigns, and malicious attachments; adjust policies to improve detection accuracy and report significant threats.
- Manage CrowdStrike Falcon EDR across 10,000 systems — ensure 100% agent coverage, monitor the console for active detections and containment events, and drive installation on all gaps in coverage.
- Investigate and respond to CrowdStrike detections — triage severity, contain affected endpoints, escalate confirmed incidents, document findings and remediation, and track recurrent patterns for root-cause analysis.
10. Cloud Environments (Azure & Oracle OCI)
- Administer the Microsoft Azure environment — manage subscriptions, resource groups, VMs, virtual networks, storage accounts, and Entra ID integration; monitor cost and usage and enforce governance policies.
- Monitor Azure spend against budget; configure cost alerts; identify optimisation opportunities; implement Azure Policy controls; review and remediate Azure Security Centre / Defender for Cloud recommendations.
- Administer Oracle Cloud Infrastructure (OCI) — manage compute instances, VCNs, object storage, IAM policies, and tenancy governance; monitor resource health and cost; coordinate with Oracle support for platform issues.
11. Remote Access, Conference Rooms & Additional Platforms
- Manage TeamViewer enterprise console — assign agent licences to IT staff, create location- and user-type-specific host policies (store vs. back office), administer device groups, and validate correct policy assignment across all endpoints.
- Manage smart meeting room technology globally (Barco ClickShare, Yealink, NearHub, Miracast, Apple TV) — firmware updates, user access, cross-platform wireless sharing integration with Teams and Zoom, and room technology standards for new buildouts.
- Administer Zoom Business (user accounts, licences, permissions), Circularo e-signature platform (user accounts, signing workflows), and NFC e-business cards for the management team.
- Serve as Level 3 technical escalation point for the Workplace Technology team — diagnose and resolve complex AD, backup, storage, M365, and network-level issues beyond L1/L2 capability.
12. Active Projects — In Progress
- Druva InSync full estate deployment — identify and enrol all systems not yet covered by endpoint backup; validate agent deployment and produce completion tracking report.
- Patch Manager Plus full estate deployment — push agents to all missed systems via PDQ or GPO; validate reporting coverage and update the patch compliance baseline.
- Qualys agent full estate deployment — push vulnerability assessment agents to all uncovered systems; confirm scan coverage in the Qualys Cloud Platform across all regions.
- Office 2019 (EOL) to Microsoft 365 Apps migration — identify affected systems, package M365 deployment, schedule upgrades per business unit, and validate activation post-deployment.
- Windows 10 (EOL) to Windows 11 upgrade programme across stores and back office — assess hardware compatibility, define upgrade waves, coordinate deployment, and validate post-upgrade functionality.
- Windows Server 2012 (EOL) to Server 2022/2025 upgrade — identify all affected instances, assess application compatibility, define upgrade or migration approach per server, and coordinate change windows.
Technical Skills
- VMware vSphere administration — vCenter, ESXi (7.x/8.x), vSphere HA, DRS, VM lifecycle management, and host patching.
- SAN storage administration — HPE MSA, Dell EMC VNX, Huawei Dorado; fibre channel fabric and SAN switch zoning.
- Active Directory at enterprise scale (25,000+ objects) — user lifecycle, Group Policy, OU design, Azure AD Connect, and AD audit frameworks.
- Microsoft 365 tenant administration at scale (10,000+ users) — Exchange Online, Entra ID, SharePoint, Teams, Conditional Access, and licence management.
- Backup and DR — Commvault (server/tape), Druva InSync, cloud-to-cloud O365 backup, and TigerBridge replication.
- Patch management — ManageEngine Patch Manager Plus and PDQ Deploy across large multi-site estates.
- Endpoint security — CrowdStrike Falcon EDR deployment, monitoring, and threat response at scale.
- Email security — Mimecast administration including filtering, URL/attachment control, and impersonation defence.
- Cloud administration — Microsoft Azure (IaaS, cost management, governance, Defender for Cloud) and Oracle OCI.
- Windows Server administration — DNS, DHCP, File Server, DFS, Print Server, and MyQ print management.
- Environmental and infrastructure monitoring — NTI sensors and Schneider EcoStruxure gateway.
- Remote access management — TeamViewer enterprise console, host policy configuration, and licence management.
- PowerShell scripting for automation of AD, M365, and infrastructure administration tasks.
Education & Certifications
- Bachelors in Electronics and Communication Engineering.
Certificates
- CCNA – Nice to Have!
- MCSA – Nice to have!
Experience
- Minimum 8-10 years of experience in an IT infrastructure or systems administration role.
- Proven experience managing multi-array SAN storage environments across heterogeneous platforms (HPE, Dell EMC, Huawei).
- Demonstrable experience administering Active Directory at scale (10,000+ objects) including Group Policy, Azure AD Connect, and AD audit frameworks.
- Hands-on M365 tenant administration experience for organisations with 5,000+ users, including Entra ID, Conditional Access, and Exchange Online.
- Track record of managing enterprise backup solutions (Commvault or equivalent) including tape library operations and DR testing.
- Experience managing endpoint security platforms (CrowdStrike or equivalent EDR) across large multi-site estates.
- Background in cloud infrastructure management (Azure and/or OCI) including cost governance and security posture management.
Similar roles
-
System Administrator
Landa Corporation Rehovot, Center District, Israel
-
System Administrator - ServiceNow
Reserve Bank of Australia Sydney, New South Wales, Australia
-
Subject Matter Expert III - System Administrator (SCADA)
Chugach Government Solutions Portsmouth, England, United Kingdom
-
Procore System Administrator
Cumming Group Fort Worth, Texas, United States · $77K–$103K/yr
-
#713 - System Administrator
BlueCloud Services, Inc. Santiago, Santiago Metropolitan Region, Chile
-
System Administrator
REP Fitness Westminster, Colorado, United States · $80K–$95K/yr