About the job Windows Systems Engineer (Windows Server/Active Directory/CyberArk) - Hybrid Porto (4 days/week office)
Windows Systems Engineer (Windows Server/Active Directory/CyberArk) - Hybrid Porto (4 days/week office)
ABOUT THE OPPORTUNITY
Our client, a well-established organization operating critical financial market infrastructure, is looking for a Senior Windows Systems Engineer to join its Infrastructure & Security organization. This is a hands-on role operating and securing large, multi-domain Windows Server environments that underpin mission-critical financial systems, working alongside Network, Security, DevOps, and IAM teams across multiple geographies.
PROJECT & CONTEXT
You'll take ownership of multi-domain Active Directory environments, privileged access management, PKI services, server hardening, patching, and disaster recovery for production and DR environments. The role spans day-to-day operations (domain controllers, GPOs, CyberArk vaults, certificate lifecycle, RDP/remote access security) as well as automation and continuous improvement through PowerShell, Ansible, and Terraform. You'll also support Citrix session-based and VDI environments, participate in incident response and CAB processes, and monitor infrastructure health across a distributed, multi-country team.
WHAT WE'RE LOOKING FOR (Required)
- 5+ years of hands-on Windows Server administration, including Windows Server 2019 and 2022, domain controllers, clustering, and enterprise infrastructure
- Advanced Active Directory experience in multi-domain environments: GPOs, LAPS, security groups, trusts, and identity lifecycle (JOINER/LEAVER) workflows
- Hands-on CyberArk PAM and Password Manager Plus experience, including privileged account onboarding and vault administration
- Intermediate to advanced PowerShell scripting skills
- Experience with Ansible, Terraform, and infrastructure-as-code practices for cross-platform automation
- Strong understanding of Windows security hardening, audit logging, vulnerability management, and compliance frameworks (CIS Benchmarks, NIST, etc.)
- Experience with RDP, NLA, Just-In-Time access, VPNs, TCP/IP, DNS, and Active Directory site topology
- Experience with WSUS, SCCM, Patch Manager Plus, Ivanti, and automated software deployment
- Experience with incident response, technical documentation, CAB procedures, and change management
- Ability to work effectively with distributed teams across multiple countries and time zones
- Minimum B2 (Upper Intermediate) English
NICE TO HAVE (Preferred)
- Windows Certificate Authority / PKI administration and SSL/TLS certificate lifecycle management
- Citrix session-based and VDI environment support, including application publishing
- Experience with monitoring tools such as LogicMonitor, WhatsUP Gold, PagerDuty, Coralogix, or Azure Log Analytics
- Experience with disaster recovery failover testing and backup validation
Note: I omitted the Compensation section — the job description only includes a "Maximum Salary" (€2,100) with no minimum value, and the format requires both to build the €X–€Y/month range.