Senior Cloud Infrastructure Engineer (P-178)
Smash CRSMASH, Who we are?
We are agents for tech professionals in Costa Rica and Latin America that help them build careers with companies in the United States.
We believe in long-lasting relationships with our talent. We invest time getting to know them and understanding what they seek as their professional next step.
We aim to find the perfect match. As agents, we pair our talent with our US clients, not only by their technical skills but as a cultural fit. Our core competency is to find the right talent fast.
We purposefully move away from the traditional “outsourcing” type of relationship. Our clients are looking for professionals who become an integral part of their teams, and so are we.
Our Benefits
- Wellness Coverage
- Remote Work
- Birthday day off
- Recognition and rewards system
- Referrals Program
- Business skill coaching
- English classes for Smashers and relatives
- Learning opportunities
This is a remote position supporting a US-based company. Applicants must be legally authorized to work in their country of residence within Latin America (LATAM).
Role summary
We are looking for an experienced Senior Cloud Infrastructure Engineer to deliver advanced cloud and infrastructure solutions within a Professional Services environment.
This is a highly technical, customer-facing role responsible for serving as a final escalation point for complex cloud, network, endpoint, identity, and infrastructure issues, while also supporting deployments, migrations, architecture initiatives, and solution engineering.
The ideal candidate brings deep expertise across the Microsoft ecosystem—including Azure, Microsoft 365, Entra ID, Intune, and hybrid environments—combined with networking, virtualization, security, Infrastructure as Code, and MSP experience.
Responsibilities
- Act as a final escalation point for complex technical issues across cloud, network, endpoint, identity, and infrastructure environments.
- Troubleshoot advanced issues involving Windows Server, Active Directory, DNS, DHCP, networking, virtualization, backups, and security.
- Plan and execute cloud infrastructure deployments, migrations, configurations, and modernization initiatives.
- Architect and support Microsoft Azure and Microsoft 365 environments.
- Administer and troubleshoot Exchange Online, SharePoint, OneDrive, and Microsoft 365 tenant environments.
- Design and support Microsoft Entra ID, including Conditional Access, identity security, passwordless authentication, and phishing-resistant MFA.
- Architect and support Microsoft Intune and Autopilot configurations and endpoint management.
- Design, configure, and troubleshoot Azure virtual networking and hybrid cloud connectivity.
- Manage and troubleshoot VMware and Hyper-V virtualized environments.
- Perform advanced Layer 2 and Layer 3 network troubleshooting across firewalls, routers, switches, and related infrastructure.
- Support firewall configurations, security protocols, and network modernization initiatives involving SASE/SSE and Zero Trust Network Access.
- Apply Zero Trust architecture principles across client environments.
- Collaborate with security teams on Microsoft Defender XDR and Microsoft Sentinel detection, response, and reporting workflows.
- Build and maintain repeatable cloud environments using Terraform, Bicep, PowerShell, and/or Azure CLI.
- Ensure Infrastructure as Code configurations are version-controlled, repeatable, and auditable.
- Manage hybrid, multi-cloud, and edge workloads using Azure Arc and Azure Local.
- Support cloud governance, patching, and configuration consistency across cloud and on-premises environments.
- Support backup and disaster recovery solutions, including immutable and air-gapped backups, ransomware recovery testing, and restore runbooks.
- Own or support FinOps and cloud cost optimization, including consumption monitoring, resource right-sizing, reservations, licensing, and identification of savings opportunities.
- Support client readiness for Microsoft 365 Copilot and AI workloads, including data governance, permission hygiene, and Purview sensitivity labeling.
- Participate in solution engineering activities and collaborate with sales and technical teams to design secure and scalable customer solutions.
- Maintain comprehensive technical documentation for escalations, deployments, migrations, and client environments.
- Use CRM, ticketing, and BI systems to track operational and customer service metrics.
- Mentor and share technical knowledge with Front Line Services and Project teams.
- Participate in an on-call rotation approximately 4–5 times per year, typically for one week at a time, providing after-hours escalation support for critical incidents.
Requirements – Must-haves
- 8+ years of hands-on IT infrastructure and cloud support experience.
- 5+ years of escalation-level experience within MSP environments.
- Advanced hands-on expertise with Microsoft Azure.
- Advanced expertise with Microsoft 365, including Exchange Online, SharePoint, and OneDrive.
- Strong experience with Windows Server, Active Directory, DNS, DHCP, and file services.
- Strong experience with Microsoft Entra ID, identity management, Conditional Access, and MFA.
- Experience with Microsoft Intune and Autopilot.
- Experience supporting Microsoft 365 endpoint administration and tenant migrations.
- Strong knowledge of Azure networking and hybrid cloud environments.
- Advanced networking troubleshooting capabilities across Layer 2 and Layer 3.
- Experience troubleshooting and configuring firewalls, routers, and switches.
- Experience with VMware and Hyper-V virtualization.
- Experience with backup, disaster recovery, and business continuity technologies.
- Hands-on experience with Infrastructure as Code, using Terraform, Bicep, PowerShell, Azure CLI, or similar technologies.
- Strong understanding of Zero Trust security architecture.
- Experience supporting cloud and infrastructure security controls.
- Proven experience supporting technical projects, including scoping, planning, deployment, migration, and execution.
- Strong experience troubleshooting complex, business-critical infrastructure incidents.
- Strong customer-facing communication and technical documentation skills.
- Ability to collaborate effectively with service, project, security, sales, and client teams.
- Availability to participate in the required after-hours on-call rotation.
Nice-to-haves (optional)
- Previous experience working in an MSP/MSSP environment.
- Experience with Microsoft Defender XDR and Microsoft Sentinel.
- Experience with Microsoft Purview and Microsoft 365 Copilot readiness initiatives.
- Experience with Azure Arc and Azure Local.
- Experience with FinOps and Azure cost optimization.
- Experience designing or supporting SASE/SSE architectures.
- Experience implementing immutable or air-gapped backup architectures and ransomware recovery strategies.
- Experience participating in pre-sales or solution engineering activities.
- Bachelor’s degree in Computer Science, Information Technology, or a related discipline, or equivalent professional experience/certifications.
Preferred Certifications
- Microsoft Certified: Azure Administrator Associate
- Microsoft 365 Certified: Endpoint Administrator Associate
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- HashiCorp Certified: Terraform Associate
- Cisco Certified Network Associate (CCNA)
- Relevant ITIL or Project Management certifications
Languages
- English C1
- Spanish C1