Role: Cloud Infra & Security Engineer
Location: NY, remote
Employment Type: Contract
Cloud & Server Infrastructure
Microsoft Azure / Entra
Client is an Azure- and Microsoft Entra ID-centric organization. Entra ID serves as the identity platform underpinning authentication, access, and (per the MDM section below) device management.
- Cloud-hosted servers/workloads in Microsoft Azure
- Microsoft Entra ID as the core identity provider
On-Premises Infrastructure
- VMware ESX hypervisor environment
- 10 virtual servers running on-premises
AWS Membership System (In Development)
A new Membership system is currently being built and hosted in AWS, running alongside the Azure/on-prem footprint. This represents Client's first significant AWS presence and will require the vendor to support a multi-cloud environment (Azure + AWS).
Legacy System IBM i
An IBM i (AS/400) server remains in production and is in the process of being retired. Vendors should expect limited-duration support needs for this platform; timeline and replacement details to be confirmed during discovery.
Networking & Security
Networking
- Meraki for networking (switching/wireless/SD-WAN, per standard Meraki deployment)
- Cisco Firepower as the perimeter firewall
Remote Access
Remote and hybrid staff connect to internal resources via Cisco AnyConnect client VPN through the existing Firepower firewall.
Security Tooling
- Microsoft Defender endpoint/threat protection
- Microsoft Sentinel SIEM / security monitoring
- Tenable vulnerability management
- KnowBe4 security awareness training / phishing simulation
End-User Computing
Devices
- Windows laptops
- Mac laptops
Mobile Device Management (MDM)
- Microsoft Intune Windows device management
- JAMF Mac device management
IT Service Management
Client uses ServiceNow as its helpdesk/ITSM ticketing platform. Vendor support workflows are expected to integrate with or operate through ServiceNow.
Backup & Disaster Recovery
Veeam is the primary backup solution in use.
Areas of MSP Support
The following outlines the specific areas where Client is looking for MSP support as part of this engagement.
Cloud Architecture and Engineering (AWS and Azure)
The initial focus of this workstream is infrastructure visibility and logging across both cloud platforms. Work should proceed in the following priority order:
- Network inventory establish what is on the network and what is currently visible
- Logging ensure logging is configured across all assets
- Conditional access and policies more user-impacting, to be addressed after inventory and logging are in place.
Sentinel Coverage Gaps Identified
The following gaps in Microsoft Sentinel coverage have been identified and should be addressed as part of this workstream:
- IoT devices (printers, HVAC, Pelotons) are not currently feeding into Sentinel
- Some endpoints are missing telemetry, likely due to firewall rules blocking Defender data
- The IBM i system is not contributing sufficient data/logs to Sentinel.