Job Title: Director, Systems Engineer
Department: Information Technology
Reports To: VP, Head of Systems Engineering
FLSA Code: Exempt
Estimated Salary: $185,000 - $200,000
Job Summary:
The ideal candidate will be part of the Infrastructure team responsible for the design, implementation, maintenance, and performance of all global systems, ensuring availability, security, and consistency for our environment. This position is a “hands-on” engineering role spanning our enterprise Windows and Cloud environments. The role will be both operations and highly engineering focused, working with different technology teams to deliver secure, well-architected solutions for core business initiatives. Cohen & Steers is committed to an inclusive culture, valuing diversity in support of our people and clients.
Major Responsibilities/Activities:
- Maintain operational excellence by keeping the on-premises, cloud, and hybrid environment secure, compliant, and up to date, including timely patching and vulnerability remediation.
- Responsible for end-to-end Windows Server management.
- Configure, install, maintain, and provide support for critical software and hardware components of our VMware virtualization environment.
- Design, build, and operate Azure infrastructure across IaaS and PaaS workloads, following best practices and architectural guidelines throughout the application implementation life cycle.
- Evaluate application architectures and determine how each workload should be networked, secured, authenticated, connected to on-premises systems, monitored, and recovered.
- Design and manage cloud networking, including private connectivity, DNS, network security, and hybrid connectivity to on-premises environments.
- Implement identity and access for cloud and hybrid workloads using Entra ID, RBAC, and managed identities, eliminating stored credentials wherever possible.
- Develop automation using PowerShell, Infrastructure as Code, and CI/CD pipelines, from server health checks and AD, patch, and certificate compliance reporting to automated cloud provisioning and configuration.
- Establish and enforce cloud governance, including subscription and management group structure, tagging standards, and Azure Policy.
- Provide troubleshooting and root cause analysis across the full stack and assist the help desk support group in resolving escalated issues, determining whether problems originate in Windows, VMware, storage, network, or the cloud.
Minimum Requirements:
- Requires a minimum of 10+ years of experience working within an IT infrastructure group, preferably with Financial experience in a trading environment.
- Extensive hands-on experience planning, deploying, and maintaining enterprise Windows Server environments (2016 through 2025), including builds, upgrades at scale, performance troubleshooting, patch management, and vulnerability remediation.
- Expertise in Active Directory and core Windows services.
- VMware vSphere experience (ESXi, vCenter, HA/DRS, networking) and an understanding of enterprise compute and SAN storage.
- Experience designing and operating Azure infrastructure – virtual machines, storage, backup and site recovery.
- Identity knowledge – Entra ID and hybrid identity, RBAC, managed identities, app registrations, and privileged access/identity management – including how modern token-based authentication differs from traditional Windows authentication, and protocols such as SAML, Kerberos, RADIUS & MFA.
- Experience in PowerShell scripting to build automation and reporting and working with code repositories and CI/CD pipelines.
- Day to day management of monitoring and task scheduling platforms, including tailoring advanced alerting & reports.
- Root Cause analysis and troubleshooting experience are required.
- Must be willing to work weekends and evenings and be on call as required; the responsibilities are for a 7x24 IT operation dispersed amongst the team.
- Must maintain a sincere, polite, and respectful customer service attitude when working with the business.
- Ability to support multiple globally dispersed locations.
- Demonstrates inclusive behaviors in support of a culture that values diverse perspectives.
- Agrees to comply with the firm’s hybrid work policy (“work from home policy,” as aligned with the Company’s employee handbook), which currently requires reporting to the Company’s New York City office four (4) days per week, with one (1) remote workday permitted.
Nice to Have:
- Experience with Azure PaaS services such as Function Apps, App Services, containers, and managed databases, including how networking, identity, and security apply around them.
- Cloud networking expertise – VNet design, private endpoints and Private DNS, firewalls and load balancing, and hybrid connectivity to on-premises (VPN/ExpressRoute).
- Experience with cloud governance and security best practices, including subscriptions and management groups, tagging, Azure Policy, and Cloud Adoption Framework/Well Architected Framework.
- Experience with Infrastructure as Code (IaC), preferably Terraform or Bicep.
- Experience managing a Cisco UCS compute environment and Pure Storage arrays or similar.
- Working knowledge of SCCM or similar platforms used to keep systems up to date and package deployments.
- Well-rounded knowledge of Office 365 and related Microsoft services.
- Managing and maintaining Microsoft security services such as Defender and Intune a big plus.
- Experience with Citrix technologies (Delivery Controller, PVS, StoreFront, NetScaler/VPX), including Citrix Cloud.
Note: This job description reflects management's assignment of essential functions; it does not prescribe or restrict the tasks that may be assigned. The job title or duties and responsibilities may be changed by the Company at any time.