Systems Engineer
at GLG
- Location
- New York
- Posted
- 5d ago
at GLG
<p><span data-contrast="auto">Our Systems Engineering team owns the infrastructure that keeps a ~2,500-person global firm running around the clock: cloud (primarily AWS), Microsoft 365, Windows Server, identity platforms (Entra ID, Active Directory, SailPoint), and enterprise email flow. We are in the middle of a deliberate shift from click-ops to modern engineering practice: infrastructure as code, version control, CI/CD, cloud infrastructure, least-privilege identity, and AI-assisted workflows.</span><span data-ccp-props="{"335559739":140}"> </span></p> <p><span data-contrast="auto">We're hiring a System Engineer to help drive that shift. You'll operate and harden the current stack while actively replacing manual, one-off work with automation and repeatable, reviewable process. We're looking for a DevOps/SRE mindset: someone who sees a manual runbook and wants to turn it into code, contributes to technical standards, and uses AI to move faster than the team could before.</span><span data-ccp-props="{"335559739":140}"> </span></p> <p><span data-contrast="auto">Just as important, we want someone who questions why things are the way they are. Much of our stack was inherited; some of it is legacy or dependent on one person's knowledge. You should be comfortable looking at an established design, asking whether there's a better way, and making the case for change, grounded in a clear-eyed read of the pros, cons, and migration trade-offs, not change for its own sake.</span><span data-ccp-props="{"335559739":140}"> </span></p> <p><span data-contrast="auto">This is a broad remit: identity and access, email flow, cloud, and core infrastructure. We're not expecting you to arrive an expert in every one. We are looking for someone comfortable stepping into each area, learning fast, and growing into full ownership over time.</span><span data-ccp-props="{"335559739":140}"> </span></p> <p><strong><span data-contrast="none"><span data-ccp-parastyle="heading 2">What you'll do</span></span></strong><span data-ccp-props="{"335559738":260,"335559739":120}"> </span></p> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Automate and operate core infrastructure across AWS, Microsoft 365, and Windows Server, with reliability, security, and least privilege as defaults.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Engineer identity and access across our identity platforms (Entra ID, Active Directory / Domain Controllers, and SailPoint), including provisioning, governance, and least-privilege models on-prem and in the cloud.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Own and improve enterprise email flow: Exchange Online, our secure email gateway, and email authentication (SPF, DKIM, DMARC) across first- and third-party sending platforms.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Evaluate inherited architecture and legacy tooling, ask why it works the way it does, and propose better approaches, backed by honest pros, cons, and migration trade-offs.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Contribute to the move to infrastructure as code: build and maintain declarative infrastructure (our stack is OpenTofu and Spacelift) so environments are version-controlled, peer-reviewed, and reproducible.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Put your infrastructure and automation under version control (Git), and work in a pull-request review and CI/CD workflow.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Support and extend our cloud footprint across AWS and Azure, including networking, identity, and workload migration.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <ul> <li data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":360,"335559991":220,"469769242":[8226],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="8" data-aria-level="1