Why this Job is Exciting
The L3 Systems Engineer is a hands-on senior engineering role within the NexusTek Engineering Center, the company's dedicated L3 Center of Excellence for the hybrid cloud stack. This role carries a deep, hire-in specialization in AWS, with Azure and GCP experience preferred and expected to grow on the job as the engineer supports environments across all three public clouds, plus on-premises infrastructure, for mid-market and enterprise managed services clients as well as internal projects and initiatives. As a member of the Engineering Center, this engineer owns the hardest problems alongside other L3 peers for the accounts they support: final-tier escalation resolution, root cause ownership, and platform-grade automation and standards across hybrid cloud environments. This is a fully remote position with limited travel.
Work Environment
- Fully remote — open to candidates coast to coast within the United States.
- Limited travel is required; engineering, incident, and client-facing work is largely performed remotely.
- Rotational on-call schedule shared across the team; this is a required responsibility of the role, and rotation frequency may vary based on team and business needs.
Core Responsibilities
- Own resolution of escalated incident, service request, and alert tickets across SLA-bound and non-SLA queues.
- Serve as the L3 escalation point for issues that exceed L1/L2 capability, taking ownership from intake through resolution and RCA closure as needed.
- Handle direct engineer-to-engineer escalations and mentorship as they arise.
- Partner with customer technical contacts on long-term solutions, lifecycle planning, and infrastructure health/remediation reviews — remotely, with no on-site presence required.
- Design, deploy, and support scalable, secure, and highly available architectures across AWS, with growing scope across Azure, GCP, and on-premises compute infrastructure.
- Infrastructure as code experience is a plus.
- Support of containerized and serverless workloads (Amazon EKS, AWS Lambda) as part of modern, cloud-native platform delivery is a plus.
- Streamline infrastructure delivery and reduce manual repetitive work.
- Extend engineering depth into on-premises/hybrid infrastructure and secondary clouds (Azure, GCP) as client environments require — all delivered remotely.
- Configure and maintain identity and access management controls (IAM, Active Directory/Entra ID, SSO, MFA) across cloud and hybrid environments.
- Perform vulnerability remediation, audits, and compliance/audit-readiness activities relevant to client environments (e.g., CMMC 2.0, SOC 2, HIPAA).
- Apply cloud security best practices, including encryption, centralized logging, and threat-detection tooling.
- Monitor platform health, ticket SLAs, and service metrics; proactively identify and remediate issues before they escalate.
- Build and maintain automated health checks, remediation playbooks, and DR/backup validation routines that reduce manual intervention over time.
- Create and maintain runbooks, technical documentation, and procedure guides so knowledge is documented and shared, not single-threaded.
- Review and perform cost optimization and rightsizing across managed cloud environments.
- Serve as primary or secondary engineer on project work, including cloud migrations, infrastructure modernization, onboarding/offboarding, and lifecycle/EOL upgrades.
- Participate in customer-facing calls and technical reviews as a senior engineer/subject-matter expert, including project SOW reviews and solutioning discussions.
- Assist with customer onboarding and managed services transitions, including technical assessments, discovery, and project scoping.
- Identify and submit new opportunities uncovered during the course of engineering engagements.
- Contribute to the certification roadmap and internal Skill Builder Workshop program by building and delivering technical content that raises team-wide capability.
- Provide mentorship and technical guidance to L1/L2 engineers — supporting them well is core to this team's mission.
- Take ownership of improving processes, tools, and documentation; when something isn't working, take point on fixing it.
- Communicate early and often on progress, blockers, and risk, and own mistakes quickly so the whole team can learn from them.
- Participate in a rotational on-call schedule as an escalation engineer, engaged on P1/P2 incidents outside standard business hours when 24x7 L1/L2 cannot resolve them.
- Acknowledge and respond to after-hours escalations per team SLA commitments, and hand off active incidents with full documentation at the close of the on-call window.
Technical Skills & Tools
- EC2, Auto Scaling & Compute Services
- VPC & Hybrid/Cloud Networking
- EKS & Container Orchestration — a plus
- Lambda & Serverless (API Gateway / Step Functions)
- S3 & EBS Storage
- Organizations / Multi-Account Architecture
- CloudWatch
- Microsoft Azure: core compute, storage, networking, and identity (Active Directory/Entra ID, SSO, MFA).
- Google Cloud Platform: core compute, storage, and networking fundamentals.
- Prior hands-on AWS specialists without Azure/GCP background are still encouraged to apply; Azure and GCP proficiency is expected to develop on the job.
- Linux & Windows Server Administration
- Hybrid Networking, Firewalls & VPN
- Terraform / Infrastructure as Code
- Ansible / Configuration Management
- CI/CD Pipelines (Jenkins, GitLab CI, AWS CodePipeline)
- Kubernetes & Docker
- Monitoring & Observability (CloudWatch, LogicMonitor, N-Able, SIEM)
- Backup & Disaster Recovery (Veeam/Commvault, replication, failover testing)
- Scripting & Automation (Python, Bash, PowerShell)
- Security & Compliance Frameworks (CMMC 2.0, SOC 2, HIPAA)
Certifications (Preferred)
- AWS Certified Solutions Architect – Associate or Professional
- AWS Certified SysOps Administrator – Associate
- AWS Certified DevOps Engineer — a plus
- Microsoft Certified: Azure Administrator Associate (or equivalent) — a plus
- Google Cloud Associate Cloud Engineer (or equivalent) — a plus
Certification is a plus, not a requirement at hire. Engineers who do not already hold a current AWS certification are expected to obtain at least one recognized AWS certification within 12 months of hire, supported by NexusTek's certification program.
Pay and Benefits:
Estimated Starting Salary/Wage Range: $115,000 to $120,000 annual based on candidate's experience, qualifications, and location.
In addition to legally-required benefits, NexusTek offers a benefit package to eligible full-time employees, which currently includes the following:
- Four weeks of annual accrued PTO
- Seven paid national holidays
- Medical, dental, vision options
- Company-paid life insurance, short and long-term disability
- Voluntary benefits such as critical illness and accident
- Voluntary Legal Shield and identity theft protection
- Discretionary annual 401k match plan
- Generous employee referral bonus plan
- Employee Assistance Program
- Access to over 90,000+ courses in ADP My Learning
- StandOut employee engagement tools
- Eligible to apply for a Pluralsight license
- Eligible to apply for NexusTek Technical Academy or Leadership Academy
We’re happy to provide our comprehensive benefits guide. Each benefit is subject to eligibility requirements as specified in plan documents, and the Company reserves the right to modify the benefits it offers from time to time.
Interview Process - Typical interview process for this role:
Application and Screening Stage - Thanks for showing interest!
- Submit your application
- Our recruiters carefully consider each application. If you are selected to move forward, we will contact you for the 20 minute introductory screening to learn more about you and why you want to work for NexusTek.
Interview Stage - We’ll dive into your experience more in depth
- One-hour technical interview with hiring manager (virtual)
- 30-minute to one-hour follow up interview with team member to be determined (virtual)
- References – 3 professional references at least one direct supervisor
- You are welcome to request additional conversations with team members you didn’t get to meet during the process
NexusTek provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws
NexusTek participates in E-Verify for all US Employees
Please be aware of potential recruitment fraud and fake social media pages. NexusTek will never ask you to pay a fee as part of the interview process. Additionally, we will not ask for your personal banking information until you have signed an employment offer and completed virtual onboarding training and paperwork provided by our HR team.
All communications with NexusTek professionals will only be sent from an @nexustek.com or ADP email address and never originate from gmail.com, yahoo.com, or other commercial email services. If you are viewing this job post outside of our website and interested in exploring opportunities, please go directly to our Careers Page: https://www.nexustek.com/nexustek-careers/ or https://workforcenow.adp.com/mascsr/default/mdf/recruitment/recruitment.html?cid=567e686e-7575-49d9-b29f-985e7365f987&ccId=19000101_000001&type=MP&lang=en_US