Unknown Company

Principal Infrastructure Engineer

virginia beach, va • Posted 6 days ago
Hybrid Full Time General

Principal Infrastructure EngineerWe are seeking a hands-on Principal Infrastructure Engineer to serve as the senior technical authority for infrastructure across Paradigm and @Gov. Reporting to the Chief Information Officer, this senior individual contributor role will own the most complex infrastructure engineering, troubleshooting, assessment, and architecture work across two segmented environments. The successful candidate will be the tier 3 escalation point for complex issues spanning network, security, virtualization, identity, cloud, ERP, backup, monitoring, and application infrastructure.This role is ideal for an active practitioner who can assess inherited infrastructure, identify technical debt and security gaps, design a scalable and resilient future state, and execute the roadmap needed to support business growth, FedRAMP readiness, and future cloud migration.

This is not a people-management position; however, the role is expected to mentor administrators, strengthen operational processes, and improve documentation and knowledge transfer across the IT team.This is a full-time, exempt position based in Virginia Beach, Virginia, with a hybrid work arrangement.Paradigm, Inc. is a leading credentialing services provider with over 34 years of experience delivering printed and digital diplomas, certificates, and comprehensive learner records to higher education institutions. As a SOC2 Type II certified organization, we pride ourselves on integrity, security, and exceptional , Inc.

is a next-generation platform provider specializing in government credential solutions, including digital apostilles and vital records management for state agencies. We are committed to modernizing government operations through secure, verifiable digital and paper credentials while promoting sustainability.Together, our organizations serve educational institutions and government agencies with trusted, secure credential management solutions that require the highest standards of infrastructure reliability, information security, data integrity, privacy, and compliance.Microsoft-based infrastructure using primarily Windows desktop OS and Windows Server with Office 365; primarily.Net web and desktop development utilizing Microsoft SQL database back-end and limited use of Azure blob storage; integrations with Microsoft's Dynamics Navision, D365 systems, UPS WorldShip, ShipWise, and Endicia; Palo Alto security network has been implemented.Key ResponsibilitiesInfrastructure Architecture & StrategyAssess the current Paradigm and @Gov infrastructure environments, including network segmentation, firewall policy, Active Directory forests, VMware vSphere, Azure, Microsoft 365, Dynamics, backup, monitoring, DNS/CDN, and certificate management.Design and maintain secure, scalable, and resilient infrastructure architectures that support credentialing, apostille, vital records, and government services platforms.Create prioritized remediation plans for misconfigurations, single points of failure, capacity constraints, technical debt, and operational risk.Develop target-state architecture and transition plans for Paradigm's hybrid environment and @Gov's post-FedRAMP cloud migration path.Recommend improvements to tooling, automation, vendor relationships, licensing, and infrastructure processes where they improve maturity, resilience, security, or cost efficiency.Tier 3 Escalation & Complex Problem ResolutionServe as the senior escalation resource for complex incidents that span multiple infrastructure domains or exceed the capabilities of day-to-day administration.Diagnose and resolve production issues end-to-end across Palo Alto firewalls, VMware vSphere, Active Directory and Entra ID, Azure services, Dynamics environments, email deliverability, backups, monitoring, and application infrastructure.Lead high-severity incident response, coordinate with infrastructure, development, QA, business stakeholders, and vendors, and drive root-cause analysis and post-incident remediation.Build and maintain runbooks, escalation procedures, architecture diagrams, and post-mortem templates that improve response consistency and team capability.Network, Security & IdentityAdminister and optimize Palo Alto next-generation firewall configurations, including security policies, NAT rules, threat prevention, URL filtering, GlobalProtect VPN, and inter-network access controls.Manage network switching, routing, VLANs, VPNs, load balancers, DNS, DHCP, and related physical and virtual network infrastructure across segmented environments.Serve as a senior authority for separate Active Directory forests and domains, including domain controllers, replication, Group Policy, DNS/DHCP, OU design, trusts, and hybrid identity patterns.Manage Paradigm's Azure/Entra ID hybrid identity, Microsoft 365 administration, conditional access, SSO, MFA, privileged access controls, and user lifecycle processes.Harden infrastructure in alignment with SOC2, NIST, government security requirements, and FedRAMP readiness expectations for @Gov.Virtualization, Cloud & Systems OperationsAdminister and improve VMware vSphere environments, including ESXi, vCenter, HA/DRS, vMotion, resource management, VM networking, templates, upgrades, storage, and performance tuning.Administer Azure infrastructure for Paradigm, including compute, networking, storage, subscriptions, identity services, monitoring, and hybrid connectivity with on-premises systems.Plan @Gov's future migration from fully on-premises infrastructure to Azure once FedRAMP certification objectives are met.Implement automation and infrastructure-as-code practices using tools such as Terraform, Ansible, PowerShell, or similar platforms.Maintain server hardware, operating systems, patching, rack/data-center coordination, UPS, and supporting infrastructure needed for reliable operations.Business Applications, Monitoring & Disaster RecoverySupport infrastructure for Microsoft Dynamics Business Central and NAV environments, including server administration, SQL Server coordination, performance, availability, backups, and change windows.Manage and improve monitoring and observability using tools such as Dynatrace, SolarWinds, Netwrix, and related alerting/reporting platforms.Manage Veeam backup and recovery capabilities, including job configuration, retention, restore testing, disaster recovery documentation, and recoverability validation for critical systems.Administer supporting platforms such as Cloudflare, GlobalSign certificates, SendGrid, CodeTwo, Jscape, Files.com, Dropbox, LastPass, and collaboration tools as needed.Map critical workflows and dataflows across edge, firewall, application, database, ERP, identity, and cloud layers to identify dependencies, bottlenecks, and operational risks.Collaboration, Documentation & MentorshipPartner with software engineering, QA, finance, operations, product, and executive stakeholders to align infrastructure decisions with business needs and customer commitments.Participate in change control, release planning, audit support, and compliance documentation with attention to cross-system and cross-network impacts.Mentor systems administrators through pairing, documentation, architecture reviews, and hands-on knowledge transfer without assuming direct people-management responsibilities.Identify team skill gaps and recommend training, certifications, and process improvements that raise the technical capability of the IT organization.QualificationsRequired Experience:Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field; equivalent professional experience may be considered.10+ years of hands-on experience across infrastructure engineering, systems administration, network engineering, cloud engineering, and/or security engineering.Demonstrated ability to independently diagnose and resolve complex multi-layer infrastructure problems across network, security, virtualization, identity, cloud, and application layers.Deep production experience with VMware vSphere, including ESXi, vCenter, vMotion, HA/DRS, storage, distributed networking, lifecycle management, and performance troubleshooting.Strong experience with Palo Alto Networks firewalls, including policy design, NAT, threat prevention, VPN/GlobalProtect, segmentation, and Panorama or equivalent management.Deep knowledge of Active Directory architecture and administration, including multi-forest environments, Group Policy, replication, DNS/DHCP, trusts, and hybrid identity with Microsoft Entra ID.Hands-on experience with Microsoft Azure infrastructure, hybrid architectures, Microsoft 365 administration, Exchange Online, Teams, SharePoint, conditional access, and MFA.Experience with backup, disaster recovery, and restore validation using Veeam or similar enterprise backup platforms.Strong understanding of networking fundamentals, including TCP/IP, VLANs, routing, switching, VPNs, load balancers, DNS, certificates, CDN/edge services, and email authentication such as SPF, DKIM, and DMARC.Experience supporting Windows Server and Linux environments, patch management, system hardening, monitoring, and operational documentation.Working knowledge of compliance and security frameworks such as SOC2, NIST, and FedRAMP, especially as they relate to infrastructure controls and cloud readiness.

Back to Job Search