Systems Engineer
About this role
Our Systems Engineering team owns the infrastructure that keeps a ~2,500-person global firm running around the clock: cloud (primarily AWS), Microsoft 365, Windows Server, identity platforms (Entra ID, Active Directory, SailPoint), and enterprise email flow. We are in the middle of a deliberate shift from click-ops to modern engineering practice: infrastructure as code, version control, CI/CD, cloud infrastructure, least-privilege identity, and AI-assisted workflows.
We're hiring a System Engineer to help drive that shift. You'll operate and harden the current stack while actively replacing manual, one-off work with automation and repeatable, reviewable process. We're looking for a DevOps/SRE mindset: someone who sees a manual runbook and wants to turn it into code, contributes to technical standards, and uses AI to move faster than the team could before.
Just as important, we want someone who questions why things are the way they are. Much of our stack was inherited; some of it is legacy or dependent on one person's knowledge. You should be comfortable looking at an established design, asking whether there's a better way, and making the case for change, grounded in a clear-eyed read of the pros, cons, and migration trade-offs, not change for its own sake.
This is a broad remit: identity and access, email flow, cloud, and core infrastructure. We're not expecting you to arrive an expert in every one. We are looking for someone comfortable stepping into each area, learning fast, and growing into full ownership over time.
What you'll do
- Automate and operate core infrastructure across AWS, Microsoft 365, and Windows Server, with reliability, security, and least privilege as defaults.
- Engineer identity and access across our identity platforms (Entra ID, Active Directory / Domain Controllers, and SailPoint), including provisioning, governance, and least-privilege models on-prem and in the cloud.
- Own and improve enterprise email flow: Exchange Online, our secure email gateway, and email authentication (SPF, DKIM, DMARC) across first- and third-party sending platforms.
- Evaluate inherited architecture and legacy tooling, ask why it works the way it does, and propose better approaches, backed by honest pros, cons, and migration trade-offs.
- Contribute to the move to infrastructure as code: build and maintain declarative infrastructure (our stack is OpenTofu and Spacelift) so environments are version-controlled, peer-reviewed, and reproducible.
- Put your infrastructure and automation under version control (Git), and work in a pull-request review and CI/CD workflow.
- Support and extend our cloud footprint across AWS and Azure, including networking, identity, and workload migration.
- Participate in operational coverage and incident response for a 24/7 business spanning the world, then help write the postmortems and automate the fix so it doesn't recur.
- Use AI to troubleshoot, script, document, and design faster, and share what works with the team.
- Help raise the bar on security, reliability, documentation, and repeatability through code review and collaboration.
What we're looking for
- 3–5 years in systems / infrastructure / platform / SRE engineering.
- A DevOps/SRE mindset: you reach for automation and repeatable process over manual, one-off work, and can point to click-ops you've replaced (or want to replace) with code.
- You ask "why do we do it this way?" and push for something better, but you're honest about the trade-offs and know when a change is worth the effort and when it isn't.
- Solid scripting and automation skills (PowerShell and Bash required; Python, Javascript or similar a plus).
- Exposure to infrastructure as code (Terraform, Ansible, OpenTofu, etc.), and comfort (or eagerness to grow) working in Git with pull-request-based review.
- Strong working knowledge of the Microsoft ecosystem: Microsoft 365 and Windows Server.
- Comfort with identity platforms and identity security: Entra ID and Active Directory required; SailPoint or another identity governance tool a plus.
- Familiarity with enterprise email flow: Exchange Online, secure email gateways (e.g. Mimecast), and email authentication (SPF, DKIM, DMARC), or a strong foundation to grow into it.
- Cloud experience in AWS and/or Azure, including networking, identity, and core services. AWS is our primary platform.
- Networking fundamentals (DNS, DHCP, TCP/IP, VPN, firewalls).
- A security-first, least-privilege mindset.
- Curiosity about using AI tools to work faster and better.
- Clear communicator who collaborates well across a distributed team.
- Based on a 9–5 ET schedule, but realistic about infrastructure work: occasional after-hours or weekend maintenance windows and releases, a shared on-call rotation, and some flexibility to coordinate across US, European, and Indian time zones.
Nice to have
- Relevant certifications (AWS, Azure, SailPoint, Microsoft).
- CI/CD pipeline experience (GitHub Actions, AWS CodePipeline, or similar).
- Containers and orchestration (Docker, AWS ECS).
- Monitoring and observability tooling.
- Experience modernizing a traditional ops team.
Why this role
You'll be part of modernizing how a global firm runs its infrastructure, with real mandate and support to replace manual work with engineering. If you want to build automation, grow your DevOps/SRE skills, and push the frontier of AI-assisted operations rather than maintain the status quo, this is a place to do it. We invest in a learning, collaborative culture, and this role has room to grow.
What We Offer:
Benefits: All U.S. GLGers also have access to benefits such as:
- Comprehensive medical, dental and vision coverage effective on your first day of employment
- Flexible paid time off. No pre-determined limits on vacation time, plus 10 company holidays
- 401(k) and Roth 401(k) plans with an employer match (subject to annual limits & vesting)
- Tuition reimbursement program for eligible courses including language skills courses
- Paid parental leave, adoption and surrogacy reimbursement
- Free wellbeing support with the Calm app, Maven and EAP, and free long-term therapy & counselling assistance through Pathways
- Other work perks and benefits available based on final job location
Compensation: GLG is committed to fair and equitable compensation practices. Actual compensation is based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. Certain roles may also be eligible for incentive compensation.
About GLG / Gerson Lehrman Group
GLG is the world’s leading platform for trusted human expertise. We connect global decision-makers—from hedge fund managers and private equity partners to strategy leaders at Fortune 500s—with the specific, authoritative voices required to answer their most critical questions.
At GLG, you are an extension of our clients' core teams. You will work at the intersection of industries and global markets, navigating high-stakes challenges across the full spectrum of their strategic initiatives. Operating within the industry’s most trusted research environment, you’ll help our clients capture the nuanced perspectives that drive smarter, faster business outcomes.
We are a global team of pragmatic problem-solvers who mirror the intensity of the markets we serve. If you are driven by intellectual curiosity and a bias toward action, join us in reinventing the industry we invented.
Gerson Lehrman Group, Inc. (“GLG”) is an equal opportunity employer and will not discriminate against any employee or applicant on the basis of age, race, religion, color, marital status, disability, gender, national origin, sexual orientation, veteran status, or any classification protected by federal, state, or local law.
