MSP Systems Engineer
Mechanicus LLC has provided professional IT support and technology solutions to businesses in and around Irwin, Pennsylvania since 2010. We deliver enterprise-level expertise with the personalized service and practical approach small and midsized businesses need.
Our practice is security-forward by design. Rather than simply forwarding alerts to a third party, we take an active, hands-on approach to identifying risks, strengthening environments, and keeping our clients’ technology secure and reliable.
The Role
We’re looking for an MSP Systems Engineer (L3) to serve as the senior technical escalation point for complex infrastructure, cloud, and security challenges across our clients’ environments.
You’ll be the person we trust with our hardest problems, most complex environments, and most critical escalations. You’re the person Tier 2 calls when an impossible-travel alert turns out to be a real compromise, an AVD environment needs to be re-architected, or a client’s M365 tenant is compromised at 2 a.m. When things get difficult, you’re the one who steps in, takes ownership, and finds a way forward.
This isn’t simply a “senior tech” role. We’re looking for someone who thinks beyond the immediate ticket or incident. You’ll identify patterns across client environments, improve processes, strengthen documentation and training, and help reduce key-person risk. You’ll also play a key role in raising the technical bar across the team by bringing structure, consistency, and repeatability to the way we solve problems.
What You’ll Be Doing
Technical Leadership
- Serve as the Tier 3 escalation point for advanced technical issues
- Mentor junior engineers and contribute to technical standards
- Create documentation, operational runbooks, and repeatable processes
- Identify recurring problems and build long-term solutions
Security Operations & Incident Response
- Investigate phishing attacks, suspicious login activity, and account compromise incidents
- Perform threat hunting, log analysis, containment, and remediation
- Lead response efforts for Microsoft 365 and Azure-related security events
- Collaborate with security partners and vendors during active incidents
- Conduct post-incident reviews and improve prevention strategies
Microsoft 365 & Identity Security
- Design and improve Conditional Access policies and identity security controls
- Manage and optimize Microsoft Defender and Entra ID security features
- Implement security baselines and hardening standards across client environments
- Improve MFA, privileged access, and identity governance workflows
Cloud & Infrastructure Engineering
- Support and troubleshoot Azure infrastructure and Azure Virtual Desktop environments
- Handle complex escalations involving networking, virtualization, storage, and authentication
- Lead migrations involving Microsoft 365, Azure, servers, and cloud infrastructure
- Assist with automation and infrastructure-as-code initiatives
What We’re Looking For
- 5+ years of progressive IT experience, with at least 2 years of experience in security operations
- Incident response experience - you've worked a real BEC, a real ransomware incident, or a real account takeover end-to-end and can talk through the timeline, the decisions, and what you'd do differently.
- Strong Microsoft 365 security stack experience: Defender for Office 365, Defender for Endpoint, Defender for Identity, Entra ID Protection, Conditional Access at scale.
- Solid Azure fundamentals - Entra ID, AVD, networking (VNets, NSGs, Private Endpoints), RBAC, and at least familiarity with IaC (Bicep or Terraform).
- PowerShell at a functional scripting level - able to automate administrative tasks, work with Microsoft 365/Azure modules, and troubleshoot or modify existing scripts.
- Excellent written communication - incident reports, RCA documents, client-facing summaries that don't make a non-technical CFO panic.
Nice To Have
- Certifications: SC-200, SC-300, AZ-500 (mapped directly to our Microsoft Sentinel / Entra ID / Azure security work)
- Operational experience with Blackpoint Cyber MDR - incident handoff, isolation decisions, post-incident workflow with their SOC.
- Hands-on with our full operational stack:
- HaloPSA (PSA/ticketing)
- NinjaOne / NinjaRMM (RMM)
- CIPP (M365 multi-tenant admin)
- Hudu (documentation)
- Barracuda Email Protection policy management and incident response (BEC, mass-quarantine events).
- Experience designing CIS or NIST CSF-aligned baselines for SMB clients running Microsoft 365 and Azure.
HR Information
- Full-time, permanent role
- Salary: $80,000 – $110,000 depending on experience and certifications
- Annual performance bonus tied to security KPIs (mean time to detect, mean time to contain, recurring-incident reduction)
- Health insurance
- Simple IRA
- 12 days PTO to start (accrual increases with tenure) + 8 paid holidays
- Schedule: Mondays-Fridays, 8 AM-5PM Eastern Time
- Home office stipend
- Remote role - candidate must be based in the East Coast or Central US