←  Back to all vacancies

Lead System Administrator & Infrastructure

Apparel Group

Retail & FMCG

πŸ“ United Arab Emirates
πŸ’Ό Full-time
πŸ•’ Posted 11 days ago

Job description

Role Overview

Lead System Administrator & Infrastructure at Apparel Group. This is a strategic infrastructure leadership role responsible for the design, administration, and optimisation of a large-scale enterprise IT environment spanning multiple datacentres, cloud platforms, and global business units.

Role Purpose

IT Infrastructure & Systems is the primary technical owner of the organisation's on-premises and cloud infrastructure, responsible for maintaining the availability, security, and performance of a large-scale enterprise environment spanning 7,500 managed systems, 10,000 CrowdStrike-protected endpoints, and 11,000+ Microsoft 365 users. The role encompasses the full infrastructure stack β€” from VMware virtualisation and SAN storage through Active Directory, Microsoft 365, backup and disaster recovery, patch management, email security, cloud environments (Azure and Oracle OCI), and endpoint detection and response. The position serves as Level 3 technical escalation point for the Workplace Technology team and leads a portfolio of active infrastructure upgrade projects targeting end-of-life system remediation and security agent deployment.

Key Responsibilities

Virtualisation & Server Infrastructure

  • Administer VMware vCenter and ESXi infrastructure (v7.x and v8.x) across the 9-host server fleet β€” cluster management, vSphere HA/DRS configuration, resource pool management, and host patching within approved maintenance windows.
  • Provision new virtual machines aligned to workload requirements; monitor VM resource utilisation and implement right-sizing recommendations to optimise cluster performance and capacity.
  • Monitor physical host hardware health via iLO/iDRAC and vCenter hardware status; coordinate firmware and driver updates; manage hardware failures and vendor RMA processes.
  • Configure and maintain on-premises servers for both physical and virtualised workloads; diagnose server-level OS and application issues; apply security patches within approved windows.

SAN Storage Management

  • Administer the HPE MSA 2060 and MSA 2050 arrays β€” manage disk groups, virtual pools, volumes, and host mappings; monitor health and I/O performance; coordinate drive replacements and firmware updates.
  • Administer the Dell EMC VNX unified storage platform β€” manage storage pools, LUNs, file systems, and CIFS/NFS shares; coordinate with Dell EMC support for firmware and fault resolution.
  • Administer the Huawei Dorado all-flash array β€” manage storage pools, LUNs, host groups, and replication; monitor NVMe performance and capacity; coordinate Huawei support for upgrades.
  • Configure and manage SAN switch zoning, ISL links, and port assignments supporting the fibre channel fabric; monitor fabric health and resolve path failures between hosts and LUNs.
  • Monitor storage capacity trends across all arrays; forecast growth requirements and raise procurement proposals before capacity thresholds are reached.

Identity & Access Management

  • Administer Active Directory for 25,000+ user accounts β€” manage user lifecycle, group memberships, OU structure, and attribute management; conduct regular AD hygiene reviews for stale accounts and empty groups.
  • Design, configure, and maintain Group Policy Objects across all OUs β€” security settings, software deployment, desktop restrictions, and drive mapping; conduct regular GPO audits for conflicts and misconfigured inheritance.
  • Manage workstation, laptop, and server domain join; troubleshoot join failures and ensure correct OU placement and GPO application for all newly joined systems.
  • Manage and maintain the Azure AD Connect server β€” monitor sync cycles, diagnose and resolve synchronisation errors (object conflicts, attribute mismatches, connector failures), and manage password hash sync to Office 365.
  • Manage the AD audit framework β€” user activity logging, AD object change tracking, and file access audit logs; review audit reports for anomalies and produce compliance reports for management.
  • Administer enterprise DHCP servers β€” manage scopes, reservations, and exclusion ranges across all network segments; monitor utilisation, resolve IP conflicts, and maintain IPAM documentation.
  • Administer enterprise DNS servers β€” manage forward and reverse lookup zones, all record types, and conditional forwarders; troubleshoot resolution failures affecting authentication, applications, and internet access.

Print & File Server Management

  • Administer the enterprise print server β€” manage queues, share permissions, driver deployments, and print spooler health; deploy printers via Group Policy; resolve print failures and driver conflicts.
  • Manage the MyQ print management platform β€” configure Active Directory integration, quota management, pull-print queues, and cost reporting; troubleshoot MyQ agent and authentication failures.
  • Administer the Head Office and Bur Dubai file servers β€” manage shared folder structures, NTFS and share-level permissions, and ACL inheritance; conduct regular permissions audits for least-privilege compliance.
  • Configure and maintain DFS Replication between Head Office and Bur Dubai file servers; monitor replication health, resolve backlogs and conflicts, and validate data consistency between namespaces.
  • Manage file-level recovery from Shadow Copies, VSS snapshots, and Commvault restore jobs; validate restored data integrity and document recovery actions.

Patch & Application Management

  • Manage ManageEngine Patch Manager Plus for OS and third-party application patching across 7,500 systems spanning all regions β€” define approval workflows, test in pilot groups, schedule deployment windows, and report compliance.
  • Configure and manage PDQ Deploy for remote application deployments and patch packages β€” build packages, define target collections, schedule deployments, and investigate failed deployment root causes.
  • Generate patch compliance reports from ManageEngine and PDQ; identify and remediate non-compliant systems; report monthly compliance status to IT management.

Monitoring, Environmental Sensors & Alerts

  • Deploy and maintain NTI (Network Technologies Inc.) environmental sensors across datacentre and server rooms; monitor temperature, humidity, and power conditions; configure alert thresholds and notification policies.
  • Manage the EcoStruxure gateway for proactive monitoring of 2 UPS units and 2 cooling units; configure real-time incident notifications and coordinate with Facilities for physical event remediation.
  • Maintain holistic infrastructure monitoring across VMware, storage, Active Directory, backup, and network; review dashboards daily, investigate flagged events, and implement root-cause fixes to reduce recurring alert noise.

Backup & Disaster Recovery

  • Administer the Commvault data protection platform covering server backup, storage management, and tape library integration; configure plans, retention policies, and schedules; monitor jobs and validate integrity via restore tests.
  • Manage Druva InSync endpoint backup for senior and higher-level employees; administer enrolment, backup policies, retention, and restore requests; investigate missed backups and failed sync events.
  • Manage cloud-to-cloud Office 365 backup (mailboxes, SharePoint, OneDrive, Teams) for Grade 8 and above employees; configure schedules and retention; monitor job health and process restore requests.
  • Manage TigerBridge cloud replication for file server data; configure policies, monitor sync health, and validate consistency between on-premises file servers and the cloud target.
  • Maintain and test disaster recovery procedures for critical infrastructure; document RTO/RPO targets, validate runbooks, and conduct periodic DR tests to confirm recoverability.

Microsoft 365 Administration

  • Administer the enterprise Microsoft 365 tenant for 11,000+ users across all regions β€” tenant-level settings, security and compliance policies, service health monitoring, and administrative role assignments.
  • Manage individual user mailboxes β€” archive policies, litigation hold, quotas, forwarding, and delegation; assign and reclaim licences based on role requirements and licence budgets.
  • Create and manage shared mailboxes, meeting room mailboxes with booking policies, distribution lists, mail-enabled security groups, and Microsoft 365 Groups including lifecycle and ownership management.
  • Administer Microsoft Entra ID β€” user identities, app registrations, enterprise applications, guest access, Conditional Access policies, MFA enforcement, and sign-in risk monitoring.
  • Administer SharePoint Online and Microsoft Teams β€” site collections, permissions, storage quotas, external sharing policies, Teams governance, and meeting settings; support escalated site and team owner issues.
  • Manage licence allocation, Conditional Access policy configuration, and brand-specific Microsoft 365 policies across all brands and regions.
  • Administer CodeTwo Cloud Signature for centralised email signature management.

Email & Endpoint Security

  • Administer Mimecast email security β€” configure and tune email filtering, anti-spam, impersonation defence, URL scanning, and attachment sandboxing; manage quarantine, allow/block lists, and investigate blocked legitimate email.
  • Monitor Mimecast threat intelligence dashboards; investigate impersonation attempts, phishing campaigns, and malicious attachments; adjust policies to improve detection accuracy and report significant threats.
  • Manage CrowdStrike Falcon EDR across 10,000 systems β€” ensure 100% agent coverage, monitor the console

People looking at this role also searched

Report this job

⚑ Quick Apply

Create your account and upload your CV to apply for β€” takes less than a minute.

✨ Get a free AI ATS Score Report for your CV the moment you sign up.