Tier 3 Engineer

Denver or Green Bay
Job TypeDirect Hire
Remote TypeHybrid

Position summary

The Tier 3 Engineer is the senior-most technical escalation point within our Managed Services team. The role owns three things: resolution of the incidents Tier 1 and Tier 2 cannot close, formal problem management and root-cause elimination on recurring issues, and the technical standards that govern how our managed client environments are built and secured.

The role also serves as design authority on client projects and net-new implementations — reviewing and approving solution design, scope, and cutover planning, and taking hands-on lead on a bounded number of high-complexity builds each year. Day-to-day project delivery is owned by the project and implementation team so that escalation response is not compromised.

The ideal candidate combines deep expertise across Microsoft cloud and on-premises infrastructure, networking, and security with the communication skills to explain a problem and its remedy to a business owner, and is comfortable operating with a high degree of autonomy across many client environments.

 

Escalation and root-cause ownership

       Serve as the final technical escalation point for complex, high-severity, and recurring incidents raised by Tier 1/Tier 2 engineers, the NOC, and monitoring alerts.

       Own formal problem management: perform root-cause analysis on recurring and systemic issues, implement permanent fixes rather than workarounds, and close the loop by updating monitoring, automation, and documentation so the issue cannot recur unnoticed.

       Lead technical response for major incidents — multi-user or multi-site outages, core network and identity failures, and security events including account compromise, business email compromise, and ransomware — covering containment, recovery, and post-incident review.

       Actively reduce escalation volume at the source: identify what is reaching Tier 3 that should have been resolved one tier down, then close that gap with tooling, automation, documentation, or targeted training.

       Meet response and resolution SLA targets on high-severity escalations, and maintain accurate, auditable ticket notes and time entry.

 

Standards, architecture, and security

       Own the technical standards for supported client environments — reference configurations, security hardening baselines, backup and recovery standards, and documentation conventions — and drive environments that have drifted back to standard.

       Design and maintain identity and access architecture across client tenants: Entra ID, Conditional Access, MFA and passwordless, privileged access, and least-privilege models.

       Own the security engineering side of the stack: EDR/XDR deployment and tuning, Microsoft Defender configuration, email security, patch management, and vulnerability remediation.

       Design, deploy, and maintain core client infrastructure: Windows Server, Active Directory, Microsoft 365, Azure, virtualization (Hyper-V and/or VMware), and backup and disaster recovery.

       Configure and maintain network infrastructure across client sites: firewalls, switching, routing, VPN, wireless, and SD-WAN or SASE where deployed.

       Verify that backup and disaster recovery actually work — scheduled restore testing, immutable or air-gapped copies, documented RTO/RPO per client, and recovery runbooks that someone else can execute.

       Support client security reviews, cyber-insurance attestations, and compliance evidence requests relevant to client verticals (HIPAA, CMMC/NIST 800-171, PCI-DSS, CIS benchmarks).

 

Project and solution design

       Act as design authority on net-new client implementations and major infrastructure projects: review and approve solution design, scope, dependencies, and cutover and rollback planning.

       Provide technical review and risk assessment during pre-sales and scoping alongside sales and project management, so that what gets committed is deliverable as scoped and priced.

       Take hands-on lead engineer responsibility on a bounded number of high-complexity or first-of-kind implementations each year, where design risk warrants senior ownership end to end.

       Ensure every completed project transitions cleanly into managed services — documentation, monitoring, alerting, and a support handoff that Tier 1 and Tier 2 can actually run.

 

Enablement and mentorship

       Raise Tier 1 and Tier 2 capability deliberately: knowledge-transfer sessions, ride-alongs, and walking escalations back through the engineer who raised them.

       Convert repeat fixes into documentation, runbooks, and automation in our documentation platform so the next occurrence is resolved at Tier 1 or Tier 2.

       Maintain accurate technical documentation, network diagrams, and standard operating procedures for managed client environments.

       Contribute to technical assessment of service desk and engineering candidates during hiring.

 

Automation and continuous improvement

       Automate recurring administrative and remediation work using PowerShell and RMM scripting, and maintain what you build.

       Improve monitoring and alerting so that problems are detected and remediated before clients notice them, and tune out alert noise that trains the team to ignore alarms.

       Recommend improvements to our managed services stack, standards, and processes based on what you see failing in the field.

 

How success is measured

This role is not measured primarily on ticket volume closed. Within the first year we expect to see:

       Re-escalation and reopen rates on Tier 3 tickets trending down.

       A measurable reduction in recurring and repeat tickets in the environments you own.

       Escalation rate from Tier 2 declining as documentation, tooling, and training close known gaps.

       Standards and documentation coverage across managed clients, with identified drift actively remediated.

       Backup and disaster recovery restore testing completed and documented on schedule for every managed client.

       SLA attainment on high-severity escalations and major incidents.

       Project designs delivered without post-go-live rework attributable to design gaps.

 

Required qualifications

       5+ years of experience in an MSP, IT consulting, or multi-client infrastructure environment, including at least 2 years functioning as a senior or escalation-level resource.

       Demonstrated ownership of root-cause analysis on systemic problems. You should be able to walk us through a specific recurring failure you diagnosed and permanently eliminated, and how you proved it was fixed.

       Expert-level Windows Server administration, Active Directory, Group Policy, DNS/DHCP, and certificate services fundamentals.

       Strong hands-on Microsoft 365 and Entra ID administration: Exchange Online, Intune, SharePoint and Teams, and Conditional Access.

       Working Azure infrastructure competence: virtual machines, virtual networking, RBAC, and cloud backup.

       Solid networking fundamentals — TCP/IP, VLANs, routing and switching — with hands-on configuration of business-class firewalls and both site-to-site and remote-access VPN.

       Working proficiency with PowerShell for administration and automation. At this level this is a requirement, not a bonus.

       Practical security engineering experience: EDR/XDR, email security, MFA, patch and vulnerability management, and real incident response.

       Ability to explain a technical problem, its cause, and its remediation clearly to a non-technical business owner, both in writing and live.

       Disciplined documentation and time-entry habits in a PSA, RMM, and IT documentation toolset.

       Strong troubleshooting methodology and the ability to prioritize multiple concurrent escalations under pressure without losing track of commitments.

       Valid driver’s license and reliable transportation for occasional travel to client sites.

 

Depth preferred in several of the following

We are not looking for a candidate who has all of these. Genuine depth in several, plus the judgment to know what you do not know, matters more than shallow familiarity with everything.

       Virtualization at scale — Hyper-V and/or VMware, including host lifecycle and shared storage.

       Enterprise backup and DR platforms (for example Veeam or Datto) with a track record of proven, tested restores.

       SD-WAN, SASE, or zero-trust network access design and deployment.

       Multi-tenant security operations — Microsoft Defender XDR, Microsoft Sentinel, or working alongside an outsourced SOC/MDR provider.

       Compliance-driven client environments: HIPAA, CMMC/NIST 800-171, PCI-DSS, or CIS benchmark implementation.

       Co-managed engagements where an internal client IT team shares ownership of the environment.

       Infrastructure-as-code or configuration management, and version control habits around scripts you write.

       Line-of-business application integration in manufacturing, healthcare, finance, or professional services.

       Prior experience mentoring or leading junior technical staff.

       True MSP background — working across many diverse client environments simultaneously rather than a single-organization IT role.

 

Preferred certifications

Candidates are not required to hold any of the certifications below, and we do not screen on certifications alone. Current or in-progress credentials in these areas are meaningful. Microsoft and Fortinet both restructured their certification programs during 2026, so current equivalents are accepted in place of any specific exam code listed here.

       Microsoft — Microsoft 365 and identity: MS-102 (retiring October 2026; successor exam AB-650), MD-102, or SC-300.

       Microsoft — Azure and security: AZ-104, SC-200, or SC-500 (successor to AZ-500, which retires August 31, 2026).

       Networking and firewall: Cisco CCNA, Fortinet NSE 4 or higher in a relevant track, or an equivalent vendor credential for the firewall platforms we support.

       Security and process: CompTIA Security+ or CySA+, and ITIL 4 Foundation.

       Virtualization and backup: VMware VCP, Veeam VMCE, or equivalent.

 

How we protect this role

We are explicit about this because senior engineers are routinely hired into escalation roles and then buried in work that belongs one tier down.

       Tier 3 is not the overflow queue for Tier 2. Tickets escalate on complexity and required access scope, not on queue depth.

       A recurring escalation is treated as a defect in our documentation, tooling, or training. Fixing that cause is part of this job, not a distraction from it.

       Protected time is allocated for problem management, standards work, and automation. It is not whatever is left over after the escalation queue is clear.

       On-call is shared across the engineering team on a published rotation. It is not absorbed by whoever happens to be most senior.

       This role carries a productive-time expectation, as every client-facing role here does. Problem management, root-cause work, documentation, standards, and automation count toward it. We do not ask you to hit a utilization number by pushing the structural work into your own time.

 

Physical and work environment requirements

       Ability to lift and move IT equipment weighing up to 50 pounds — servers, network gear, and workstations — with or without reasonable accommodation.

       Ability to work in server rooms, data closets, and varied client office environments.

       Ability to sit, stand, and work at a computer for extended periods.

       Availability for scheduled after-hours maintenance windows and participation in the published on-call rotation, including response to critical after-hours incidents.

 

Drag & Drop Resume

(PNG, JPEG, PDF, DOC, TXT)

Message & data rates may apply to all numbers allowed to receive messages

Message frequency varies. Text STOP to opt-out or HELP for assistance