Sobre este puesto de Infrastructure Engineer en Cleveland Metropolitan School District
Position Type:
Administration and ProfessionalsDate Posted:
2026-09-14Location:East Professional CenterABOUT CLEVELAND METROPOLITAN SCHOOL DISTRICT
The Cleveland Metropolitan School District (CMSD) is Ohio's third-largest public school system, serving more than 35,000 students.
CMSD strives to ensure that every child receives a high-quality education, regardless of the provider. To that end, CMSD lets families choose which District schools their children attend, with options that include STEM, the arts, single-gender education, International Baccalaureate, Montessori, and early college.
Our schools have autonomy over human and financial resources in exchange for accountability for performance. The principal has primary responsibility and accountability for establishing their school as a high-quality, high-expectation academic center focusing on personalized instruction, professional support for teachers, and school-wide practices that lead to measurable results.
CMSD ensures that students have access to technology and training to prepare them for the future. The District provides a free laptop or tablet for every student and connects every family that needs internet access. Graduating seniors leave commencement with not only a diploma but also a laptop.
In our pursuit of a more fair, just, and good system of education, we strive to ensure that all of our learners, both scholars and educators, to be challenged with academically and intellectually complex tasks that are worthy of their efforts and provide them opportunities to demonstrate their best work.
BUILDING BRIGHTER FUTURES
The Cleveland Board of Education adopted the Building Brighter Futures (BBF) initiative on December 9, 2025. Building Brighter Futures is a strategic and data-driven plan shaped by more than a year of community engagement, information analysis, and thoughtful deliberation. The goal of this plan is to strengthen enrollment and ensure scholars attend a newer school building that offers more educational opportunities, including algebra in the eighth grade, more sports and extracurricular activities, and college credits and college and career pathways in high school. BBF is ensuring academic excellence so every CMSD scholar can thrive.
THE OPPORTUNITY:
Reports to: Infrastructure Solutions Architect
FLSA Status: Exempt
Salary Band: 7
Compensation: $ 68,891.00 - $ 93,003.00
**Internal applicants are required to upload a resume to their application**
The Infrastructure Engineer is the District's senior hands-on engineer for enterprise network and cloud infrastructure. Reporting to the Infrastructure Solutions Architect (ISA), the Engineer builds, configures, operates, and troubleshoots the platforms that carry every instructional and operational system in the District — the Cisco Meraki campus and wireless estate across all school sites, the data center and administrative network, the District's SD-WAN and carrier transport, and the network foundation of the Azure environment that now hosts the majority of District workloads.
Where the ISA sets architecture, standards, and roadmap, the Engineer implements those standards and owns day-to-day engineering outcomes: designs are turned into working configurations, changes are planned and executed within approved windows, and faults are isolated and resolved. The Engineer is expected to work independently on complex problems, to propose design alternatives back to the ISA with supporting analysis, and to serve as the District's deepest source of operational knowledge on the network estate.
As a secondary assignment, the Engineer serves as a backup and day-to-day implementer on the District's endpoint and device management platforms, and supports the District's remaining on-premises platform services — VMware vSphere, Active Directory Domain Services, DNS, file, print, and SMTP relay
— as legacy services, while continuing migration to Azure equivalents.
This is an individual contributor role. The Engineer provides technical guidance and mentorship to Specialists, Administrators, and building technicians, but does not carry supervisory responsibility; day-to-day task assignment and performance management sit with the ISA.
KEY RESPONSIBILITIES
Network Engineering and Operations
- Engineer, configure, deploy, and maintain the District's Networking estate: security appliances and their NextGen Layer 7 functions, Layer 3 distribution and Layer 2 access switches, and wireless access points across all school sites.
- Maintain Layer 3 services delivered at the site edge, including DHCP scopes, relay, and inter-VLAN routing hosted on the Layer 3 switches at each building.
- Engineer and support the data center and administrative network, including data center switching and routing platforms (OSPF/BGP as deployed), QoS, and network segmentation.
- Support the District's SD-WAN and WAN transport, site turn-ups, path policy, failover behavior, and carrier fault isolation and escalation.
- Implement and maintain network segmentation, access control lists, VPN services, and Network Access Control integrations in accordance with architecture standards and Cybersecurity requirements.
- Perform switch, firewall, and appliance firmware lifecycle management; plan and execute upgrades inside approved change windows.
- Support fiber and structured cabling projects with Facilities, Capital Improvements, and District contractors: validate designs, confirm circuit and patching records, and commission or decommission new, renovated, or repurposed buildings.
- Serve as the District's internal escalation point for network faults raised by IT Customer Excellence, building technicians, and site staff — the level above front-line support, below vendor engineering.
- Own the onward escalation path once District-side troubleshooting is exhausted: open and drive cases directly with the network platform support vendor and engage the District's network managed service provider for enterprise and data center network platforms. Provide the diagnostic detail the case requires, stay engaged through resolution, and confirm the fix rather than handing the fault off
Cloud Infrastructure Engineering (Azure)
- Own the network foundation of the District's Azure presence: ExpressRoute circuits, peering and gateways, the routing relationship between ExpressRoute and the District's SD-WAN transport, virtual network and subnet design, route tables, network security groups, and name resolution across the on-premises boundary.
- Engineer Azure IaaS in partnership with the Server Administrator and the District's managed service provider, who carry day-to-day administration: sizing, placement, connectivity, resiliency, and the design decisions that follow from District architecture standards.
- Assist in defining the backup, replication, and recovery configuration infrastructure workloads are held to — retention, recovery objectives, and replication targets — and validate that what is implemented and reported meets it; participate in recovery testing and document results.
- Support workload migration from on-premises platforms to Azure equivalent services: network readiness, dependency assessment, cutover execution, and post-migration validation, with the Server Administrator and the managed service provider.
- Provide depth behind the Server Administrator on Azure infrastructure work during absence, escalation, or a major incident.
- Validate that Azure work delivered by the managed service provider meets District architecture and security standards; provide technical input on capacity, performance, and cost.
- Apply infrastructure automation and Infrastructure-as-Code practices to network and connectivity builds where standards call for it; maintain scripts and runbooks to District coding standards
Wi-Fi Engineering and Surveying
- Deploy, tune, and troubleshoot District wireless in line with WLAN standards: channel and power plans, RF hygiene, roaming behavior, capacity in high-density spaces, and client-side troubleshooting across Chromebook, iPad, macOS, Windows, and Android device populations.
- Maintain the legacy wireless estate at school sites still served by Cisco Catalyst wireless LAN controllers and Aironet access points, and migrate them to the Meraki wireless standard as refresh funding allows.
- Conduct predictive, validation, and troubleshooting wireless surveys using Ekahau; produce survey output and remediation recommendations for ISA review.
Reliability, Monitoring, and Change Management
- Implement and maintain monitoring, alerting, and telemetry for network, cloud, and server infrastructure; tune alerting to reduce noise and surface real degradation.
- Execute changes through the District change management process; prepare implementation plans, test plans, and rollback criteria for review.
- Respect maintenance and change-freeze windows aligned to academic, graduation, and statewide testing calendars; schedule disruptive work accordingly.
- Contribute capacity, lifecycle, and refresh data to the ISA's planning and E-Rate cycles.
- Maintain accurate configuration, circuit, IP address management, and CMDB records; keep documentation current as a condition of closing work.
Data Center and Legacy Platform Operations Support
- Administer the VMware vSphere environment: hosts, clusters, virtual machine lifecycle, resource allocation, patching, and capacity monitoring.
- Maintain remaining on-premises Microsoft platform services — Active Directory Domain Services, DNS, file services, print services, and SMTP relay — as legacy services pending migration.
- Maintain the server, storage, and backup platforms remaining in the District data center; set the standards they run to and carry out lifecycle replacement and routine maintenance.
- Execute retirement and decommissioning of legacy systems as workloads transition to Azure, including dependency validation, cutover, and documentation updates.
- Assist in defining and maintaining disaster recovery and business continuity provisions for network, computing, and storage systems; verify recoverability through periodic exercises.
Endpoint and Device Management Platform Support
- Serve as backup and day-to-day implementer on District endpoint and device management platforms (Microsoft Intune and Autopilot, Apple School Manager, Jamf, Samsung Knox, Clevertouch MDM), executing configuration, enrollment, policy, and application distribution tasks to defined baselines.
- Support the network-side dependencies of those platforms: certificate and PKI distribution, 802.1X and NAC integration, secure Wi-Fi and VPN profiles, and connector health.
- Provide escalation support to the 1:1/Device Prep Team and Customer Excellence Specialists on platform issues with an
- infrastructure root cause.
Security and Compliance Support
- Implement infrastructure security controls defined with the Division of Cybersecurity and IT Risk Management & Compliance; apply hardening baselines and zero-trust patterns to network and cloud builds.
- Remediate infrastructure vulnerabilities on the priority and schedule set by Cybersecurity and the ISA; report exceptions with compensating controls.
- Support FERPA, CIPA, and District policy compliance in infrastructure configuration, including content filtering and logging dependencies.
- Provide technical analysis and evidence during network security incidents and audits.
Incident Response and After-Hours Support
- Participate in after-hours and weekend maintenance windows, cutovers, and emergency response; share on-call coverage for network and infrastructure outages.
- Serve as a technical responder on the ITOps network security incident response team; support triage, containment, recovery, and post-incident review under the ISA's coordination.
- Perform fault isolation with carriers, managed service providers, and vendors during outages, including fiber, power, and environmental events affecting site connectivity.
- Contribute to root cause analysis and corrective actions after significant incidents
Vendor, Managed Service Provider, and Documentation Support
- Work with vendors and managed service providers on implementation, escalation, and chronic issue remediation — principally Cisco Meraki support and the District's network managed service provider; validating that delivered work meets District standards and tracking open cases to closure.
- Contribute technical requirements, configuration details, and effort estimates to the ISA for RFPs/RFQs, evaluations, and proofs of concept.
- Create and maintain technical documentation, standard configurations, runbooks, and knowledge transfer materials for ITOps and Customer Excellence staff.
- Travel within the District as required; occasional out-of-District travel.
- Other duties as assigned by the supervisor.
MINIMUM QUALIFICATION
Education
- Bachelor’s degree in computer science, Information Technology, Engineering, or a related field, or equivalent work experience.
Work Experience
- 5 years of progressive experience engineering and operating enterprise-level network infrastructure in a multi-site environment.
- 3 years of hands-on experience with cloud infrastructure services, Azure preferred, including virtual networking and hybrid connectivity.
- 3 years’ experience with enterprise routing and switching, firewalls/UTM, and WAN or SD-WAN transport.
- 2 years’ experience administering virtualization and core Microsoft platform services (vSphere, Windows Server, Active Directory Domain Services, DNS).
- 2 years’ experience with enterprise wireless deployment, tuning, and RF troubleshooting, including use of survey tools (e.g., Ekahau).
- 1 year of exposure to endpoint/device management platforms in an operational or backup capacity.
- Experience participating in after-hours incident response and major outage recovery.
- K-12 or public sector experience, including E-Rate funded infrastructure, preferred.
Competency
- Works independently on complex technical problems; escalates with analysis, not just symptoms.
- Disciplined change practice — plans, tests, documents, and can back out cleanly.
- Clear written and verbal communication with technical peers, District staff, and vendors.
- Customer-focused and process-driven; protects instructional time in scheduling and execution.
- Collaborative across ITOps, Cybersecurity, Customer Excellence, and operational departments.
Technical Breadth
- Cisco Meraki full stack and Cisco Catalyst/Nexus platforms.
- Enterprise routing, switching, segmentation, QoS, VPN, and Network Access Control.
- Cisco Catalyst wireless LAN controllers and Aironet access points in a legacy support and migration context.
- SD-WAN and carrier WAN services, including circuit turn-up and fault isolation.
- Azure IaaS, virtual networking, ExpressRoute, backup and site recovery; Entra ID fundamentals.
- VMware vSphere, Windows Server, Active Directory Domain Services, DNS, file, print, and SMTP relay services.
- Monitoring and observability tooling; scripting and Infrastructure-as-Code (PowerShell preferred).
- Security fundamentals aligned to NIST and zero trust; familiarity with firewalls, IDS/IPS, NAC, and SIEM.
Preferred Certifications
- CCNA required or obtainable within the first year; CCNP Enterprise preferred.
- Cisco Meraki certification (CMNA/ECMS) preferred.
- Microsoft Azure Administrator Associate (AZ-104) or Azure Network Engineer Associate (AZ-700) preferred.
- Ekahau ECSE preferred.
- VMware VCP, Microsoft Windows Server certifications, ITIL Foundation, CompTIA Network+/A+ are a plus but not required.
Schedule and Travel Requirements
- On-call availability for critical incidents and after-hours emergency response.
- Regular evenings/weekends availability for maintenance windows and cutovers; flexibility in work hours contingent on District needs, including short notice and beyond school hours.
Working Conditions/Physical Demands
The characteristics listed below represent the work environment typically encountered while performing the essential duties of this position. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential duties.
- While performing the duties of this job, the employee is regularly required to stand, walk, and sit; use hands to finger, handle, or feel; and reach with hands and arms.
- The employee is frequently required to talk and/or hear.
- Standard office, technical room, data center, and active school building environments; frequent travel between a large number of school sites.
- Work in telecom closets and above-ceiling spaces; occasional ladder use and lifting of equipment up to 50 pounds.
NOTE: The above-stated duties are intended to outline those functions typically performed by individuals assigned to this classification. This description of duties is not intended to be all-inclusive or to limit the discretionary authority of management to assign other tasks of similar nature or level of responsibility.
Education
To Apply
EEO Statement
We believe that equity and inclusion at CMSD is an essential call to action, a catalyst to ensure value and appreciation among all our employees, so we may be fair and welcoming now and in the future. CMSD provides equal opportunities for employment, retention and advancement of all personnel by administering all terms and conditions of employment regardless of race, color, ethnicity, ancestry, national origin, sex, disability or genetic information, age, citizenship status, military status, sexual orientation or expression, socio-economic status, title, other dimensions of identity, or any other characteristic protected by law.
The District’s Policy Prohibiting Discrimination, Discriminatory Harassment, and Sexual Harassment and the District’s Title IX grievance procedures, including information on how to report or file a complaint of discrimination, how to report or file a formal complaint of sexual harassment, and how the District will respond, may be accessed on the District’s Civil Rights Notices webpage, available at ClevelandMetroSchools.org/domain/105. The District’s Title IX Coordinator / Director of Equal Employment Opportunity may be reached at:
1111 Superior Avenue East, Suite 1800
Cleveland, Ohio 44114
(216)-838-0070