Lead Engineer - L3 Middleware
Skills
About the role
Presidio, Where Teamwork and Innovation Shape the Future
At Presidio, we're at the forefront of a global technology revolution, transforming industries through cutting-edge digital solutions and next-generation AI. We empower businesses - and their internal customers - to achieve more through innovation, automation, and intelligent insights.
KEY RESPONSIBILITIES
Escalation & Complex Incident Resolution
Serve as the definitive escalation authority for all P1/P2 incidents across the middleware stack
Lead war-room bridge calls; drive structured incident resolution with clear action plans and stakeholder communication
Perform deep-dive root cause analysis (RCA) using heap dump analysis, GC log review, network traces, and vendor diagnostic tools
Engage IBM and Oracle vendor support (PMR/SR) with detailed diagnostic packages; drive cases to resolution
Author comprehensive post-incident reports (PIR) with permanent corrective actions, timeline analysis, and SLA impact assessment
Establish and maintain the escalation runbook library; coach L1/L2 on escalation procedures and decision trees
IBM WebSphere Application Server
Design and maintain WAS Network Deployment cell topologies, high-availability configurations, and session persistence strategies
Perform advanced JVM tuning: GC policy selection (gencon, balanced), heap sizing, compressed references, JIT optimization
Diagnose complex class loader conflicts, memory leaks, thread contention, and connection pool exhaustion using IBM GCMV, IBM Thread and Monitor Dump Analyzer, and Eclipse MAT
Design and oversee WAS to WebSphere Liberty or OpenShift migration blueprints
Implement and validate security configurations: LDAP, RACF, SSL/TLS mutual authentication, JAAS, application security policies
Provide architecture guidance for WAS ND clustering, HTTP server (IHS) plug-in configuration, and WebSphere eXtreme Scale (WXS)
IBM MQ
Design IBM MQ cluster architectures including full repository, partial repository, and gateway queue managers
Architect MQ high-availability solutions: MQ multi-instance queue managers (RDQM), MQ HA with NFS/GPFS, MQ on OpenShift
Troubleshoot MQ cluster routing, message affinity issues, back-out threshold failures, and channel security (TLS/CHLAUTH)
Implement MQ Advanced Message Security (AMS), TLS mutual authentication, and channel authentication rules
Diagnose and resolve complex MQ performance bottlenecks: disk I/O saturation, channel congestion, large message handling
Architect migration path from on-premises MQ to IBM MQ on OpenShift or IBM Cloud Pak for Integration
IBM API Connect
Architect IBM API Connect v10 deployments on OpenShift: Management, Analytics, Developer Portal, and Gateway subsystem sizing and HA design
Design API lifecycle governance: version management, rate limiting, OAuth 2.0 / OIDC security schemes, API product publishing
Troubleshoot complex API policy assembly failures, GatewayScript errors, and DataPower integration issues
Implement API observability: custom analytics dashboards, alerting, correlation with backend service traces
Lead API Connect cluster upgrades, certificate rotation procedures, and disaster recovery testing
IBM DataPower Gateway
Architect multi-domain DataPower deployments for DMZ, internal, and B2B integration patterns
Design and troubleshoot complex XSLT transformations, GatewayScript policies, Web Service Proxies, and Multi-Protocol Gateways (MPGW)
Implement advanced security policies: XML threat protection, schema validation, WS-Security, OAuth token enforcement
Diagnose performance bottlenecks using DataPower probe, latency graphs, and IBM Support Advisor
Architect DataPower Gateway Operator deployment on OpenShift; manage DataPowerService CR lifecycle
IBM Event Streams (Apache Kafka)
Architect IBM Event Streams (Kafka) cluster topologies for throughput, fault tolerance, and geo-replication
Tune broker configurations: replication factor, ISR settings, log retention, consumer group rebalancing, and compaction policies
Diagnose consumer lag escalations, partition leadership imbalances, under-replicated partition alerts, and ZooKeeper/KRaft quorum issues
Design Kafka Connect pipelines, Schema Registry integration, and MirrorMaker 2 replication for DR
Implement Kafka security: mTLS, SASL/SCRAM, topic-level ACLs, and network policies on OpenShift
Lead Event Streams operator upgrades, topic schema migrations, and Kafka version upgrades on OpenShift
Oracle WebLogic & Service Bus
Architect Oracle WebLogic Server (WLS) domains: Administration Server, Managed Servers, Cluster configuration, and Node Manager HA
Design and tune WebLogic JVM parameters: heap, metaspace, GC policy, Work Manager thread priorities
Diagnose complex WLS issues: stuck threads, slow drains, deployment failures, EJB/JPA performance, JDBC multi-data-source failover
Architect Oracle Service Bus (OSB) pipeline patterns: message routing, content-based routing, SLA alerting, error handling frameworks
Troubleshoot OSB proxy service failures, business service timeouts, WS-Security policy mismatches
Design migration path from Oracle WebLogic/OSB to containerized Java runtimes on OpenShift (Quarkus, Liberty, Helidon)
OpenShift Platform & Middleware Migration
Lead end-to-end middleware platform migration to OpenShift Container Platform (OCP 4.x)
Design target-state architecture: Operator-based middleware management (IBM MQ Operator, DataPower Operator, Event Streams Operator, WebSphere Liberty Operator)
Define namespace strategy, resource quotas, pod disruption budgets, node affinity rules, and storage class selection for stateful middleware
Establish GitOps-based middleware configuration management using ArgoCD/Tekton pipelines
Design persistent storage architecture for stateful workloads: OpenShift Data Foundation (ODF), NFS, block storage for MQ, WAS, Kafka
Implement OpenShift network policy for middleware service mesh, ingress/egress controls, and TLS termination via Routes/Ingress
Lead containerization of legacy WAS ND workloads using IBM WebSphere Migration Toolkit and Transformation Advisor
Define migration waves, cut-over strategies, fallback plans, and parallel-run testing frameworks
Establish observability stack: OpenShift monitoring (Prometheus/Grafana), log aggregation (EFK/Loki), distributed tracing (Jaeger/Zipkin)
Architecture Governance & Advisory
Serve as the Subject Matter Expert (SME) for all middleware technology decisions within the managed services engagement
Conduct quarterly architecture reviews: capacity planning, technology currency assessments, EOL/EOS risk reviews
Define middleware standards, design patterns, integration blueprints, and reference architectures for client organizations
Drive FinOps discipline for middleware workloads on OpenShift: resource right-sizing, license optimization, cost allocation
Participate in pre-sales and solution design activities for new managed services engagements
REQUIRED QUALIFICATIONS
Education & Experience
Bachelor’s degree in computer science, Software Engineering, or equivalent (advanced degree preferred)
10+ years of enterprise middleware platform engineering, architecture, and operations experience
5+ years of hands-on experience with IBM middleware products (WAS, MQ, API Connect, DataPower, Event Streams) in production environments
3+ years of experience with Oracle WebLogic and/or Oracle Service Bus in enterprise-grade deployments
3+ years of OpenShift or Kubernetes platform engineering experience including middleware workload containerization
Demonstrated experience leading P1 incident resolution and RCA for mission-critical middleware platforms
Proven track record of middleware platform migrations (on-premises to container / cloud)
Technical Depth
Deep expertise in JVM internals: memory management, GC algorithms, class loading, thread lifecycle
Proficiency with diagnostic tools: IBM GCMV, Eclipse MAT, IBM Thread and Monitor Dump Analyzer, JProfiler, VisualVM, yourkit
Strong Linux/Unix systems administration: kernel tuning, network stack, disk I/O performance, security hardening
Proficiency in scripting: Bash, Python, or Groovy for automation of middleware operations tasks
Deep knowledge of integration patterns: messaging, pub/sub, API gateway, ESB, event streaming, synchronous/asynchronous patterns
OpenShift/Kubernetes: Operators, Helm, CRDs, RBAC, network policies, persistent volumes, StatefulSets
CI/CD and GitOps: Jenkins, Tekton, ArgoCD, GitHub Actions
Security: PKI/TLS management, OAuth 2.0, OIDC, SAML, Kerberos integration with middleware platforms
PREFERRED CERTIFICATIONS
IBM Certified Solution Architect – IBM Cloud Pak for Integration
IBM Certified System Administrator – WebSphere Application Server (Advanced)
IBM Certified MQ Administrator
IBM Certified Associate Developer / Administrator – IBM DataPower Gateway
Oracle Certified Master – Java EE Enterprise Architect or Oracle WebLogic Server
Red Hat Certified Architect (RHCA) or Red Hat Certified OpenShift Administrator (EX280)
Red Hat Certified Specialist in OpenShift Application Development
Certified Kubernetes Administrator (CKA) or Certified Kubernetes Application Developer (CKAD)
ITIL 4 Strategist or ITIL 4 Managing Professional
BEHAVIORAL COMPETENCIES
Executive presence: ability to communicate complex technical issues clearly to C-suite and senior stakeholders
Crisis leadership: calm, decisive, and authoritative during major incidents with high business impact
Mentorship and knowledge transfer: proactive in upskilling L1/L2 engineers through coaching, shadowing, and documentation
Strategic mindset: balances tactical operational demands with longer-term platform modernization roadmap
Vendor management: skilled at driving IBM, Oracle, and Red Hat support organizations toward swift resolution
Collaborative: works effectively across organizational boundaries (application teams, network, security, infrastructure)
Commitment to continuous improvement: drives automation, self-healing, and observability maturity initiatives
Your future at Presidio
Joining Presidio means stepping into a culture of trailblazers - thinkers, builders, and collaborators - who push the boundaries of what's possible. With our expertise AI-driven analytics, cloud solutions, cybersecurity, and next-gen infrastructure, we enable businesses to stay ahead in an ever-evolving digital world.
Here, your impact is real. Whether you're harnessing the power of Generative AI, architecting resilient digital ecosystems, or driving data-driven transformation, you'll be part of a team that is shaping the future.
Ready to innovate? Let's redefine what's next-together.
About Presidio
Presidio is committed to hiring the most qualified candidates to join our amazing culture. We aim to attract and hire top talent from all backgrounds, including underrepresented and marginalized communities. We encourage women, people of color, people with disabilities, and veterans to apply for open roles at Presidio. Diversity of skills and thought is a key component to our business success.
At Presidio, speed and quality meet technology and innovation. Presidio is a trusted ally for organizations across industries with a decades-long history of building traditional IT foundations and deep expertise in AI and automation, security, networking, digital transformation, and cloud computing. Presidio fills gaps, removes hurdles, optimizes costs, and reduces risk. Presidio's expert technical team develops custom applications, provides managed services, and enables actionable data insights and builds forward-thinking solutions that drive strategic outcomes for clients globally. For more information visit
Applications will be accepted on a rolling basis.
Presidio is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to recruitment@presidio.com and let us know the nature of your request and your contact information.
Presidio is a VEVRAA Federal Contractor requesting priority referrals of protected veterans for its openings. State Employment Services, please provide priority referrals to.
Notice of Massachusetts Candidates: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Recruitment Agencies, Please Note: Presidio does not accept unsolicited agency resumes/CVs. Do not forward resumes/CVs to our career's email address, Presidio employees or any other means. Presidio is not responsible for any feeds related to unsolicited resumes/CVs.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.