Trusted. Flexible. Secure. Helping organisations pay and get paid.
Infrastructure as Code Engineer
Location
United Kingdom
Posted
4 days ago
Salary
0
Seniority
Senior
Job Description
Infrastructure as Code Engineer
paygate
• Audit our existing AWS environment, including the current admin web application, and assess what should be preserved, wrapped or retired as part of the target design • Design and implement a modular, reusable Terraform codebase covering our core AWS infrastructure (compute, networking, storage, IAM and managed services), replacing manual/console-driven provisioning and the parts of the existing admin tool that fall outside a proper audit trail • Set up remote state management with locking (for example S3 and DynamoDB) and encryption at rest, and define access controls so state files are never stored locally or committed to version control • Build and integrate CI/CD pipelines that plan, validate and apply Terraform changes automatically, including automated policy and security scanning (Checkov, tfsec) on every pull request • Establish version control workflows, module structure and environment separation (dev/staging/prod and demo) so every infrastructure change is peer reviewed, logged and attributable to a person and a pull request • Embed our existing compliance obligations into reusable modules and pipeline checks: secure configuration and patch/update tracking relevant to Cyber Essentials Plus, access control and logging relevant to ISO 27001, and change control and data handling discipline relevant to our Bacs Approved Bureau status • Sequence the migration plan so it does not put ISO 27001 certification at risk, given our audit falls within this contract window. You are not responsible for managing or liaising on the audit itself, but the phasing, rollback approach and documentation must be aware of that date • Design and build an on-demand ephemeral environment capability: a full, isolated stack that a developer or QA engineer can spin up on demand, run a complete test pass against, and tear down automatically afterward • Ensure any fixture or seed data used in ephemeral test environments is synthetic or properly masked, not copied production data, given BAB rules on customer data handling and verification • Document architecture decisions, runbooks and module usage so the environment is maintainable after the engagement ends • Deliver hands-on training and workshops for the internal CTO, DevOps and infrastructure team, pairing with staff, including the lead DevOps engineer who built the current admin tool, on real migration work • Define a phased migration plan that brings existing infrastructure under code without service disruption, prioritising the highest risk manual and unaudited changes first • Produce a transition and handoff plan and knowledge transfer materials ahead of contract end, with a clear list of what the internal team owns going forward
Job Requirements
- Proven hands-on Terraform experience at an enterprise level: module design, state management, workspaces and multi-environment patterns, not just tutorial-level familiarity
- Deep working knowledge of AWS services: EC2, VPC, IAM, RDS/Aurora, ECS/EKS, Lambda, ELB, S3
- Experience building CI/CD pipelines for infrastructure (GitHub Actions, GitLab CI, Jenkins or CircleCI)
- Experience designing ephemeral/on-demand environments (PR- or job-triggered stack creation and teardown, database seeding from masked snapshots or synthetic fixtures, automated cost/resource cleanup)
- Scripting ability in Python and/or Bash for automation and tooling glue
- Experience with IaC security and compliance scanning tools (Checkov, tfsec or similar) and secrets management
- Experience embedding audit trails and change control evidence into infrastructure workflows, able to speak concretely to how Terraform plus CI/CD produces the traceability an unaudited admin script cannot
- Working familiarity with UK compliance regimes relevant to us: ISO 27001 controls (access control, logging, risk treatment), Cyber Essentials Plus control areas (secure configuration, patch management, access control), and Bacs Approved Bureau requirements around change control and data handling.
- Demonstrated experience training, mentoring or upskilling engineering teams; teaching ability is a hard requirement here, not a nice to have
- Experience leading or contributing to a brownfield migration (existing manual/bespoke automation to IaC), including the judgement to assess and diplomatically integrate with tooling already built by internal staff
- Strong written documentation skills, since your output is only as valuable as what the team can run without you afterward.
Benefits
- 25 days annual leave plus a day for your birthday or significant celebration
- Private Health Insurance
- Life Assurance at 4x base salary
- Enhanced company pension contribution
- Personal Travel Insurance
- Access to Benefiz benefits platform and a range of opt-in benefits
- Electric/Hybrid Vehicle scheme and Cycle to Work scheme
- 10-day rolling sick plan including extended illness pay
- EAP and Mental Health First Aider support
Related Guides
Related Categories
Related Job Pages
More Infrastructure Engineer Jobs
• Help build, manage, and scale Openstack compute and storage infrastructure. • Work remotely with team members in various time zones. • Contribute to the Openstack team by leveraging strong knowledge of infrastructure systems and experience with troubleshooting.
Role Description As a Distinguished Systems and Infrastructure Engineer, you will: - Provide overall direction by analyzing business objectives and customer needs. - Develop, communicate, build support for, and implement business strategies, plans, and practices. - Analyze costs and forecasts and incorporate them into business plans. - Determine and support resource requirements. - Evaluate operational processes and measure outcomes to ensure desired results. - Identify and capitalize on improvement opportunities. - Promote a customer environment and demonstrate adaptability. - Sponsor continuous learning. Requirement and Scoping Analysis: - Analyze the requirements/updates/modifications for alignment with business objectives and priorities. - Articulate the impact of the proposed solution on business and its ability to address requirements. - Mediate conflicting requirements of the various stakeholders. - Guide teams to assess feasibility of new requirements. - Prioritize the product/solution requirements to drive creation of Minimum Viable Product (MVP). - Proactively identify areas for product enhancements, new features, and updates based on customer requirements/feedback. - Contribute to the creation of user stories for complex requirements across the domain (for agile methodology). Architecture Acumen: - Decompose the product/platform architecture into multiple components and modules. - Define architectural specifications for each module. - Design the plan for customizing the product/platform architectural layout. - Define the architecture blueprint for the product/solution/platform. - Prepare architecture documents and presentations defining the rationale and implications of architectural decisions. - Evaluate system performance and scalability and provide tuning recommendations. - Identify the tech stack for the product in line with business needs and technology strategy. Infrastructure Design: - Understand business requirements in detail and translate into architectural requirements relevant for all systems within a domain. - Decompose the system architecture into multiple components and modules. - Design solutions that encompass multiple applications/modules/business processes/functionality for large scale systems. - Create detailed design for multiple systems within a domain, making architectural decisions impacting the entire domain. - Define success criteria and guiding principles to evaluate solution design. - Introduce appropriate security guidelines and processes to ensure adherence to security norms. Develop and leverage internal and external partnerships and networks to maximize the achievement of business goals: - Sponsor and lead key community outreach and involvement initiatives. - Engage key stakeholders in the development, execution, and evaluation of appropriate business plans and initiatives. - Support associate efforts in these areas. Coding: - Select appropriate frameworks (e.g., ActiveX, .Net, Cocoa, Android application framework, etc.). - Guide the team on coding patterns, languages, and frameworks in line with evolving trends in the industry. - Drive scalability and security. Telecommuting/work from home permitted. Qualifications - Bachelor's degree or the equivalent in computer science, information technology, engineering, or a related field plus 6 years of experience in systems and infrastructure engineering or related experience. - OR 8 years of experience in systems and infrastructure engineering or related experience. Requirements - Experience with developing roadmaps and strategies. - Providing technical oversight and leading teams for Authentication, SSO, MFA, and identity Governance and Privileged Access Management. - Designing and implementing Authentication solutions for Enterprise using OAuth, OIDC, SAML, and legacy protocols using Ping Federate, Azure Entra, ADFS, Broadcom Siteminder, and Oracle SSO. - Designing and implementing Multi-Factor Authentication solutions for Enterprise using TOTP, SMS, FIDO2, and SmartCard based methods and protocols. - Designing, architecting, and implementing Privileged Identity Management solutions using CyberArk, CA PAM, Beyond Trust, and Azure PIM. - Designing, architecting, implementing, and delivering Identity Lifecycle Management and Governance for the Enterprise using IBM ISIM, Oracle IDM, Azure IGA, CA Identity Manager. - Coding in an object-oriented programming language (C++, C#, JSP), HTML, and scripting languages (Perl, PowerShell, Unix shell scripting). - Designing and architecting Directory Services and Databases for the Enterprise using Sun LDAP, CA Directory, AD, IBM Directory Services, Azure Graph, SQL Server, Oracle DB, IBM DB2. - Designing, architecting, and implementing security solutions for the enterprise using Zero Trust Architecture. Benefits - Competitive pay as well as performance-based incentive awards. - Health benefits include medical, vision, and dental coverage. - Financial benefits include 401(k), stock purchase, and company-paid life insurance. - Paid time off benefits include PTO (including sick leave), parental leave, family care leave, bereavement, jury duty, and voting. - Other benefits include short-term and long-term disability, education assistance with 100% company paid college degrees, company discounts, military service pay, adoption expense reimbursement, and more. - Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. - Benefits are subject to change and may be subject to specific plan or program terms.
Infrastructure as Code Engineer
Vesta Software GroupThey buy and sell. We acquire, invest and grow... forever!
• Audit our existing AWS environment, including the current admin web application, and assess what should be preserved, wrapped or retired as part of the target design • Design and implement a modular, reusable Terraform codebase covering our core AWS infrastructure (compute, networking, storage, IAM and managed services), replacing manual/console-driven provisioning and the parts of the existing admin tool that fall outside a proper audit trail • Set up remote state management with locking (for example S3 and DynamoDB) and encryption at rest, and define access controls so state files are never stored locally or committed to version control • Build and integrate CI/CD pipelines that plan, validate and apply Terraform changes automatically, including automated policy and security scanning (Checkov, tfsec) on every pull request • Establish version control workflows, module structure and environment separation (dev/staging/prod and demo) so every infrastructure change is peer reviewed, logged and attributable to a person and a pull request • Embed our existing compliance obligations into reusable modules and pipeline checks: secure configuration and patch/update tracking relevant to Cyber Essentials Plus, access control and logging relevant to ISO 27001, and change control and data handling discipline relevant to our Bacs Approved Bureau status • Sequence the migration plan so it does not put ISO 27001 certification at risk, given our audit falls within this contract window. You are not responsible for managing or liaising on the audit itself, but the phasing, rollback approach and documentation must be aware of that date • Design and build an on-demand ephemeral environment capability: a full, isolated stack that a developer or QA engineer can spin up on demand, run a complete test pass against, and tear down automatically afterward • Ensure any fixture or seed data used in ephemeral test environments is synthetic or properly masked, not copied production data, given BAB rules on customer data handling and verification • Document architecture decisions, runbooks and module usage so the environment is maintainable after the engagement ends • Deliver hands-on training and workshops for the internal CTO, DevOps and infrastructure team, pairing with staff, including the lead DevOps engineer who built the current admin tool, on real migration work • Define a phased migration plan that brings existing infrastructure under code without service disruption, prioritising the highest risk manual and unaudited changes first • Produce a transition and handoff plan and knowledge transfer materials ahead of contract end, with a clear list of what the internal team owns going forward
• Design, implement, and maintain scalable, reliable infrastructure in AWS • Operate and improve Kubernetes-based environments, including production workloads • Build and maintain infrastructure as code using Terraform • Improve CI/CD pipelines, deployment workflows, and release automation in partnership with engineering teams • Build and maintain the packaging and reference architectures customers use to install our software in their own environments • Strengthen observability across the platform, including monitoring, logging, alerting, and actionable dashboards • Improve developer experience through tooling, environment automation, and self-service infrastructure • Operate within and preserve the established security and compliance posture of our environments • Monitor, troubleshoot, and resolve complex infrastructure issues with clear and timely communication • Participate in incident response and post-incident analysis • Develop and maintain documentation, runbooks, and technical standards • Identify opportunities to improve cost efficiency, performance, and resilience across environments




