Vesta Software Group logo
Vesta Software Group

They buy and sell. We acquire, invest and grow... forever!

Infrastructure as Code Engineer

Infrastructure EngineerInfrastructure EngineerFull TimeRemoteSeniorTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

United Kingdom

Posted

4 days ago

Salary

0

Seniority

Senior

Job Description

Infrastructure as Code Engineer

Vesta Software Group

• Audit our existing AWS environment, including the current admin web application, and assess what should be preserved, wrapped or retired as part of the target design • Design and implement a modular, reusable Terraform codebase covering our core AWS infrastructure (compute, networking, storage, IAM and managed services), replacing manual/console-driven provisioning and the parts of the existing admin tool that fall outside a proper audit trail • Set up remote state management with locking (for example S3 and DynamoDB) and encryption at rest, and define access controls so state files are never stored locally or committed to version control • Build and integrate CI/CD pipelines that plan, validate and apply Terraform changes automatically, including automated policy and security scanning (Checkov, tfsec) on every pull request • Establish version control workflows, module structure and environment separation (dev/staging/prod and demo) so every infrastructure change is peer reviewed, logged and attributable to a person and a pull request • Embed our existing compliance obligations into reusable modules and pipeline checks: secure configuration and patch/update tracking relevant to Cyber Essentials Plus, access control and logging relevant to ISO 27001, and change control and data handling discipline relevant to our Bacs Approved Bureau status • Sequence the migration plan so it does not put ISO 27001 certification at risk, given our audit falls within this contract window. You are not responsible for managing or liaising on the audit itself, but the phasing, rollback approach and documentation must be aware of that date • Design and build an on-demand ephemeral environment capability: a full, isolated stack that a developer or QA engineer can spin up on demand, run a complete test pass against, and tear down automatically afterward • Ensure any fixture or seed data used in ephemeral test environments is synthetic or properly masked, not copied production data, given BAB rules on customer data handling and verification • Document architecture decisions, runbooks and module usage so the environment is maintainable after the engagement ends • Deliver hands-on training and workshops for the internal CTO, DevOps and infrastructure team, pairing with staff, including the lead DevOps engineer who built the current admin tool, on real migration work • Define a phased migration plan that brings existing infrastructure under code without service disruption, prioritising the highest risk manual and unaudited changes first • Produce a transition and handoff plan and knowledge transfer materials ahead of contract end, with a clear list of what the internal team owns going forward

Job Requirements

  • Proven hands-on Terraform experience at an enterprise level: module design, state management, workspaces and multi-environment patterns, not just tutorial-level familiarity
  • Deep working knowledge of AWS services: EC2, VPC, IAM, RDS/Aurora, ECS/EKS, Lambda, ELB, S3
  • Experience building CI/CD pipelines for infrastructure (GitHub Actions, GitLab CI, Jenkins or CircleCI)
  • Experience designing ephemeral/on-demand environments (PR- or job-triggered stack creation and teardown, database seeding from masked snapshots or synthetic fixtures, automated cost/resource cleanup)
  • Scripting ability in Python and/or Bash for automation and tooling glue
  • Experience with IaC security and compliance scanning tools (Checkov, tfsec or similar) and secrets management
  • Experience embedding audit trails and change control evidence into infrastructure workflows, able to speak concretely to how Terraform plus CI/CD produces the traceability an unaudited admin script cannot
  • Working familiarity with UK compliance regimes relevant to us: ISO 27001 controls (access control, logging, risk treatment), Cyber Essentials Plus control areas (secure configuration, patch management, access control), and Bacs Approved Bureau requirements around change control and data handling
  • Demonstrated experience training, mentoring or upskilling engineering teams; teaching ability is a hard requirement here, not a nice to have
  • Experience leading or contributing to a brownfield migration (existing manual/bespoke automation to IaC), including the judgement to assess and diplomatically integrate with tooling already built by internal staff
  • Strong written documentation skills, since your output is only as valuable as what the team can run without you afterward.

Benefits

  • 25 days annual leave plus a day for your birthday or significant celebration
  • Private Health Insurance
  • Life Assurance at 4x base salary
  • Enhanced company pension contribution
  • Personal Travel Insurance
  • Access to Benefiz benefits platform and a range of opt-in benefits
  • Electric/Hybrid Vehicle scheme and Cycle to Work scheme
  • 10-day rolling sick plan including extended illness pay
  • EAP and Mental Health First Aider support

Related Categories

Related Job Pages

More Infrastructure Engineer Jobs

Istari logo

Senior Cloud Infrastructure Engineer

Istari

Empowering our physical world with a digital one

Full TimeRemoteTeam 11-50H1B No Sponsor

• Design, implement, and maintain scalable, reliable infrastructure in AWS • Operate and improve Kubernetes-based environments, including production workloads • Build and maintain infrastructure as code using Terraform • Improve CI/CD pipelines, deployment workflows, and release automation in partnership with engineering teams • Build and maintain the packaging and reference architectures customers use to install our software in their own environments • Strengthen observability across the platform, including monitoring, logging, alerting, and actionable dashboards • Improve developer experience through tooling, environment automation, and self-service infrastructure • Operate within and preserve the established security and compliance posture of our environments • Monitor, troubleshoot, and resolve complex infrastructure issues with clear and timely communication • Participate in incident response and post-incident analysis • Develop and maintain documentation, runbooks, and technical standards • Identify opportunities to improve cost efficiency, performance, and resilience across environments

California
$135K - $220K / year
Rimutee logo

Arquitecto de Infraestructura y Ciberseguridad, Oracle

Rimutee

We believe LATAM digital & tech talent need to expand their reach.

Full TimeRemoteTeam 11-50H1B No Sponsor

• Asumirás el liderazgo estratégico para el diseño, implementación, tuning y aseguramiento del stack tecnológico de Oracle en plataformas críticas del sector financiero • Diseñar y desplegar arquitecturas de infraestructura híbridas y Cloud Native en OCI altamente resilientes, garantizando conectividad avanzada y alta disponibilidad • Optimizar y realizar tuning avanzado en plataformas de capa media y clústeres complejos (WebLogic, SOA Suite, Forms & Reports) para maximizar el rendimiento operativo • Blindar el ecosistema crítico de la organización mediante la implementación de arquitecturas de seguridad robustas, gestión de identidades (IAM) y controles de ciberseguridad especializados para la banca • Orquestar la infraestructura como código (IaC) y la conteneización utilizando Terraform y Kubernetes (OKE) para automatizar y escalar los entornos financieros • Asegurar el alineamiento y cumplimiento de las plataformas con los estándares y marcos internacionales de referencia (NIST, CIS, COBIT, ITIL)

Argentina

Role Description Maintains the OBIWAN operating-system, virtualization, server, network, storage, monitoring, and cybersecurity environment to ensure continuous, secure, and reliable service. The position administers Red Hat Enterprise Linux and supporting Windows/VMware infrastructure, monitors Oracle/Exadata-related platforms, performs controlled patching and lifecycle maintenance, resolves infrastructure incidents, maintains architecture and inventory records, and supports ATO sustainment, vulnerability remediation, audits, and FAA cybersecurity coordination. The candidate must have the ability to operate effectively under pressure adhering to the ProSol Core Values of: - Agility: rapid adaptation to the changing requirements and environment of our clients; - Excellence: Service quality that exceeds the expectations of our clients; - Integrity: Accountability and honesty−always doing the right thing; - Long-Term Commitment: Unquestioned loyalty and dedication to our clients, partners and employees. Qualifications - Advanced Red Hat Enterprise Linux administration, including services, permissions, filesystems, networking, logging, shell scripting, package management, patching, hardening, and troubleshooting. - Hands-on experience with VMware/VxRail or comparable virtualization, Windows server dependencies, networking, storage, backup, monitoring, and enterprise data-center operations. - Experience with Oracle/Exadata-related infrastructure, Oracle Enterprise Manager, secure shell access, certificates, identity services, and application/database dependencies. - Strong cybersecurity operations knowledge, including vulnerability scanning, secure configuration, patch management, ATO support, NIST SP 800-53 controls, POA&M management, evidence collection, and audit readiness. - Ability to diagnose complex incidents spanning hardware, operating systems, network, storage, databases, applications, security controls, and vendor products. - Ability to plan controlled maintenance, assess impact, document implementation and rollback steps, validate results, and communicate risk clearly. - Strong technical documentation and collaboration skills, including architecture diagrams, inventories, runbooks, incident records, security artifacts, and customer-ready recommendations. Requirements - Bachelor’s degree in computer science, information technology, cybersecurity, engineering, or a related technical field; directly relevant experience may substitute for a portion of formal education. - At least seven years of experience supporting Linux-based enterprise infrastructure, systems administration, cybersecurity operations, or mission-critical data-center environments. - At least five years of hands-on Red Hat Linux or comparable enterprise Linux administration experience. - Demonstrated experience with patching, monitoring, virtualization, infrastructure troubleshooting, secure configuration, vulnerability remediation, and disaster-recovery readiness. - Experience supporting federal information systems, sensitive financial data, or other environments requiring formal authorization, audit, and records-management controls. Preferred Qualifications - Red Hat Certified System Administrator (RHCSA), Red Hat Certified Engineer (RHCE), Security+, CISSP, VMware, Microsoft, Oracle, or comparable infrastructure/security certification. - Experience with Dell VxRail, Oracle Exadata X9, Oracle Enterprise Manager, PRTG, Splunk, Microsoft Defender, Nessus, WebInspect, or similar monitoring and security tools. - Experience supporting FAA security requirements, ATOM/SMART, ATO recertification, SSP/SAR/ISCP/PTA documentation, and FAA ISSO coordination. - Experience with Active Directory, service-account governance, MFA, certificate renewal, cipher hardening, log aggregation, and security-event analysis. - Experience coordinating vendor service requests, hardware replacement, enterprise data-center access, and remote/onsite incident response. Core Competencies - Red Hat Linux administration - Infrastructure monitoring and recovery - Virtualization and data-center support - Cybersecurity and ATO sustainment - Vulnerability and patch management - Architecture and configuration control - Incident response and troubleshooting - Technical documentation and audit readiness Supervisory Responsibilities This position has no routine direct reports. The employee may act as infrastructure or cybersecurity technical lead, coordinate vendors, direct technical response during incidents, and mentor or cross-train team members. Work Environment and Physical Requirements Work is primarily performed remotely or at a Contractor facility and requires extended computer use, frequent review of monitoring data and logs, and occasional work outside normal hours. Pre-approved travel to the FAA Enterprise Data Center may require entry into controlled technical spaces, walking, standing, bending, reaching, and handling or inspecting installed equipment in accordance with site safety rules. Performance Expectations - OBIWAN infrastructure remains available, stable, secure, monitored, patched, and recoverable. - Incidents and alerts are detected early, escalated appropriately, resolved safely, and documented through root cause and preventive action. - Security findings, POA&M items, patches, certificates, and audit evidence are tracked to timely and verifiable closure. - Architecture diagrams, inventories, configuration baselines, runbooks, and maintenance records remain accurate and current. - Maintenance and infrastructure changes are fully planned, tested, approved, reversible, and executed with minimal user impact. Position Description Disclaimer This description summarizes the position’s primary duties and may be revised for related business or contract needs. It does not create an employment contract. Reasonable accommodations may be provided in accordance with applicable law and company policy. Additional Information ProSol is an equal opportunity employer, all interested qualified applicants are encouraged to apply, EEO/D/M/V/F. ProSol welcomes and encourages diversity in the workforce. All your information will be kept confidential according to EEO guidelines.

United States
NCV HOLDCO LLC logo

Director of Engineering, Infrastructure

NCV HOLDCO LLC

At NetCov, we specialize in delivering cutting-edge IT and cybersecurity solutions designed to protect and optimize the digital infrastructure for the industries we serve. We differentiate ourselves from our competition through our deep and intimate knowledge of our customers’ business.

Role Description The Director of Infrastructure leads a specialized engineering delivery function overseeing infrastructure, cloud, and network teams and projects across complex client environments. This role is responsible for guiding technical delivery across infrastructure, cloud, and network initiatives, supporting regulated industry architecture, and managing execution through a team of Managers, Team Leads, and Engineers. The position partners closely with the PMO, GRC, and Technology organizations, while owning the engineering-side execution of regulated and compliance-driven initiatives. The Director of Infrastructure is accountable for delivery quality, architectural alignment, and execution predictability across infrastructure, cloud, and network engagements. While primarily a leadership role, this position requires sufficient technical depth to guide architecture decisions and, when necessary, step in to support delivery execution. Accountabilities - Infrastructure, Cloud & Network Leadership - Lead technical delivery efforts across infrastructure, cloud, and network teams and projects - Establish and maintain engineering standards aligned with secure architecture and regulatory requirements - Partner with internal stakeholders to align infrastructure, cloud, and network strategies with architectural, regulatory, and operational constraints - Identify, assess, and mitigate technical and delivery risks during infrastructure, cloud, network, and compliance-driven initiatives - Engineering Team Leadership & Development - Lead and develop a team of Managers, Team Leads, and Engineers responsible for driving execution and coordination of infrastructure, cloud, and network initiatives - Define delivery standards, expectations, and escalation paths for the Infrastructure team - Provide oversight for complex, high-risk, or multi-stream projects - Lead and support engineers delivering infrastructure, cloud, network, and compliance-driven solutions - Foster a culture of accountability, technical excellence, and continuous improvement - Provide mentorship, coaching, and performance management for both Engineers and Team Leads - Step in to support or temporarily cover delivery responsibilities when business needs require - Identify skill gaps and partner on training and capability development initiatives - Client Engagement & Escalation - Act as a senior technical escalation point for infrastructure, cloud, network, and compliance-related delivery challenges - Participate in client-facing discussions requiring architectural or regulatory-aligned technical leadership - Support confidence and trust in delivery outcomes through clear communication and execution discipline - Delivery Planning, Efficiency & Financial Accountability - Oversee delivery planning, resource allocation, and execution across infrastructure, cloud, and network initiatives - Monitor utilization, delivery health, and execution efficiency across teams - Contribute to project scoping, estimation, and delivery strategy for infrastructure, cloud, and network engagements - Participate in sprint planning, and ensure managers and team members do the same, in coordination with the PMO so that work is planned and executed effectively - Engineering Leadership Partnership - Work closely with engineering leadership to align infrastructure, cloud, and network priorities with broader organizational strategy - Provide regular reporting on delivery performance, risks, and improvement opportunities - Contribute to the evolution of secure architecture patterns and regulated service offerings - Performance Management & Results - Track KPIs related to delivery quality, predictability, and execution effectiveness - Drive data-informed improvements to delivery processes and outcomes - Ensure commitments are met and delivery standards are consistently upheld - Other duties as assigned Qualifications - 7+ years of experience in IT leadership, technical management, or engineering delivery roles, including experience leading managers or team leads - Experience leading infrastructure, cloud, or network teams and projects in complex client environments - Strong understanding of secure architecture principles, including identity, access control, segmentation, and logging - Strong technical foundation across infrastructure, cloud platforms (e.g., Azure, AWS), and enterprise networking - Working knowledge of regulated industry technical requirements with a focus on engineering execution - Experience leading technical teams and coordinating cross-functional delivery efforts - Ability to translate regulatory and compliance requirements into executable technical solutions - Strong communication, escalation management, and stakeholder engagement skills - Familiarity with delivery frameworks such as ITIL, Agile, or similar methodologies Requirements - Prior experience supporting regulated environments (e.g., CMMC, NIST-aligned frameworks) - Background in solutions architecture, engineering leadership, or technical delivery management - Relevant certifications in security, architecture, delivery, or leadership disciplines Benefits - This is a full-time position - This position may require travel occasionally for on-site meetings Company Description At NetCov, we specialize in delivering cutting-edge IT and cybersecurity solutions designed to protect and optimize the digital infrastructure for the industries we serve. We differentiate ourselves from our competition through our deep and intimate knowledge of our customers’ business.

United States
$105K - $165K / year