Senior Infrastructure Engineer
il y a 2 jours
London
The Role • Design and deliver a Windows 11 virtual desktop solution for engineering users, • Support hybrid VDI platforms across on‑premises and Azure environments, • Implement a secure access model enabling development and testing, including controlled elevated privilege use, • Ensure logical isolation of development and test workloads from production environments, • Integrate virtual desktops with enterprise identity services (Active Directory / Entra ID), • Implement role‑based access control (RBAC) for standard and privileged engineering access, • Design secure privilege‑elevation mechanisms aligned with least‑privilege principles, • Enable approved self‑service provisioning of engineering virtual desktops, • Automate virtual desktop lifecycle management (provision, update, retire), • Manage and administer Windows Server and Wintel infrastructure including build, configuration, patching, and lifecycle management, • Maintain and support Active Directory (AD) services (users, groups, GPOs, DNS, DHCP) and implement AD tiering models, • Execute infrastructure changes including server configurations, AD updates, and deployment activities, • Perform security remediation including service account cleanup, access control fixes, and compliance alignment, • Provide L2/L3 support for incidents, perform root cause analysis, and ensure SLA-driven resolution, • Support Change Management (CAB) processes and ensure controlled and validated deployments, • Monitor system performance, ensure high availability, capacity management, and resilience of infrastructure, • Automate operational tasks using PowerShell/scripts to improve efficiency and reduce manual effort, • Support testing, validation, and service transition (Project to BAU) activities Essential skills/knowledge/experience: (Up to 10, Avoid repetition) • Strong hands-on experience with Windows Server environments, including installation, configuration, patching, and troubleshooting, • Solid expertise in Active Directory (AD) including users, groups, GPOs, DNS, DHCP and AD governance models, • Experience in AD tiering, access control, and identity governance, including remediation of service accounts and security alignment, • Proven experience in enterprise infrastructure deployment and configuration, including server builds and environment changes, • Strong knowledge of virtualization technologies (e.g., VMware / Hyper-V) and clustered environments, • Experience in infrastructure security and compliance, including server hardening, patching, and vulnerability management, • Hands-on expertise in monitoring, troubleshooting, and performance optimization of infrastructure platforms, • Good understanding of backup, disaster recovery, and high availability solutions for enterprise environments, • Strong scripting and automation skills using PowerShell to improve operational efficiency, • Experience working with cloud-integrated or hybrid environments (e.g., Azure / Azure AD / Entra ID), • Good understanding of ITIL processes (Incident, Problem, Change Management) and working in SLA-driven environments, • Windows Server & Active Directory Expertise – Strong hands-on experience with Windows environments and AD services (GPO, DNS, DHCP, identity governance), • Enterprise Infrastructure & Virtualization – Proven capability in server deployment, configuration, and virtualization platforms (VMware / Hyper-V), • Security & Compliance Management – Experience in AD tiering, access control, server hardening, and remediation of security vulnerabilities, • Automation & Troubleshooting – PowerShell scripting with strong skills in monitoring, performance tuning, and resolving complex infrastructure issues, • Experience working in large-scale enterprise or regulated environments with strong compliance and governance requirements, • Exposure to hybrid cloud technologies such as Microsoft Azure, Azure Local (Azure Stack HCI), and Azure Arc, • Knowledge of advanced identity and security controls, including Entra ID integrations, conditional access, and zero-trust principles, • Experience with infrastructure automation frameworks (e.g., ARM templates, Bicep, or similar tools), • Familiarity with enterprise monitoring and logging platforms (e.g., Azure Monitor, Log Analytics, SIEM tools), • Exposure to service transition, documentation, and BAU handover processes in managed services environments Virtual Desktop Infrastructure (VDI) Expertise • Strong experience designing and implementing Windows 11 and 10 Virtual Desktop solutions, • Hands-on expertise with: Azure Virtual Desktop (AVD) & On-prem VDI platforms (e.g., Citrix Virtual Apps & Desktops, Windows RDS etc), • Knowledge of multi-session and single-session desktop environments, • Experience in high-performance engineering workstation environments, • Strong knowledge of: Active Directory (AD DS) and Microsoft Entra ID, • Experience integrating VDI with: Enterprise identity services &Authentication and access control systems, • Expertise in implementing: Role-Based Access Control (RBAC) &Least privilege access models, • Experience designing: Secure privilege elevation mechanisms& Controlled administrative access for developers/engineers, • Environment Segmentation & Isolation, • Automation & Scripting (PowerShell), • Networking & Performance Optimization including with understanding of Load balancing and network performance optimization, • Ability to define and segment user personas based on: Job roles (developers, testers, admins, contractors, etc.), • Experience conducting: User profiling and workload analysis