Infrastructure Engineer
We are seeking a highly skilled Infrastructure Engineer to architect, build, and maintain a robust, secure, and scalable IT infrastructure. This position sits at the intersection of systems administration, cloud engineering, network engineering, and security. The ideal candidate will ensure seamless operations of both on-premises and cloud environments, automate as much as possible, and proactively design solutions to prevent downtime and security risks.
This is a role for someone who is comfortable across multiple domains — Windows environments, networking, cloud, scripting, and security.
Technology: Azure, CI/CD, VPN, ISO, GDPR, Microsoft Dynamics BC
Experience: 2+
Language: English, Intermediate +
Location: Bucharest (Romania) or Kyiv (Ukraine)
Areas of responsibility
Windows & Domain Infrastructure
- Deploy, maintain, and upgrade Windows Server environments, including domain controllers.
- Manage Active Directory, OU structures, user/group policies, GPOs.
Network Infrastructure & Security
- Configure and manage routers, switches, firewalls (MikroTik, Unifi, etc.).
- Design and maintain wired and wireless networks, VLANs, routing, NAT, firewall rules.
- Setup VPN (site-to-site, client VPN), SSL/TLS certificates, encryption protocols.
- Apply network segmentation, zero-trust concepts, firewall policies, traffic inspection.
Cloud Infrastructure & Automation
- Architect and maintain infrastructure in Azure and AWS.
- Use Infrastructure as Code (Terraform, ARM, etc.) to define and deploy resources.
- Design and maintain CI/CD pipelines (Azure DevOps, GitHub Actions, etc.)
- Automate infrastructure provisioning, configuration, updates, scaling.
- Monitor costs, optimize resource usage, plan for capacity growth.
Monitoring, Logging & Incident Management
- Design and run observability solutions (metrics, logs, alerts, dashboards).
- Work with tools like Elastic Stack, cloud-native monitoring (Azure Monitor, AWS CloudWatch).
- Set up alerting, incident detection, root cause analysis, and post-mortems.
- Maintain log retention, searchability, anomaly detection.
Security & Compliance
- Configure and manage endpoint protection, intrusion detection/prevention, EDR solutions.
- Run vulnerability scans, assess threats, create resolution plans.
- Collaborate in security audits, compliance reviews, risk assessments.
- Lead vendor selection / tenders for security infrastructure.
Database / Data
- Support MS SQL (backups, replication, performance tuning).
- Assist with migrations for ERP / Microsoft Dynamics BC projects.
- Write scripts / data transformation tools for migration / integration tasks.
Scripting & Automation
- Write robust scripts and tooling (primarily PowerShell, optionally Python or Bash).
- Automate common operational tasks (patching, provisioning, reporting).
- Integrate scripts with pipelines, alerts, logging.
Cross-team Collaboration & Documentation
- Document designs, runbooks, topology diagrams, security policies in Confluence.
- Liaise with development, product, security, and business teams.
- Communicate with external vendors, support teams (e.g. Microsoft, network hardware vendors) in English.
Personality & Experience
Proven experience managing Windows Server, Active Directory, GPO in enterprise environments.
Solid networking knowledge: routing, switching, VPN, TCP/IP, wireless, firewalls.
Hands-on experience with Azure and/or AWS cloud platforms.
Strong scripting abilities — PowerShell is essential; Python / Bash is a plus.
Experience with Microsoft 365 / Office 365 administration, MDM, license management.
SQL / MS SQL experience (administration, tuning, migration).
Monitoring, logging, alerting, observability experience.
Security mindset: endpoint protection, vulnerability management, secure configurations.
Ability to troubleshoot complex systems, perform root-cause analysis.
Excellent documentation skills; ability to write runbooks and procedures.
Good English communication (verbal and written) to interact with vendors, external support.
Will be a plus:
- Experience with Elastic Stack (Elasticsearch, Kibana, Logstash).
- Containerization / orchestration (Docker).
- Infrastructure as Code experience (Terraform, CloudFormation).
- Experience with CI/CD pipelines and automating infrastructure changes.
- Experience in ERP / Business Central / Dynamics BC migrations.
- Certifications (e.g. Microsoft Azure / M365, AWS, Cisco).
- Experience in security audits, compliance frameworks (ISO, GDPR, etc.).