Secuirty & Infrastructure Engineer (contract)
- Hiring from
- United Kingdom
- Work type
- Remote
- Posted
Show job descriptionHide job description
About This Job
We're looking for an experienced Security & Infrastructure Engineer to support the delivery of a secure, cutting-edge Proof of Concept (PoC) that contributes to the Royal Navy's digital transformation ambitions. Working alongside a multidisciplinary team of engineers, architects and security specialists, you'll play a key role in designing, building and validating infrastructure platforms that demonstrate how modern secure technologies can be applied within Defence environments.
This is a hands-on engineering role where you'll help shape and implement secure infrastructure solutions aligned with Zero Trust Architecture principles, Federated Mission Networking (FMN) interoperability requirements and Secure by Design practices. You'll work closely with technology vendors and internal stakeholders to evaluate emerging capabilities, integrate complex technologies and establish reusable patterns that can support future operational deployments.
The role offers the opportunity to work at the forefront of secure infrastructure engineering, solving complex technical challenges across identity, networking, security, automation and platform services. It's ideally suited to someone who enjoys combining deep technical expertise with collaborative problem solving, while contributing to highly secure and mission-critical environments.
Responsibilities
- Design, build, integrate and validate infrastructure components within a secure Proof of Concept environment.
- Implement and test Zero Trust security controls across identity, devices, networks, applications, workloads, data and automation platforms.
- Support the implementation and validation of Federated Mission Networking (FMN) services and interoperability requirements.
- Assess infrastructure and security services against Zero Trust frameworks and FMN standards, providing compliance evidence and technical recommendations.
- Collaborate with engineers, architects and security specialists to embed Secure by Design and Security by Default principles throughout the delivery lifecycle.
- Produce and maintain high-quality technical documentation, including designs, configuration baselines, build guides, operational procedures and test evidence.
- Support technical assurance activities, vulnerability assessments, risk management and security compliance reviews.
- Work with vendors to evaluate, deploy and validate technologies against functional, interoperability and security requirements.
- Develop automation and scripting solutions to improve deployment consistency, repeatability and operational efficiency.
- Support demonstrations, technical experiments, onboarding activities and knowledge transfer across the wider team.
Required Skills & Experience
Defence & Secure Infrastructure
- Experience designing, building or supporting infrastructure solutions within Defence, government or other highly regulated environments.
- Experience delivering infrastructure services in secure or assured environments.
- Strong understanding of Secure by Design, Security by Default and defence-in-depth principles.
- Ability to produce technical documentation and evidence to support design assurance, security accreditation and compliance activities.
Zero Trust Architecture
- Practical experience implementing Zero Trust Architecture principles within enterprise or secure environments.
- Understanding of Zero Trust domains, including identity, devices, networks, applications, workloads, data, analytics and automation.
- Experience with identity federation, trust relationships and certificate management.
Platforms, Identity & Core Infrastructure
- Strong experience with Windows Server 2022/2025, Active Directory, Group Policy and Windows 11 administration.
- Experience deploying and supporting Hyper-V and virtualised infrastructure environments.
- Knowledge of Public Key Infrastructure (PKI), DNS and DNSSEC.
- Experience managing patching and updates across Windows and Linux platforms.
- Familiarity with privileged access controls, Just-in-Time (JIT) administration, Just Enough Administration (JEA), Multi-Factor Authentication (MFA) and policy-driven access management.
Security Engineering & Monitoring
- Experience implementing and assessing security baselines using CIS Benchmarks, DISA STIGs and Microsoft security hardening guidance.
- Knowledge of Endpoint Detection and Response (EDR/XDR) technologies.
- Experience integrating SIEM platforms, centralised logging, telemetry and security monitoring solutions.
- Understanding of vulnerability management, remediation processes and configuration compliance.
Desirable Experience
- Experience working with FMN standards, NATO interoperability requirements or Defence networking architectures.
- Knowledge of Zero Trust reference architectures used within Defence or Government organisations.
- Experience with software-defined infrastructure, micro-segmentation and policy-based security controls.
- Familiarity with security orchestration and automated response technologies.
- Experience with Ubuntu Linux, Ansible and Python.
- Exposure to hybrid cloud platforms, VMware, Docker and Kubernetes.
- Knowledge of enterprise technologies from vendors such as Microsoft, Arista Networks, Palo Alto Networks or similar.
Clearance Requirements
Due to the nature of this work, applicants must be eligible to obtain and maintain UK security clearance and be comfortable working within secure and Defence-focused environments.