Security Infrastructure Systems Engineer
Surrey Satellite Technology Ltd. Guildford, England, United Kingdom
Aviation and Aerospace Component Manufacturing · 201-500 employees
About the role
The Security Infrastructure Engineer is responsible for the implementation, operation, and maintenance of core IT infrastructure with a focus on security, resilience, and compliance. They will also provide 3rd line support to the Service Desk and participate in incident response activities.
What they look for
Requirements
Candidates should have 3-5+ years of experience in security analysis or infrastructure roles and hands-on experience with cloud platforms and security technologies. A degree in computing or equivalent experience is required, with professional certifications like CISSP or Security+ considered an advantage.
Full description
Security Infrastructure Engineer – Job Ref:2147
Reports To
Infrastructure Manager
Responsible For
Responsible for the implementation, operation, maintenance and continuous improvement of SSTL’s core IT infrastructure and project delivery with a particular focus on security, resilience and compliance.
The Provision of 3rd line support to the Service Desk
Working closely with infrastructure, networking, application colleagues the Security Infrastructure Engineer will help ensure that security is embedded into the design and operation of infrastructure rather than treated as a separate activity.
Key Tasks
· Maintain infrastructure services to agreed availability, performance and security standards.
· Implement secure configurations and system-hardening standards.
· Review and remediate infrastructure vulnerabilities.
· Support access control processes, including access
· reviews, privileged access checks, and enforcement of least privilege principles.
· Support endpoint/server security controls.
· Ensure appropriate logging and security monitoring is enabled and reviewed.
· Support encryption and certificate-management requirements.
· Review infrastructure against security standards and vendor recommendations.
· Identify unsupported and end-of-life systems and associated risks.
· Support security improvements across existing infrastructure.
· Oversee and engage in system upgrades, patching, configuration changes and lifecycle-management activities.
· Monitor Security and compliance within the SSTL infrastructure capacity, performance, availability and health.
· Diagnose and resolve security incidents and problems.
· Support backup, recovery, business continuity and disaster-recovery arrangements.
· Participate in infrastructure projects, migrations and technology refresh programmes.
· Manage the security of the infrastructure through appropriate change, configuration and release-management processes.
· Participate in Cyber Security Incident Response Team (CSIRT) activities, including incident investigation, containment, recovery, and continuous improvement of incident readiness.
PERSON SPECIFICATION (essential requirements)
Qualifications
Educated to degree level or equivalent experience (preferably in computing)
CISSP, CCSP, or Security+ all an advantage but not necessary
Experience
· 3–5+ years of experience in security analysis, infrastructure, DevSecOps, or a related role.
· Hands-on experience securing cloud platforms such as AWS, Azure, or Google Cloud.
· Experience with identity and access management, SSO, MFA, RBAC, and privileged-access controls.
· Experience deploying and maintaining security technologies, including SIEM, EDR, vulnerability-management, secrets-management, and intrusion-detection tools.
· Experience with Linux administration, system hardening, patch management, and configuration management.
· Experience investigating security incidents, reviewing logs, identifying root causes, and implementing remediation.
Knowledge & Skills
Technical (Understanding, awareness or experience with the following)
· Strong knowledge of networking, including TCP/IP, DNS, firewalls, VPNs, proxies, and load balancers.
· Proficiency with infrastructure-as-code and automation tools such as Terraform, Ansible, Python, or Bash.
· Familiarity with containers and orchestration platforms such as Docker and Kubernetes.
· Understanding of security frameworks and standards such as NIST, CIS Benchmarks, ISO 27001, or SOC 2.
· Ability to conduct threat modelling, infrastructure risk assessments, and architecture reviews.
· Strong troubleshooting, documentation, and cross-functional communication skills.
Personal
· Team player with strong communication skills
· Competent troubleshooting skills
· Ability to articulate Project deliverables and designs
· Ability to work under own initiative and in a busy environment