We are looking for a hands-on Senior Infrastructure Engineer to take ownership of our on-premises data centre and hybrid cloud environment. The ideal candidate combines deep experience managing physical infrastructure (firewalls, switches, servers, access points) with strong cloud and IT systems administration skills across Microsoft 365 and Azure. You will be responsible for keeping our infrastructure secure, available and well-architected, and for owning IT hardware procurement end-to-end.
Key Responsibilities
On-Premises Data Centre Management
Own day-to-day operations of the on-premises data centre, including capacity planning, racking, cabling, power, cooling and physical security. Maintain documentation, asset inventory and rack diagrams; ensure change management processes are followed for all DC operations. Plan and execute hardware refreshes, firmware upgrades, patching cycles and decommissioning activities with minimal business impact. Define and enforce backup, monitoring and disaster recovery practices for on-prem workloads.
Network & Security Hardware
Hands-on configuration and management of on-prem firewalls, core and access switches, wireless access points and servers. Maintain VLANs, routing, VPNs, firewall rules, ACLs and secure remote access for staff and contractors. Troubleshoot network and connectivity issues across LAN, WAN, Wi-Fi and VPN; perform root-cause analysis and remediation. Monitor performance and security posture of network and server infrastructure; respond to alerts and incidents.
IT Hardware Procurement
Own end-to-end IT hardware procurement: requirements gathering, vendor evaluation, quotations, purchase orders, delivery, asset tagging and lifecycle tracking. Build and maintain relationships with OEMs, distributors and resellers; negotiate pricing, warranties and support contracts. Maintain hardware standards across servers, networking equipment, end-user devices and peripherals to ensure consistency and supportability. Track budgets, renewals (support, licenses, warranties) and forecast hardware needs in line with business growth.
On-Prem and Cloud Networking
Design and operate hybrid networking between on-premises infrastructure and Azure (VNets, subnets, peering, Express Route / VPN gateways, NSGs, route tables). Implement secure, segmented network architectures across on-prem and cloud, aligned to least-privilege and zero-trust principles. Manage DNS, DHCP, NTP and certificate services across hybrid environments.
IT Systems Administration (Microsoft 365 Stack)
Administer Microsoft 365 services including Exchange Online, Share Point Online, One Drive and Teams (Teams Admin Centre). Manage device lifecycle, compliance and policies through Intune (enrollment, configuration profiles, compliance policies, app deployment, autopilot). Maintain Share Point sites, permissions, external sharing controls, and information governance. Manage identities, groups, conditional access and licensing in Entra ID (Azure AD).
Azure Cloud
Operate and maintain workloads in Azure across compute, storage, networking and identity. Implement monitoring, alerting, cost management and security best practices using native Azure tooling. Support hybrid identity and connectivity between on-prem and Azure tenants.
Infrastructure As Code (Preferred)
Use Terraform to provision and manage Azure resources in a repeatable, version-controlled way. Contribute to module design, code reviews and CI/CD pipelines for infrastructure changes.
Required Skills & Experience
Proven hands-on experience managing on-premises data centre infrastructure (servers, storage, racks, power, cooling). Strong working experience configuring and maintaining enterprise firewalls, switches and wireless access points. Demonstrable experience owning IT hardware procurement, vendor management and asset lifecycle. Solid networking fundamentals across both on-prem and cloud (TCP/IP, routing, VLANs, VPN, DNS, Azure VNets). Proven administration experience with Microsoft 365: Intune, Share Point, Teams Admin Centre, Exchange Online and Entra ID. Working experience operating workloads in Microsoft Azure. Strong troubleshooting skills, ownership mindset and ability to work independently in a lean team.
Preferred
Hands-on experience with Terraform for Azure infrastructure. Relevant certifications (e.g. Microsoft AZ-104, MS-102, MD-102; Cisco CCNA; vendor firewall certifications). Experience with monitoring, backup and DR tooling for hybrid environments. Scripting experience (Power Shell, Bash) for automation of routine administrative tasks.
نحن نبحث عن مهندس بنية تحتية أول عملي لتولي مسؤولية مركز البيانات الخاص بنا وبيئة السحابة الهجينة. يجمع المرشح المثالي بين الخبرة العميقة في إدارة البنية التحتية المادية (جدران الحماية، المحولات، الخوادم، نقاط الوصول) ومهارات قوية في السحابة وإدارة أنظمة تكنولوجيا المعلومات عبر Microsoft 365 و Azure. ستكون مسؤولاً عن الحفاظ على بنيتنا التحتية آمنة ومتاحة ومصممة جيداً، وعن تولي عمليات شراء أجهزة تكنولوجيا المعلومات من البداية إلى النهاية.
المسؤوليات الرئيسية
إدارة مركز البيانات المحلي
تولي العمليات اليومية لمركز البيانات المحلي، بما في ذلك تخطيط السعة، والتركيب على الرفوف، والكابلات، والطاقة، والتبريد، والأمن المادي. الاحتفاظ بالوثائق وجرد الأصول ومخططات الرفوف؛ وضمان اتباع عمليات إدارة التغيير لجميع عمليات مركز البيانات. تخطيط وتنفيذ تحديثات الأجهزة، وتحديثات البرامج الثابتة، ودورات التصحيح، وأنشطة الإيقاف عن العمل بأقل تأثير على الأعمال. تحديد وتنفيذ ممارسات النسخ الاحتياطي والمراقبة والتعافي من الكوارث لأحمال العمل المحلية.
أجهزة الشبكة والأمن
التكوين والإدارة العملية لجدران الحماية المحلية، والمحولات الأساسية والوصول، ونقاط الوصول اللاسلكية والخوادم. الحفاظ على شبكات VLAN، والتوجيه، وVPNs، وقواعد جدار الحماية، وقوائم التحكم في الوصول (ACLs)، والوصول الآمن عن بعد للموظفين والمقاولين. استكشاف أخطاء الشبكة والاتصال عبر الشبكات المحلية (LAN) والواسعة (WAN) وشبكات Wi-Fi و VPN وإصلاحها؛ وإجراء تحليل السبب الجذري والمعالجة. مراقبة أداء وأمن البنية التحتية للشبكة والخادم؛ والاستجابة للتنبيهات والحوادث.
شراء أجهزة تكنولوجيا المعلومات
تولي مسؤولية شراء أجهزة تكنولوجيا المعلومات من البداية إلى النهاية: جمع المتطلبات، وتقييم الموردين، وعروض الأسعار، وأوامر الشراء، والتسليم، ووضع علامات الأصول وتتبع دورة الحياة. بناء والحفاظ على علاقات مع الشركات المصنعة للمعدات الأصلية (OEMs) والموزعين والبائعين؛ والتفاوض على الأسعار والضمانات وعقود الدعم. الحفاظ على معايير الأجهزة عبر الخوادم، ومعدات الشبكات، وأجهزة المستخدم النهائي، والأجهزة الطرفية لضمان الاتساق والقدرة على الدعم. تتبع الميزانيات، والتجديدات (الدعم، التراخيص، الضمانات) وتوقع احتياجات الأجهزة بما يتماشى مع نمو الأعمال.
شبكات السحابة والمحلية
تصميم وتشغيل الشبكات الهجينة بين البنية التحتية المحلية و Azure (شبكات VNet، والشبكات الفرعية، والتناظر، وبوابات Express Route / VPN، ومجموعات أمان الشبكة NSGs، وجداول التوجيه). تنفيذ بنيات شبكة آمنة ومجزأة عبر السحابة والمحلي، تتماشى مع مبادئ الامتياز الأقل والثقة الصفرية. إدارة خدمات DNS و DHCP و NTP وخدمات الشهادات عبر البيئات الهجينة.
إدارة أنظمة تكنولوجيا المعلومات (مجموعة Microsoft 365)
إدارة خدمات Microsoft 365 بما في ذلك Exchange Online و SharePoint Online و OneDrive و Teams (مركز إدارة Teams). إدارة دورة حياة الجهاز والامتثال والسياسات من خلال Intune (التسجيل، وملفات تعريف التكوين، وسياسات الامتثال، ونشر التطبيقات، وAutopilot). صيانة مواقع SharePoint والأذونات وعناصر تحكم المشاركة الخارجية وحوكمة المعلومات. إدارة الهويات والمجموعات والوصول المشروط والترخيص في Entra ID (Azure AD).
سحابة Azure
تشغيل وصيانة أحمال العمل في Azure عبر الحوسبة والتخزين والشبكات والهوية. تنفيذ المراقبة والتنبيه وإدارة التكلفة وأفضل ممارسات الأمان باستخدام أدوات Azure الأصلية. دعم الهوية الهجينة والاتصال بين المستأجرين المحليين ومستأجري Azure.
البنية التحتية ككود (مفضل)
استخدام Terraform لتوفير وإدارة موارد Azure بطريقة قابلة للتكرار ومتحكم فيها بالنسخ. المساهمة في تصميم الوحدات، ومراجعات الكود، وخطوط أنابيب CI/CD لتغييرات البنية التحتية.
المهارات والخبرة المطلوبة
خبرة عملية مثبتة في إدارة البنية التحتية لمركز البيانات المحلي (الخوادم، التخزين، الرفوف، الطاقة، التبريد). خبرة عمل قوية في تكوين وصيانة جدران حماية المؤسسات، والمحولات، ونقاط الوصول اللاسلكية. خبرة يمكن إثباتها في تولي شراء أجهزة تكنولوجيا المعلومات، وإدارة الموردين، ودورة حياة الأصول. أساسيات شبكات قوية عبر السحابة والمحلي (TCP/IP، التوجيه، VLANs، VPN، DNS، Azure VNets). خبرة إدارية مثبتة مع Microsoft 365: Intune، SharePoint، مركز إدارة Teams، Exchange Online، وEntra ID. خبرة عمل في تشغيل أحمال العمل في Microsoft Azure. مهارات استكشاف الأخطاء وإصلاحها القوية، وعقلية الملكية، والقدرة على العمل بشكل مستقل في فريق صغير.