Sr. Infrastructure & Security Engineer
dinCloud Pakistan, An ATSG Company
Date: 2 weeks ago
City: Remote
Contract type: Full time
Remote
We are seeking a highly skilled Senior Infrastructure & Security Engineer to join our infrastructure team. This role is critical to ensuring the reliability, scalability, and security of our hybrid cloud environment. You will act as a bridge between development and operations, with a strong focus on automation, security, and system resilience. Your expertise will guide the team in maintaining high-availability systems while continuously improving our infrastructure-as-code practices.
Key Responsibilities
1. Infrastructure & OS Management
Category
Must-Have
OS
Expert in Rocky Linux, CentOS, RHEL (6+ years); Windows Server experience
Security
WAF, vulnerability scanning, LDAP, OS hardening, kernel patching
Automation
Ansible (playbooks, roles, AWX/Tower), Python/Shell scripting
CI/CD & SCM
GitHub Enterprise administration, GitHub Actions, branch protection rules
Containers
Docker (build/security scanning), Kubernetes (deployment, networking, storage)
Web Servers
Apache, Nginx (configuration, SSL, reverse proxy)
Monitoring
Prometheus, Grafana, ELK, or commercial tools (Datadog/New Relic)
Code Security
SAST/DAST tools (SonarQube, Snyk, Checkmarx)
Preferred Qualifications
Key Responsibilities
1. Infrastructure & OS Management
- Manage and maintain Linux-based systems (Rocky Linux, CentOS, RHEL) in production and staging environments.
- Perform kernel patching, security updates, and system hardening following industry best practices.
- Troubleshoot and debug complex OS-level issues (performance, memory, I/O, kernel panics).
- Manage and support Windows Server environments where applicable.
- Perform regular security scanning and vulnerability assessments using tools like Nessus, Qualys, or OpenVAS.
- Conduct code security scans (SAST/DAST) and integrate them into CI/CD pipelines.
- Configure and maintain LDAP authentication for centralized access management.
- Ensure all systems comply with internal security policies and external regulatory standards.
- Implement and manage WAF (Web Application Firewall) configurations to protect against OWASP Top 10 threats.
- Write and maintain Ansible playbooks for automated provisioning, patching, and configuration management.
- Manage GitHub Enterprise repositories, branching strategies, and CI/CD workflows (GitHub Actions preferred).
- Develop automation scripts using Python, Shell, or Go to reduce toil and improve operational efficiency.
- Configure and maintain Apache and Nginx web servers, including performance tuning and reverse proxy setup.
- Troubleshoot web server logs, SSL/TLS issues, and load balancing configurations.
- Deploy, manage, and scale applications on Kubernetes clusters (EKS, AKS, or on-prem).
- Build and maintain Docker images with secure base layers and minimal attack surfaces.
- Monitor cluster health, resource usage, and implement auto-scaling policies.
- Deploy and maintain monitoring tools (Prometheus, Grafana, Datadog, or ELK stack).
- Define SLIs, SLOs, and error budgets; drive blameless post-mortems.
- Participate in on-call rotations and lead incident response efforts.
Category
Must-Have
OS
Expert in Rocky Linux, CentOS, RHEL (6+ years); Windows Server experience
Security
WAF, vulnerability scanning, LDAP, OS hardening, kernel patching
Automation
Ansible (playbooks, roles, AWX/Tower), Python/Shell scripting
CI/CD & SCM
GitHub Enterprise administration, GitHub Actions, branch protection rules
Containers
Docker (build/security scanning), Kubernetes (deployment, networking, storage)
Web Servers
Apache, Nginx (configuration, SSL, reverse proxy)
Monitoring
Prometheus, Grafana, ELK, or commercial tools (Datadog/New Relic)
Code Security
SAST/DAST tools (SonarQube, Snyk, Checkmarx)
Preferred Qualifications
- 8+ years in SRE, DevOps, or Systems Engineering roles.
- Experience with Terraform or other IaC tools.
- Familiarity with service mesh (Istio/Linkerd) and CNI plugins (Calico/Cilium) or similar.
- Understanding of zero-trust networking and SSO integrations.
- Certifications: RHCE, CKA, or CISSP are a plus.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Senior Network Engineer - Cisco, Aruba, Fortinet - TJ / 1866698
Recruit AI,
Remote
PKR 250,000
per month
10 hours ago
Our client Hecta Solutions is looking for a Senior Network Engineer - Cisco, Aruba, Fortinet in IslamabadHecta Solutions is seeking a Senior Network Engineer to design, implement, and maintain high-performance network infrastructures across multi-vendor enterprise environments.This hands-on, individual contributor role focuses on managing routing, switching, wireless networks, and complex firewall architectures using Cisco, Cisco Meraki, Aruba, and Fortinet technologies. The...
Jr. Product Designer (SaaS)
RepairDesk,
Remote
11 hours ago
RepairDesk is a modern repair shop management software with 40+ powerful integrations and modules. The software is customisable to meet the workflows of single-store, multi-store, and franchise repair businesses in various industry verticals. Available in 30+ languages, RepairDesk is trusted by over 3,000 businesses globally, helping them save time, manage inventory, and run profitable repair stores.TasksJoin our team and play...
Business Analyst
Troxis,
Remote
PKR 250,000
-
PKR 300,000
per month
1 day ago
We are seeking a detail-oriented and analytical Business Analyst to join our team. The ideal candidate will be responsible for bridging the gap between business needs and technology by analyzing processes, gathering requirements, and providing data-driven insights. You will work closely with stakeholders to drive strategic initiatives, improve operations, and support the development of business solutions.Key Responsibilities:Gather, document, and analyze...