Purpose of the role
Own client-facing infrastructure and the security posture of everything we run. Self-hosted client deployments, cloud infrastructure, migrations, backups, access control and incident response sit with this seat.
Client production systems depend on this role directly. Downtime on a client instance is a commercial event, not a technical one.
Key responsibilities
Infrastructure operations
- Provision, configure and maintain client server environments across cloud providers and self-hosted deployments.
- Run OS-level administration on Linux servers: patching, upgrades, performance tuning, resource monitoring, capacity planning.
- Maintain uptime against contracted service levels. Monitor proactively; do not learn about an outage from the client.
- Manage DNS, SSL certificates, mail deliverability records and domain configuration across all company and client domains.
Migrations
- Plan and execute server and platform migrations end to end: assessment, runbook, dry run, cutover, validation, rollback plan.
- Produce a written migration plan before any cutover, including a defined rollback trigger and a named fallback state.
- Execute cutovers inside agreed maintenance windows with confirmed client sign-off.
Backup and recovery
- Maintain backup schedules across every production system with defined retention.
- Test restores on a fixed schedule. An untested backup is not a backup.
- Maintain documented recovery procedures with actual recovery time objectives per system.
Security
- Own access control across all systems: provisioning, revocation on exit, periodic review, least-privilege enforcement.
- Manage credential handling and rotation. Credentials never travel through chat groups, plain text or shared documents.
- Harden servers: firewall rules, SSH configuration, intrusion detection, vulnerability patching on a defined cadence.
- Run periodic security reviews of client-facing infrastructure and produce written findings with remediation priority.
- Respond to security incidents: contain, investigate, remediate, document. Produce a written incident record every time.
- Maintain compliance posture relevant to client data handling in both UAE and India jurisdictions.
Integrations and internal technical support
- Build and maintain API integrations between client systems and third-party platforms.
- Support technical elements of the sales process: environment provisioning for demos, technical feasibility assessment, integration scoping input.
- Handle scripted data operations, extraction tasks and automation the delivery and sales teams require.
Documentation and handover
- Document every workplace: architecture, access paths, dependencies, credentials location, recovery procedure.
- No single point of failure on knowledge. Every system you run must be operable by someone else from your documentation.
- Maintain a current inventory of all client infrastructure with hosting provider, renewal date, cost and owner.
Commercial boundaries
- Infrastructure work outside a signed scope is quoted as a variation before it starts. Flag it; do not absorb it.
- Never commit timelines, scope or support terms to a client directly. Technical input goes to the account owner, who commits commercially.
- Managed infrastructure is a priced service. Nothing is provided complimentary without written approval.
Requirements
- 3 to 5 years in DevOps, systems administration, cloud infrastructure or IT security.
- Strong Linux server administration. Command-line proficiency is assumed, not a bonus.
- Hands-on experience with at least two of: AWS, Google Cloud, Oracle Cloud, Azure, Hetzner or comparable providers.
- Demonstrated migration experience. You have moved a live production system and can describe the plan, the failure modes and the rollback.
- Networking fundamentals: DNS, TLS, firewalls, VPN, reverse proxies, load balancing.
- Scripting capability in Bash and Python for automation, monitoring and data operations.
- Backup and disaster recovery experience with tested restores, not just configured schedules.
- Security fundamentals: hardening, access control, vulnerability management, incident response.
- Ability to write documentation another engineer can follow without asking you a question.
Preferred
- Experience running self-hosted enterprise software for external clients under service-level commitments.
- Containerisation and orchestration experience: Docker, Kubernetes.
- Infrastructure as code: Terraform, Ansible.
- Monitoring and alerting stacks: Prometheus, Grafana, Zabbix or equivalent.
- API integration development experience.
- Security certification: CompTIA Security+, CEH, AWS Security Specialty or equivalent.
- Exposure to data protection requirements in UAE or India.
📌 Walk-in || DevOps & IT Security Engineer (Noida)
🏢 VORTEX
📍 Noida