Designation: Senior IT Infrastructure Engineer- Infrastructure, Cloud & Endpoint Operations
Location: Gurgaon or Hyderabad
ROLE OVERVIEW The Senior IT Infrastructure Engineer is a hands-on technical role responsible for designing, building, configuring, and maintaining Xebia's server, virtualisation, cloud, and end-user computing infrastructure. The role owns the health, security, performance, and cost-efficiency of the infrastructure estate — from on-premises and virtual servers through to Microsoft 365 and multi-cloud environments — and ensures everything is configured, governed, and documented to enterprise standards.
The role combines deep technical expertise in server and policy configuration, virtualisation, and cloud administration with solid governance discipline across Microsoft 365, software asset management, cloud spend, and supplier relationships. The ideal candidate is equally comfortable creating and hardening virtual machines, authoring group and security policies, optimising cloud cost, and managing vendors — while automating repetitive work wherever possible.
KEY RESPONSIBILITIES
1. Server Administration & Policy Configuration
- Build, configure, harden, patch, and maintain Windows and Linux servers across physical, virtual, and cloud environments to enterprise security baselines.
- Design and manage Active Directory, Group Policy Objects (GPOs), security policies, and configuration baselines; enforce least-privilege and standardised builds.
- Configure server roles and services — DNS, DHCP, file/print, IIS, certificate services, and clustering / high availability.
- Maintain gold images, build standards, and configuration management to ensure consistency across the estate.
2. Virtualisation & VM Lifecycle Management
- Expertly create, configure, size, and manage virtual machines across VMware vSphere / ESXi, Microsoft Hyper-V, and cloud platforms (Azure, AWS, GCP).
- Define and apply VM policies — resource allocation, affinity/anti-affinity rules, snapshots, templates, tagging, naming conventions, and lifecycle governance.
- Manage virtualisation hosts, clusters, storage (SAN/NAS), and capacity planning; optimise performance and utilisation.
3. Microsoft 365 Governance & Rule Management
- Administer and govern the Microsoft 365 tenant — Exchange Online, SharePoint, OneDrive, Teams, and Intune — to enterprise standards.
- Configure and manage mail flow / transport rules, retention and DLP policies, compliance and sensitivity labels, and eDiscovery.
- Govern identity and access via Microsoft Entra ID — conditional access, MFA, licensing assignment, and endpoint/device management through Intune.
- Define and enforce M365 governance for provisioning, external sharing, guest access, and lifecycle management of Teams / groups / sites.
4. Cloud Engineering & Infrastructure Management
- Act as a cloud engineer for the estate — architect, deploy, and manage cloud infrastructure across Azure (primary), AWS, and/or GCP — compute, storage, networking, and identity.
- Design and manage cloud networking — virtual networks, subnets, load balancers, VPN / ExpressRoute, DNS, and firewall / NSG rules.
- Define landing zones, resource governance, tagging, RBAC, and Azure Policy / guardrails for secure and consistent provisioning.
- Build and manage CI/CD and infrastructure-as-code (Terraform, ARM/Bicep) pipelines to automate provisioning and enforce consistency.
- Engineer scalability, resilience, and high availability — auto-scaling, redundancy, and multi-region / availability-zone design.
5. Cloud Cost, FinOps & Spend Management
- Own cloud spend management — monitor consumption, forecast, and report on cloud cost against budget across all subscriptions/accounts.
- Drive FinOps practices — rightsizing, reserved instances / savings plans, auto-scaling, and elimination of idle or orphaned resources.
- Produce cost dashboards and chargeback / showback reporting; identify and deliver measurable cost-optimisation opportunities.
6. Software Asset Management (SAM) & Licensing
- Own the Software Asset Management lifecycle — discovery, inventory, entitlement reconciliation, and effective-licence-position (ELP) reporting.
- Manage licensing across Microsoft, VMware, and other key vendors; ensure compliance and audit-readiness and avoid over- or under-licensing.
- Maintain the CMDB / asset register for hardware and software; manage renewals, true-ups, and lifecycle retirement.
7. Identity & Access Management (IAM) Architecture
- Act as the IAM architect for the estate — design and maintain the identity architecture across Microsoft Entra ID (Azure AD), Active Directory, and federated / SaaS identity providers.
- Architect authentication and authorisation patterns — SSO, MFA, conditional access, SCIM provisioning, and least-privilege / RBAC and ABAC models.
- Design and manage privileged access management (PAM), Privileged Identity Management (PIM), and just-in-time / zero-standing-privilege access.
- Automate the full identity lifecycle — joiner-mover-leaver, access reviews, entitlement management, and periodic recertification.
- Manage endpoint provisioning, imaging, patching, and compliance through Intune / Autopilot / SCCM (MECM); enforce endpoint security baselines, encryption, and configuration policies.
8. Backup, Disaster Recovery & Business Continuity
- Design, implement, and test backup and disaster-recovery solutions with defined RPO/RTO targets.
- Manage backup tooling (e.g. Veeam, Azure Backup), replication, and periodic recovery testing.
- Maintain and regularly rehearse business-continuity and DR runbooks.
9. Monitoring, Automation & Infrastructure-as-Code
- Implement proactive monitoring, alerting, and observability across servers, cloud, and endpoints (e.g. Azure Monitor, Nagios, Zabbix, PRTG).
- Automate routine operations using PowerShell, Python, Bash, and CI/CD pipelines to reduce manual effort and configuration drift.
- Maintain accurate documentation, runbooks, and knowledge-base articles.
10. Vendor, Supplier & Service Management
- Manage infrastructure suppliers and cloud partners — performance against SLAs, contract and renewal management, and escalations.
- Evaluate new tools and services; build business cases and coordinate procurement with IT leadership.
- Operate within ITIL-aligned change, incident, and problem management processes.
EDUCATION & CERTIFICATIONS
Education
- Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent experience).
Required / Preferred Certifications
- Microsoft: AZ-104 (Azure Administrator), MS-102 (M365 Administrator), AZ-305 (Azure Solutions Architect) or MCSE.
- Virtualisation: VMware VCP-DCV; Microsoft Hyper-V experience.
- Cloud (additional): AWS SysOps Administrator / Solutions Architect, or equivalent GCP certification.
- Service & asset management: ITIL Foundation; FinOps Certified Practitioner; IAITAM CSAM / CHAMP (SAM).
- Identity & Access Management: SC-300 (Microsoft Identity and Access Administrator); Entra ID / Active Directory administration.
- Security-adjacent (advantageous): AZ-500 (Azure Security), CompTIA Server+ / Security+.
EXPERIENCE REQUIREMENTS
- Minimum 8–10 years of hands-on IT infrastructure experience across servers, virtualisation, and cloud in an enterprise environment.
- Proven expertise configuring server and group/security policies, and creating and governing virtual machines at scale.
- Demonstrable experience with Microsoft 365 governance, transport/DLP rule management, and Entra ID administration.
- Strong track record managing cloud spend / FinOps and Software Asset Management (SAM) and licensing compliance.
- Experience managing suppliers and cloud partners within ITIL-aligned operations.
TECHNICAL SKILLS & COMPETENCIES
Core Technical Skills
- Windows Server & Linux administration; Active Directory, Group Policy, DNS, DHCP, PKI/certificates.
- Virtualisation: VMware vSphere/ESXi, Hyper-V; VM creation, policies, templates, and lifecycle.
- Microsoft 365 & Entra ID: Exchange Online, SharePoint, Teams, Intune, conditional access, transport/DLP/retention rules.
- Identity & Access Management (IAM) architecture: Entra ID / Active Directory design, SSO, MFA, conditional access, SCIM, RBAC/ABAC, PAM / PIM, and identity lifecycle automation.
- Cloud engineering: architecting and operating Azure (primary), AWS/GCP — compute, storage, cloud networking, RBAC, Azure Policy, landing zones, and high-availability design.
- FinOps & cost management; Software Asset Management (SAM) and licensing (Microsoft, VMware).
- Automation & IaC: PowerShell, Python, Bash, Terraform, ARM/Bicep.
- Backup/DR (Veeam, Azure Backup); monitoring & observability tooling.
SOFT SKILLS & COMPETENCIES:
- Problem-solving: Strong analytical and structured problem-solving with a methodical, documentation-driven approach.
- Communication: Clear written and verbal English; able to explain technical topics to non-technical stakeholders.
- Ownership: Reliable ownership of infrastructure health, security, and cost with minimal supervision.
- Automation mindset: A default preference for automating repetitive work and eliminating configuration drift.
- Collaboration: Effective supplier and cross-team collaboration within ITIL processes.
ADDITIONAL REQUIREMENTS:
- Based in Gurgaon or Hyderabad, with flexibility to work in shifts and provide on-call / out-of-hours support as required.
- Willingness to travel occasionally to other Xebia sites for infrastructure projects.
- High integrity and commitment to maintaining the confidentiality of all client, applicant, and company information.
Interested person can drop their resume at
[email protected] with following details:
Current CTC, Expected CTC, Notice period/LWD, Current Location
📌 Senior IT Infrastructure Engineer (Gurugram)
🏢 RENOVISION AUTOMATION SERVICES PVT.LTD
📍 Gurugram