- Company Name
- Vesta Consulting Limited
- Job Title
- Infrastructure Architect; SC cleared, Defence, Azure, AWS, identity, storage, networking, security
- Job Description
-
**Job Title:**
Infrastructure Architect (SC‑cleared)
**Role Summary:**
Design and deliver end‑to‑end secure, large‑scale infrastructure solutions across on‑premises, cloud (Azure/AWS), and edge environments for defence projects. Ensure compliance with Government security classifications, NCSC standards, and MOD/NAF architectural frameworks while operating in an Agile, multi‑supplier setting.
**Expectations:**
- Active UK Security Clearance (SC) – mandatory.
- Ability to travel up to 2 days per week (Taunton‑based).
- Strong collaboration with cross‑functional teams (designers, developers, product).
- Delivery within Agile/Scrum frameworks and adherence to change‑governance processes.
**Key Responsibilities:**
- Lead architecture and delivery of hybrid infrastructure (on‑prem, Azure, AWS, edge).
- Develop high‑level and low‑level design documentation, risk/impact assessments, and capacity plans.
- Implement security controls: network segmentation, zero‑trust, key/certificate management, firewalls/WAF, EDR, SIEM, vulnerability management.
- Design and operate DR/BCP solutions with multi‑region/zone resilience.
- Automate infrastructure provisioning using IaC (Terraform, Bicep, CloudFormation) and configuration management (Ansible, DSC).
- Create CI/CD pipelines for infrastructure changes; apply policy‑as‑code and immutable infrastructure patterns.
- Manage identity services (AD/AAD, PAM, SSO/MFA, federation) and networking components (TCP/IP, routing, VPN, SD‑WAN, DNS/DHCP, load balancing).
- Provide observability through logging, metrics, tracing, SIEM/SOAR, and performance tuning.
- Maintain asset/configuration data (CMDB) and ensure audit readiness.
**Required Skills:**
- Cloud platforms: Azure (landing zones, IAM, networking, HA/DR) and/or AWS (IAM, networking, HA/DR).
- On‑prem virtualization: VMware or Hyper‑V; Windows/Linux server administration.
- Storage: SAN/NAS, backup/DR solutions.
- Networking: TCP/IP, routing, VPN, SD‑WAN, DNS/DHCP, load balancers.
- Identity & access: AD/AAD, Privileged Access Management, SSO/MFA, federation.
- Security: NCSC standards, zero‑trust design, firewalls/WAF, EDR, SIEM, vulnerability management.
- Automation/DevOps: Terraform, Bicep, CloudFormation, Ansible, DSC, PowerShell, Python.
- Observability tools: SIEM/SOAR, logging/metrics platforms, performance monitoring.
- Agile/Scrum delivery, documentation (HLD/LLD), risk assessment.
- Familiarity with MODAF/NAF (nice‑to‑have), TOGAF/ITIL (helpful).
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Engineering, Information Technology, or related field (or equivalent experience).
- Active SC security clearance (must be held before start).
- Preferred certifications: TOGAF, ITIL Foundation, AWS Certified Solutions Architect, Microsoft Certified: Azure Solutions Architect Expert, Certified Information Systems Security Professional (CISSP) or equivalent.