Sr Infrastructure & Security Engineer
Job Description
Build, secure, and keep connected VizyPay’s cloud infrastructure, enterprise network, security posture, and operational reliability. In this onsite role in Waukee, IA, you will own the infrastructure foundation beneath VEXIS and support the business systems that keep payments operations protected and audit-ready.
Reporting directly to the CIO, this senior, hands-on individual-contributor position unifies cloud and platform engineering, networking, site reliability engineering, security engineering, and end-user support under one mandate. You will be a core contributor to the annual PCI DSS assessment and to the enterprise BCP/DR programs, including resilience planning and disaster-recovery exercises.
Responsibilities
- Architect, build, and operate secure, scalable cloud infrastructure across Microsoft Azure, AWS, and DigitalOcean, including compute, virtual networking, storage, and managed data services supporting VEXIS and enterprise systems.
- Make infrastructure-as-code (for example Terraform) and GitOps automation the default provisioning path, including policy-as-code and IaC security scanning; build CI/CD pipelines (for example GitHub Actions, Azure DevOps) with automated testing and controlled promotion.
- Manage infrastructure cost and capacity through rightsizing, reserved-capacity strategy, usage monitoring, and performance optimization, with spend reported against approved budget and capacity ahead of business growth.
- Provide technical leadership across InfraSec and partner with Software Engineering through engineering standards, architecture and design reviews, and mentorship while remaining a hands-on IC.
- Administer and support the enterprise network, including firewalls, SD-WAN, switches, wireless access points, and network infrastructure lifecycle management.
- Own network segmentation enforcement, TLS 1.2+ everywhere, and secure connectivity (site-to-site and remote-access VPN, DNS, load balancing, and WAF/CDN such as Cloudflare) aligned with least privilege.
- Maintain network documentation, configuration baselines, and audit-ready change records; manage network capacity, performance, and availability.
- Own and manage security platforms and services including IAM, endpoint security, MDM, password management, security monitoring, and Microsoft 365 security posture with email security controls (anti-phishing, DMARC, DKIM, SPF), including administration, policy integration, and continuous improvement.
- Lead security monitoring and detection engineering across SIEM, EDR, and file integrity monitoring (FIM) platforms, including log-source onboarding, detection content, alert tuning, and response runbooks.
- Operate vulnerability management (coverage, risk-based prioritization, remediation SLAs), patch management cadence, and asset/configuration inventory; own identity lifecycle management (joiner/mover/leaver), conditional-access administration, and privileged access management (PAM); enforce vault-based secrets management and MFA-inclusive authentication; lead threat modeling and security-by-design with Software Engineering and Product.
- Define and operate SLOs, error budgets, and availability/performance monitoring; own the observability stack end to end (metrics, structured logging, distributed tracing, alert design) and drive automation-first operations to reduce toil.
- Own incident response across infrastructure and security, including detection, escalation, mitigation, and blameless postmortems with tracked corrective actions; participate in on-call rotation and execute production changes under formal change management.
- Serve as Tier 2/3 escalation for end-user support in partnership with the InfraSec Help Desk, covering endpoint engineering and lifecycle management and Microsoft 365 administration and troubleshooting, plus automation of support workflows with measured service quality.
- Participate in annual PCI DSS assessment and audit processes, including evidence collection, remediation activities, control validation, coordination of external penetration testing, and year-round audit-ready evidence (standards, access reviews, segmentation validation, monitoring coverage, and recovery-test results).
- Design and validate resilience aligned with RTO/RPO, backups, recovery, failover architecture, graceful degradation, and disaster-recovery exercises consistent with enterprise BCP/DR standards.
- Contribute to security policy, standards, risk assessments, and employee security-awareness enablement with the CIO, aligning controls with PCI DSS and financial-industry obligations.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent).
- 7+ years of professional experience across infrastructure, cloud, network, security, or site reliability engineering, including 4+ years operating production infrastructure and security controls at scale with accountability for availability, cost, risk, and outcomes.
- Ability to operate with a high degree of autonomy, owning infrastructure and security strategy, priorities, and execution while reporting directly to executive leadership.
- Experience in security- or compliance-constrained environments (for example PCI DSS or financial services regulation), including direct participation in compliance assessments and audit evidence collection with delivery under formal SDLC and change management.
- Demonstrated incident-response ownership across infrastructure and security, including on-call participation, incident command or mitigation leadership, and postmortem-driven improvement.
- Ability to translate infrastructure, security, and reliability tradeoffs into clear recommendations for technical and executive stakeholders.
- Production engineering experience on Microsoft Azure, AWS, or DigitalOcean, including compute, virtual networking, IAM, storage, and managed database services.
- Infrastructure automation experience with Terraform (or equivalent), GitOps workflows, configuration management, and CI/CD engineering (for example GitHub Actions, Azure DevOps) with security scanning and progressive delivery; operational tooling in Python, PowerShell, and/or Bash with strong Git fluency.
- Expertise in containers and orchestration (for example Docker and Kubernetes such as AKS, EKS, or DigitalOcean Kubernetes) or managed container services, plus serverless/edge compute (for example AWS Lambda, Cloudflare Workers).
- Understanding of operating systems and directory services: Windows Server, Linux, and Active Directory/Microsoft Entra hybrid identity, plus Microsoft 365 administration.
- Skilled in enterprise network infrastructure and troubleshooting (firewalls, SD-WAN, switching, wireless), with routing and switching fundamentals including VLANs, routing protocols, and QoS, plus VPN experience.
- Knowledge in network and cloud security including segmentation, firewall policy management, DNS, TLS certificate management, WAF/CDN such as Cloudflare, encryption in transit and at rest, and CSPM.
- Experience with security monitoring, detection, and vulnerability management using enterprise SIEM/log analytics, EDR, and FIM, including detection content development, alert tuning, and remediation workflows.
- Knowledge of identity, endpoint, and end-user platforms, including least-privilege RBAC, MFA-inclusive authentication, identity lifecycle and PAM, directory and identity platforms (such as Microsoft Entra ID, AWS IAM), endpoint security, MDM, password management, and vault-based secrets management.
- Reliability engineering skills including SLO/error-budget practice, observability tooling, database backup and recovery, replication, and point-in-time restore (for example PostgreSQL, SQL Server, MySQL).
- Track record of technical leadership through mentoring, architecture or design reviews, or ownership of engineering standards.
Technologies
Microsoft Azure, AWS, DigitalOcean, Terraform, GitOps, policy-as-code, IaC security scanning, GitHub Actions, Azure DevOps, Microsoft 365, IAM, MDM, DMARC, DKIM, SPF, SIEM, EDR, file integrity monitoring (FIM), Prometheus, Grafana, CloudWatch, Azure Monitor, SLOs, PCI DSS, RTO/RPO, TLS 1.2+, SD-WAN, Cloudflare, VPN, DNS, WAF, SIEM/log analytics, privileged access management (PAM), vault-based secrets management, MFA-inclusive authentication, Active Directory, Microsoft Entra, Microsoft Entra ID, AWS IAM, Docker, Kubernetes, AKS, EKS, AWS Lambda, Cloudflare Workers, Windows Server, Linux, VLANs, QoS, CSPM, RBAC, Python, PowerShell, Bash, Git, CI/CD, distributed tracing, structured logging, PostgreSQL, SQL Server, MySQL
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Paid time off
- Retirement plan
- Vision insurance
Compensation: USD 80,000 - 100,000 per year.