Senior Infrastructure & Security Engineer

🏒 Harris · all Harris jobs
πŸ“ United Kingdom
πŸ“… Posted 2026-07-01 Β· via Himalayas
🏷 Security-Engineer,Infrastructure-Engineering,Security-Engineering,Sr.-Infrastructure-Security-Engineer,Senior-Cloud-Infrastructure-Security-Engineer,Cloud-Engineer,DevOps-Engineer,Systems-Administrator
Apply on original site β†—

Commerce Decisions, part of Harris Computer Company are currently seeking an experienced Senior Infrastructure & Security Engineer on a full-time, permanent basis operating on a remote working model.

Commerce Decisions is part of Harris . Harris ’ strategy focuses on acquiring software businesses, strengthening and managing them well, and growing them for the future. Our companies provide mission-critical software solutions to a global customer base across various vertical markets. We are part of Constellation Software Inc. (TSX: CSU), one of the world’s most active acquirers of software businesses.
Role Responsibilities
Infrastructure & cloud operations

-
Design, implement and run cloud infrastructure across Azure and Oracle Cloud (OCI) spanning the UK and Canada, for high availability, scalability and security.

-
Administer a mixed Linux and Windows server estate, plus Docker and Kubernetes workloads.

-
Own deployment of monthly SaaS releases, updates and patches into Staging, internal and hosted customer environments (Dev produces the release package).

-
Light MySQL maintenance: version upgrades, backup monitoring, replica health checks and tuning improvements.

-
Manage internal IT assets and users via ManageEngine; monitor staff device patch status.

-
Maintain internal servers and QA/test environments.

-
Investigate and resolve infrastructure issues and bugs, supporting the wider engineering team.

Automation & modernisation (β‰ˆ50% of the role)

-
Lead the migration of manually-built Oracle Cloud environments onto Terraform and Ansible, with proper change management.

-
Partner with Development to identify and build automation that improves releases and deployment. A key future initiative is building an installer to deploy updates remotely to self-hosted customers β€” replacing the time-consuming, costly on-site visits.

-
Drive automation and modernisation as a continuous theme, treating infrastructure-as-code as the living source of truth for infrastructure state.

Security engineering

- Patch management across the estate.

-
Maintain and improve hardened environments to CIS benchmarks – you’ll lead the technical hardening standards and drive their implementation.

-
Threat-horizon monitoring: track IT news, vendor advisories, CVE feeds, NCSC and similar for issues relevant to our stack, and drive remediation.

-
Operate security tooling (CrowdStrike, ESET, Rapid7, or equivalents): deploy agents, ensure coverage and updates, monitor dashboards, and triage and analyse alerts.

-
Coordinate penetration tests end-to-end and own scoping β€” as the person with the deepest knowledge of our exposed attack surface β€” through execution, triage, remediation and evidencing closure.

-
Author and review customer security questionnaires and bid responses about our hosting environments and security controls.

-
Provide technical evidence and implement controls in support of ISO 27001 and Cyber Essentials Plus; occasionally contribute to MOD-aligned security responses (e.g. JSP 440, Secure by Design).

Networking
-
Hands-on (and IaC) with Cloud based load balancers, SSL certs & ciphers, WAFs (configuration and management), security headers, network security groups and VPNs.

Resilience & business continuity

-
Capacity monitoring and resilience planning; design for high availability and scalability (Kubernetes and similar), in collaboration with Development.

-
Lead disaster-recovery and business-continuity capability: design it, test it regularly, and automate backup/restore and failover wherever possible.

-
Build and maintain alerting and observability so the right people can see what they need β€” consolidating and improving across Grafana/Loki (application logs), ManageEngine log analytics (server logs) and PRTG (server sensors).

Documentation & operating rhythm

-
Maintain infrastructure-as-code as the primary record of infrastructure state, supported by clear runbooks, operational processes and dec

← All remote jobs