Senior Infrastructure & Security Engineer
Commerce Decisions, part of Harris Computer Company are currently seeking an experienced Senior Infrastructure & Security Engineer on a full-time, permanent basis operating on a remote working model.
Commerce Decisions is part of Harris . Harris β strategy focuses on acquiring software businesses, strengthening and managing them well, and growing them for the future. Our companies provide mission-critical software solutions to a global customer base across various vertical markets. We are part of Constellation Software Inc. (TSX: CSU), one of the worldβs most active acquirers of software businesses.
Role Responsibilities
Infrastructure & cloud operations
-
Design, implement and run cloud infrastructure across Azure and Oracle Cloud (OCI) spanning the UK and Canada, for high availability, scalability and security.
-
Administer a mixed Linux and Windows server estate, plus Docker and Kubernetes workloads.
-
Own deployment of monthly SaaS releases, updates and patches into Staging, internal and hosted customer environments (Dev produces the release package).
-
Light MySQL maintenance: version upgrades, backup monitoring, replica health checks and tuning improvements.
-
Manage internal IT assets and users via ManageEngine; monitor staff device patch status.
-
Maintain internal servers and QA/test environments.
-
Investigate and resolve infrastructure issues and bugs, supporting the wider engineering team.
Automation & modernisation (β50% of the role)
-
Lead the migration of manually-built Oracle Cloud environments onto Terraform and Ansible, with proper change management.
-
Partner with Development to identify and build automation that improves releases and deployment. A key future initiative is building an installer to deploy updates remotely to self-hosted customers β replacing the time-consuming, costly on-site visits.
-
Drive automation and modernisation as a continuous theme, treating infrastructure-as-code as the living source of truth for infrastructure state.
Security engineering
- Patch management across the estate.
-
Maintain and improve hardened environments to CIS benchmarks β youβll lead the technical hardening standards and drive their implementation.
-
Threat-horizon monitoring: track IT news, vendor advisories, CVE feeds, NCSC and similar for issues relevant to our stack, and drive remediation.
-
Operate security tooling (CrowdStrike, ESET, Rapid7, or equivalents): deploy agents, ensure coverage and updates, monitor dashboards, and triage and analyse alerts.
-
Coordinate penetration tests end-to-end and own scoping β as the person with the deepest knowledge of our exposed attack surface β through execution, triage, remediation and evidencing closure.
-
Author and review customer security questionnaires and bid responses about our hosting environments and security controls.
-
Provide technical evidence and implement controls in support of ISO 27001 and Cyber Essentials Plus; occasionally contribute to MOD-aligned security responses (e.g. JSP 440, Secure by Design).
Networking
-
Hands-on (and IaC) with Cloud based load balancers, SSL certs & ciphers, WAFs (configuration and management), security headers, network security groups and VPNs.
Resilience & business continuity
-
Capacity monitoring and resilience planning; design for high availability and scalability (Kubernetes and similar), in collaboration with Development.
-
Lead disaster-recovery and business-continuity capability: design it, test it regularly, and automate backup/restore and failover wherever possible.
-
Build and maintain alerting and observability so the right people can see what they need β consolidating and improving across Grafana/Loki (application logs), ManageEngine log analytics (server logs) and PRTG (server sensors).
Documentation & operating rhythm
-
Maintain infrastructure-as-code as the primary record of infrastructure state, supported by clear runbooks, operational processes and dec