plush
bar

Job Description

Position:

Senior Infrastructure & Directory Services Engineer

Salary/Package:

Basic Salary + Non-Sales Incentive

Benefits:

25 days holiday entitlement rising to 28 days after 5 plus years’ service

Business Unit:

Services

Reporting to:

Head of Service Architecture & Delivery

Location/site:

Caerphilly (with travel to client/Ministry of Defence sites as required)

Vetting requirements:

Yes

Company Overview

Centerprise International (Ci) was established in 1983 and has over 30 years of experience delivering innovative ICT products and services. Our financial strength, broad portfolio, and record of success in government contracts make Ci one of the UK’s leading ICT suppliers. We continually evolve to meet market demands, now offering Managed Services and Solution Design in addition to our own products. Ci actively attracts and develops talented individuals, providing the opportunity to build a varied career path within our group of companies. All employees learn from experienced professionals and see first-hand how a thriving privatelyowned business operates. 

Role Description

We are delivering a secure, on?premise, multi?domain virtualised infrastructure for a major Defence customer. This includes directory and identity services, Windows infrastructure, core authentication components, and platform services that underpin operational and mission?critical systems. As a Senior Infrastructure & Directory Services Engineer, you will focus primarily on Active Directory, identity, Windows Server and core infrastructure services across several security domains. You will play a key role in maintaining the integrity, security and reliability of these services, while working alongside specialists across networking, security, Linux, virtualisation, and automation. Virtualisation knowledge (VMware vSphere, vCenter, ESXi, NSX?T) is highly advantageous. 

Key responsiblities 

• Architect, manage, and support multi-site Active Directory environments • Administer DNS, DHCP, and PKI infrastructure in secure environments • Design and enforce Group Policy Objects (GPOs) for security and compliance • Manage Web Application Proxy (WAP), RDS, and federation services • Implement and maintain permissions and access control models • Ensure compliance with MOD security standards and Secure by Design principles • Support MOD accreditation processes and security audits (e.g., IT Health Checks, CCVAs) • Collaborate with cross-functional teams (Security, Cloud, Virtualisation, Networking) • Participate in Change Advisory Boards (CAB) and technical design reviews • Maintain domain documentation, diagrams, and CMDB records • Drive innovation through evaluation of emerging identity technologies • Act as a senior escalation point for directory and infrastructure issues. • Work closely with specialists in networking, virtualisation, Linux, security, and automation. • Monitor domain performance and security using tools like Splunk and PowerShell • Automate routine tasks and operational workflows using PowerShell (essential); familiarity with Ansible is desirable. • Maintain operational scripts, work instructions, and associated documentation.

Competencies

Experience and Skills

Essential

  • Multi-site Active Directory design and support
  • Windows Server, DNS, DHCP
  • Group Policy management and troubleshooting
  • PKI and certificate services
  • Web Application Proxy and RDS
  • Secure access and permissions management
  • PowerShell scripting and automation
  • ITIL-based service management
  • Experience working in secure or regulated environments (Defence, Government, critical national infrastructure, etc.).
  • Strong diagnostic skills across authentication, domain services, Windows Server and multi?site infrastructure.

Desirable

  • Defence sector experience (MOD, JSP, ISO 27001)
  • Microsoft Certified: Identity and Access Administrator
  • Experience with VMware technologies (vSphere, vCenter, ESXi)
  • Awareness of NSX?T or virtualised networking.
  • Understanding of monitoring/logging concepts (e.g., SIEM fundamentals, event correlation, alerting).
  • Experience with Ansible or other automation/orchestration tools.
  • Familiarity with Linux/Unix integration with AD.
  • General understanding of secure WAN technologies (BGP/MPLS/VPN) helpful
  • Existing SC or DV clearance

Company Profile

Essential

  • • Communication Skills: Clear, concise, and professional communication with technical and non-technical stakeholders • Drive for Results: Strong ownership and accountability for delivering high-quality outcomes • Problem Solving: Analytical and methodical approach to diagnosing and resolving complex issues • Leadership & Collaboration: Ability to lead technical discussions, mentor peers, and work cross-functionally
  • Customer-Centric - Ensure customer satisfaction is our number one priority
  • Commitment - Be true to your work and go the extra mile to deliver on your promise
  • Courage To Challenge - Have the strength to make a difference and don’t be afraid to constructively challenge the status quo
  • Succeed - Be innovative and do all that is reasonable to deliver a positive outcome
  • Dedication - Giving your time and energy in the best interests of the Company

Education/Qualifications/Specific training

Essential

  • • Microsoft Certified: Identity and Access Administrator Associate (or equivalent) • ITIL v4 Foundation or higher • Degree in Computer Science, Information Systems, or equivalent experience
bar