Sr Infrastructure & Security Engineer
Azure DevOps
CI/CD
Cloud Infrastructure
Cloud Platform
Cloud Platforms
Cloud Security
Cloud Security Assurance
Cloud Security Posture Management
Data Security
DevOps
Devops Tools
DevSecOps
Engineer
Facilities Management
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Network Security
Opsec
Pci Dss
Project Management
Risk Management
Security
Security Automation
Security Compliance
Security Engineering
Security Operations
Security Standards
Software Development
Solution Architecture
Job Description
VizyPay is seeking a senior infrastructure and security engineer to own the systems that keep the organization connected, protected, and audit-ready. This role combines cloud infrastructure, enterprise networking, security posture, operational reliability, and end-user support into a single accountable mandate, with direct reporting to the CIO.
Working in a cloud-first, security- and compliance-driven payments environment, you will help maintain availability and resilience (including RTO/RPO alignment), strengthen detection and response readiness, and contribute to PCI DSS and enterprise BCP/DR efforts. The position is based onsite in Waukee, IA.
What you’ll do
- Architect, build, and operate secure, scalable cloud infrastructure across Microsoft Azure, AWS, and DigitalOcean, covering compute, virtual networking, storage, and managed data services for VEXIS and enterprise systems.
- Expand infrastructure-as-code as the default provisioning path, including Terraform, GitOps automation, policy-as-code, and IaC security scanning; implement CI/CD pipelines (for example, GitHub Actions and Azure DevOps) with automated testing and controlled promotion to remove manual, unrepeatable changes.
- Manage infrastructure cost and capacity through rightsizing, reserved-capacity strategy, usage monitoring, and performance optimization, with spend reported against approved budget while keeping capacity ahead of business growth.
- Provide hands-on technical leadership across InfraSec and in partnership with Software Engineering through engineering standards, design and architecture reviews, and mentorship.
- Administer and support the enterprise network, including firewalls, SD-WAN, switches, wireless access points, and overall network infrastructure, with design, configuration, monitoring, and lifecycle management.
- Own network segmentation design and enforcement, deploy TLS 1.2+ everywhere, and manage secure connectivity including site-to-site and remote-access VPN, DNS, load balancing, and WAF/CDN (such as Cloudflare) aligned with least privilege.
- Maintain network documentation, configuration baselines, and audit-ready change records, while managing network capacity, performance, and availability.
- Own key security platforms and services such as IAM, endpoint security, MDM, password management, security monitoring, and Microsoft 365 security posture, including email security controls (for example anti-phishing, DMARC, DKIM, SPF) with administration, integration, and continuous improvement.
- Lead security monitoring and detection engineering across enterprise SIEM, EDR, and file integrity monitoring (FIM) platforms, including log-source onboarding, detection tuning, alert refinement, and response runbooks.
- Operate vulnerability and patch management programs, manage asset/configuration inventory, and own identity lifecycle management (joiner/mover/leaver), conditional-access administration, and privileged access management (PAM). Enforce vault-based secrets management and MFA-inclusive authentication, and lead threat modeling and security-by-design with Software Engineering and Product.
- Define and operate SLOs, error budgets, and availability/performance monitoring; own observability end to end across metrics, structured logging, distributed tracing, and alert design (for example Prometheus/Grafana, CloudWatch, Azure Monitor) with centralized log management and retention aligned with compliance needs, driving automation-first operations to reduce toil.
- Own incident response for infrastructure and security, covering detection, escalation, mitigation, and blameless postmortems with tracked corrective actions; participate in the on-call rotation and operate production changes under formal change management.
- Act as the Tier 2/3 escalation point for end-user support in partnership with the InfraSec Help Desk, including endpoint engineering and lifecycle management, Microsoft 365 administration and troubleshooting across devices and business systems, and automation of support workflows with measured service quality.
- Participate in the annual PCI DSS assessment and audit process, including evidence collection, remediation activities, control validation, coordination with stakeholders and external assessors, and external penetration test coordination and remediation tracking. Maintain audit-ready evidence year-round for configuration standards, access reviews, segmentation validation, monitoring coverage, and recovery-test results.
- Design and validate resilience with RTO/RPO alignment, backup and recovery, failover architecture, and graceful degradation, and plan disaster-recovery exercises consistent with enterprise BCP/DR standards.
- Contribute to security policy, standards, and risk assessments, and support employee security-awareness enablement in partnership with the CIO while aligning controls with PCI DSS and financial-industry obligations.
What you bring
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent).
- 7+ years of professional experience across infrastructure, cloud, network, security, or site reliability engineering, including 4+ years operating production infrastructure and security controls at scale with accountability for availability, cost, risk, and outcomes.
- Ability to operate with a high degree of autonomy while owning infrastructure and security strategy, priorities, and execution, reporting directly to executive leadership.
- Experience in security- or compliance-constrained environments (such as PCI DSS or financial services regulation), including participation in compliance assessments and audit evidence collection, delivering under formal SDLC and change management.
- Demonstrated incident-response ownership across infrastructure and security domains, including on-call participation, incident command or mitigation leadership, and postmortem-driven improvement.
- Ability to translate infrastructure, security, and reliability tradeoffs into recommendations for technical and executive stakeholders.
- Production engineering experience on Microsoft Azure, AWS, and/or DigitalOcean across compute, virtual networking, IAM, storage, and managed database services.
- Infrastructure automation skills with Terraform (or equivalent), GitOps, configuration management, and CI/CD engineering (for example GitHub Actions and Azure DevOps) with security scanning and progressive delivery; operational tooling using Python, PowerShell, and/or Bash with strong Git fluency.
- Expertise in containers and orchestration/managed container services, including Docker and Kubernetes (such as AKS, EKS, or DigitalOcean Kubernetes) and serverless/edge compute (such as AWS Lambda and Cloudflare Workers).
- Understanding of operating systems and directory services, including Windows Server, Linux, Active Directory/Microsoft Entra hybrid identity, and Microsoft 365 administration.
- Network infrastructure experience covering enterprise firewalls, SD-WAN, switching, and wireless, including routing/switching fundamentals (such as VLANs, routing protocols, and QoS) and VPN.
- Network and cloud security knowledge including segmentation, firewall policy management, DNS, TLS certificate management, WAF/CDN (for example Cloudflare), encryption in transit and at rest, and cloud security posture management (CSPM).
- Security monitoring, detection, and vulnerability management experience with enterprise SIEM/log analytics, EDR, and FIM, including detection content development, alert tuning, response integration, plus scanning, risk-based prioritization, and remediation workflow design.
- Knowledge of identity, endpoint, and end-user platforms including least-privilege RBAC, MFA-inclusive authentication, identity lifecycle management and PAM, directory and identity platforms (including Microsoft Entra ID and AWS IAM), endpoint security, MDM, password management, and vault-based secrets management.
- Reliability engineering experience including SLO/error-budget practice, observability tooling, database backup/recovery, replication, and point-in-time restore (for example PostgreSQL, SQL Server, MySQL).
- Track record of technical leadership such as mentoring, architecture or design review, or engineering standards ownership.
Technologies you may work with
- Microsoft Azure, AWS, DigitalOcean, Terraform, GitOps, policy-as-code, IaC security scanning
- GitHub Actions, Azure DevOps, Microsoft 365, IAM, MDM, DMARC, DKIM, SPF
- SIEM, EDR, file integrity monitoring (FIM), Prometheus, Grafana, CloudWatch, Azure Monitor
- SLOs, PCI DSS, RTO/RPO, TLS 1.2+, SD-WAN, Cloudflare, VPN, DNS, WAF
- Privileged access management (PAM), vault-based secrets management, MFA-inclusive authentication, Active Directory, Microsoft Entra, AWS IAM
- Docker, Kubernetes, AKS, EKS, AWS Lambda, Cloudflare Workers
- Windows Server, Linux, VLANs, QoS, CSPM, RBAC, Python, PowerShell, Bash, Git, CI/CD, distributed tracing, structured logging, PostgreSQL, SQL Server, MySQL
Compensation and benefits
- Salary: USD 80,000 - 100,000 per year
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Paid time off
- Retirement plan
- Vision insurance