Infrastructure & Cyber Security EngineerIgnite Search Partners is working with a rapidly scaling global software company specialising in next-gen Warehouse Management and Supply Chain Execution Systems.
They are seeking an Infrastructure & Cyber Security Engineer to join the Cloud Hosting & Operations team, working as a hands-on individual contributor reporting to the Infrastructure Manager. This role carries a dual responsibility — keeping our infrastructure running reliably across cloud and on-premises environments, while actively protecting systems, data, and platforms from security threats.
Key Responsibilities
- Deploy, operate, and maintain cloud and on-premises infrastructure — ensuring consistent service levels, availability, and security across all platforms (AWS, Huawei Cloud, GCP).
- Manage infrastructure instances including routine patching, capacity monitoring, vulnerability remediation, and hardware lifecycle upkeep.
- Configure and maintain network security components including firewalls (next-gen/WAF), VPNs, IDS/IPS, load balancers, direct connect, and VPC configurations across all cloud platforms.
- Perform regular vulnerability assessments and penetration testing support across infrastructure, cloud environments, and applications; track and remediate findings within agreed SLAs.
- Manage identity and access management (IAM) policies, role-based access controls (RBAC), privileged access, and multi-factor authentication (MFA) across cloud and on-premises systems.
- Provide hands-on infrastructure and security support to delivery teams during customer deployment phases and WMS go-live milestones, ensuring environments are hardened and handover-ready.
- Apply and enforce cloud security controls across all environments in line with ISO 27001, SOC 2, PDPA, and GDPR requirements; manage security group rules, network ACLs, firewall policies, and access controls.
- Support the Infrastructure Manager during compliance reviews, ISO 27001 audits, and SOC 2 assessments by implementing required controls, gathering evidence, and closing remediation items.
- Manage and tune database infrastructure supporting WMS: MySQL DB, MS SQL Server, or PostgreSQL — including HA, backup, and failover.
- This including middleware service (Redis, MongoDB, Kafka, Zookeeper, Nacos).
- Set up and maintain security and infrastructure monitoring using Cloud
- Watch, Grafana, Prometheus, Huawei Cloud Eye, and SIEM platforms; define alert thresholds and escalation workflows.
- Track and report on infrastructure availability, SLA performance, RTO/RPO metrics, security incident trends, and vulnerability posture to the Infrastructure Manager.
- Automate security and infrastructure tasks including provisioning, backup, patching, and system hardening using Python, Shell, or Bash scripts.
- Maintain accurate, up-to-date documentation for all cloud environments, security configurations, incident runbooks, and architecture diagrams.
- Collaborate with R&D, Product, Delivery, and Customer Success teams across regions on infrastructure requirements, security reviews, and deployment coordination.
Requirements
- Minimum 3 years of hands-on experience in IT infrastructure, cloud operations, or cyber security engineering.
- Practical hands-on experience with AWS, Huawei Cloud, or GCP — experience across two or more platforms is a strong advantage.
- Solid understanding and practical application of cyber security principles: network security, endpoint protection, vulnerability management, incident response, and security hardening.
- Familiarity with compliance frameworks: ISO 27001, SOC 2, PDPA, GDPR — ability to implement controls and support audit activities.
- Experience supporting enterprise software environments (WMS, ERP, or Supply Chain platforms) is a strong advantage.
- Experience in application environments like Nginx, tomcat, DB (MYSQL, MSSQL or PostgreSQL), Middleware (Redis, MongoDB, Kafka, Zookeeper, Nacos).
- Linux administration, VPC networking, routing, VPNs, firewall configuration, and network segmentation.
- Docker and Kubernetes basic operations;
- CI/CD security integration;
- HA/DR implementation and cloud security frameworks.
- Infrastructure-as-Code (Terraform, Cloud
- Formation, Ansible) and scripting (Python, Shell, Bash) for automation and security hardening tasks will be an advantage.
- Strong ownership mindset, self-directed work style, attention to detail, and solid analytical problem-solving abilities.
Excellent written and spoken English; Mandarin proficiency is a strong plus for regional team and client collaboration.