Role Purpose
The Intelligent Substation programme operates across the boundary between operational technology, edge computing, and Azure cloud services.
Its solutions connect distributed substation environments to centrally managed cloud platforms, enabling secure data acquisition, monitoring, analytics, and application services.
We are seeking a senior, hands-on Cloud Infrastructure and Network Engineer to join a small multidisciplinary team responsible for maintaining, supporting and further developing this distributed environment.
The role requires deep network diagnostic capability together with practical experience of Azure hybrid infrastructure, Azure Local, Azure Arc and Kubernetes platforms.
Key Responsibilities
- Design, build, maintain and troubleshoot hybrid infrastructure connecting distributed edge locations with Azure services.
- Support Azure Local, Azure Arc-enabled servers, Arc-enabled Kubernetes and Arc-managed AKS environments.
- Configure and maintain Azure virtual networks, routing, network security controls, private endpoints, DNS and hybrid connectivity.
- Support ExpressRoute, VPN Gateway and other private connectivity patterns between operational locations, data centres and Azure.
- Analyze packet captures to diagnose application, transport, routing, firewall, name-resolution, certificate and protocol issues.
- Reproduce and test network conditions and traffic flows using tools such as Wireshark, tcp dump, tcp replay and related Linux utilities.
- Design and maintain network segmentation, VLAN, NAT, routing and firewall policies across IT, cloud, edge and operational technology environments.
- Support Azure Firewall, Network Security Groups, Private Link and controlled outbound connectivity patterns.
- Implement and support identity, certificate and trust services used by distributed infrastructure and edge applications.
- Automate infrastructure deployment, configuration and validation using Terraform, Bash, PowerShell and other appropriate tooling.
- Establish infrastructure and network monitoring using Azure Monitor, Log Analytics, Network Watcher, Prometheus, Grafana and associated alerting.
- Investigate and resolve incidents spanning edge infrastructure, cloud services, Kubernetes, connectivity and security controls.
- Produce and maintain network diagrams, configuration documentation, operational procedures and recovery guidance.
- Work closely with software, security, architecture, data and electrical transmission domain specialists, as well as telecommunications and infrastructure partners.
Required Skills and Experience
- 10+ years’ experience in network, cloud infrastructure or hybrid-platform engineering.
- Deep practical knowledge of IP networking, subnetting, routing, VLANs, NAT, DNS, firewalls, proxies and network segmentation.
- Advanced packet-capture and protocol-analysis skills, including the ability to interpret PCAP files and diagnose issues across multiple network layers.
- Strong hands-on experience with Wireshark, tcpdump, tcpreplay or comparable network diagnostic tools.
- Significant experience designing and operating Azure networking, including Virtual Network, Express Route, VPN Gateway, Azure Firewall and Private Link.
- Strong experience with Azure Local and Azure Arc in distributed or hybrid environments.
- Experience deploying or supporting Arc-enabled Kubernetes and AKS running on customer-managed infrastructure.
- Good understanding of Kubernetes networking, ingress, service discovery, load balancing, certificates and container-to-container communication.
- Experience with Entra ID, managed identities, role-based access control, certificate services and public key infrastructure.
- Strong Linux administration and Bash scripting skills, together with PowerShell experience.
- Experience implementing infrastructure as code using Terraform or an equivalent technology.
- Practical knowledge of cloud and infrastructure monitoring, logging, alerting and incident management.
- Ability to troubleshoot complex problems involving multiple suppliers, platforms, network zones and security boundaries.
Preferred Certifications
- Microsoft Certified: Azure Network Engineer Associate.
- Microsoft Certified: Azure Solutions Architect Expert.
- Cisco CCNP Enterprise, CCNP Security or equivalent.
- Relevant Azure Hybrid, Kubernetes or security certification.