This position is in-office, located in Waukee, Iowa.The GigThe Sr. Infrastructure & Security Engineer owns the cloud infrastructure, enterprise network, security posture, operational reliability, and end-user support functions that keep VizyPay connected, protected, and audit-ready. Reporting directly to the CIO, the role unifies cloud and platform engineering, networking, site reliability engineering, security engineering, and IT support into a single senior individual-contributor mandate spanning the infrastructure foundation beneath VEXIS - VizyPay's proprietary CRM platform - and the organization's business systems. The role is a core contributor to the annual PCI DSS assessment and the enterprise BCP/DR programs. Operating cloud-first in a security- and compliance-driven payments environment, it is accountable for availability and resilience (RTO/RPO), detection and response readiness, measurable risk reduction, infrastructure cost, and audit-ready controls in production.
Cloud, Infrastructure & Platform Engineering- Architect, build, and operate secure, scalable cloud infrastructure across Microsoft Azure, AWS, and DigitalOcean - compute, virtual networking, storage, and managed data services - supporting VEXIS and enterprise systems.
- Expand infrastructure-as-code (e.g., Terraform) and GitOps automation as the default provisioning path, including policy-as-code and IaC security scanning; build CI/CD pipelines (e.g., GitHub Actions, Azure DevOps) with automated testing and controlled promotion; eliminate manual, unrepeatable changes.
- Manage infrastructure cost and capacity: rightsizing, reserved-capacity strategy, usage monitoring, and performance optimization, with spend reported against approved budget and capacity kept ahead of business growth.
- Provide technical leadership across InfraSec and in partnership with Software Engineering: engineering standards, design and architecture reviews, and mentorship as a hands-on individual contributor.
Networking- Administer and support the enterprise network - firewalls, SD-WAN, switches, wireless access points, and overall network infrastructure - including design, configuration, monitoring, and lifecycle management.
- Own network segmentation design and enforcement, TLS 1.2+ everywhere, and secure connectivity - site-to-site and remote-access VPN, DNS, load balancing, and WAF/CDN (e.g., Cloudflare) - aligned with least privilege.
- Maintain network documentation, configuration baselines, and audit-ready change records; manage network capacity, performance, and availability.
Security Engineering & Identity- Own and manage key security platforms and services - identity and access management (IAM), endpoint security, mobile device management (MDM), password management, security monitoring, and Microsoft 365 security posture, including email security controls (e.g., anti-phishing, DMARC/DKIM/SPF) - including administration, policy, integration, and continuous improvement.
- Own security monitoring and detection engineering across enterprise SIEM, EDR, and file integrity monitoring (FIM) platforms: log-source onboarding, detection content, alert tuning, and response runbooks.
- Operate the vulnerability management program (coverage, risk-based prioritization, remediation SLAs), patch management cadence for operating systems and endpoints, and asset/configuration inventory; own identity lifecycle management (joiner/mover/leaver), conditional-access policy administration, and privileged access management (PAM); enforce vault-based secrets management and MFA-inclusive authentication; lead threat modeling and security-by-design with Software Engineering and Product.
Reliability, Operations & End-User Support- Define and operate SLOs, error budgets, and availability/performance monitoring; own the observability stack end to end - metrics, structured logging, distributed tracing, and alert design (e.g., Prometheus/Grafana, CloudWatch, Azure Monitor) - with centralized log management and retention aligned with compliance requirements; drive toil reduction through automation-first operations.
- Own incident response across infrastructure and security: detection, escalation, mitigation, and blameless postmortems with tracked corrective actions; participate in the on-call rotation; operate all production changes under formal change management.
- Serve as the Tier 2/3 escalation point for end-user support in partnership with the InfraSec Help Desk: endpoint engineering and lifecycle management, Microsoft 365 administration and troubleshooting across devices and business systems, and automation of support workflows with measured service quality.
Governance, Compliance & Resilience- Participate in the annual PCI DSS assessment and audit process - evidence collection, remediation activities, control validation, and collaboration with internal stakeholders and external assessors - coordinate external penetration testing and remediation tracking, and maintain audit-ready evidence year-round: configuration standards, access reviews, segmentation validation, monitoring coverage, and recovery-test results.
- Design and validate resilience - RTO/RPO alignment, backup and recovery, failover architecture, and graceful degradation - and plan and execute disaster-recovery exercises consistent with enterprise BCP/DR standards.
- Contribute to security policy, standards, risk assessments, and employee security-awareness enablement in partnership with the CIO; align all controls with PCI DSS and financial-industry obligations.
Requirements
Ready to Level Up?- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent, required.
- Required 7+ years of professional experience across infrastructure, cloud, network, security, or site reliability engineering, including 4+ years operating production infrastructure and security controls at scale with accountability for availability, cost, risk, and outcomes.
- Preferred cloud and automation certifications: AWS Solutions Architect - Professional or DevOps Engineer - Professional, Azure Solutions Architect Expert (AZ-305), Azure Administrator (AZ-104), CKA, or HashiCorp Terraform Associate.
- Preferred security and identity certifications: ISC2 CISSP or CCSP, CSA CCSK, Microsoft AZ-500, SC-300, SC-100, or MD-102, AWS Security - Specialty, CKS, or CompTIA Security+/CySA+.
- Preferred networking, incident-response, and compliance certifications: Microsoft AZ-700 or SC-200, AWS Advanced Networking - Specialty, CompTIA Network+, GIAC (e.g., GSEC, GCIH, GCIA, GMON), ISACA CISA or CRISC, PCI Professional (PCIP), or Cloudflare platform accreditations where applicable.
- Demonstrated ability to operate with a high degree of autonomy - owning infrastructure and security strategy, priorities, and execution while reporting directly to executive leadership.
- Experience in security- or compliance-constrained environments (e.g., PCI DSS or financial services regulation), including direct participation in compliance assessments and audit evidence collection, delivering under formal SDLC and change management.
- Demonstrated incident-response ownership across infrastructure and security domains: on-call participation, incident command or mitigation leadership, and postmortem-driven improvement.
- Proven ability to translate infrastructure, security, and reliability tradeoffs into clear recommendations for technical and executive stakeholders.
- Expertise in Cloud platforms: production engineering on Microsoft Azure, AWS, or DigitalOcean - compute, virtual networking, IAM, storage, and managed database services.
- Familiar with infrastructure automation: Terraform (or equivalent), GitOps workflows, configuration management, and CI/CD engineering (e.g., GitHub Actions, Azure DevOps) with security scanning and progressive delivery; Python, PowerShell, and/or Bash operational tooling with strong Git fluency.
- Expertise in containers, orchestration, and serverless: Docker and Kubernetes (e.g., AKS, EKS, DigitalOcean Kubernetes) or managed container services; serverless/edge compute (e.g., AWS Lambda, Cloudflare Workers).
- Understanding of operating systems and directory services: Windows Server and Linux administration, Active Directory/Microsoft Entra hybrid identity, and Microsoft 365 administration.
- Skilled in network infrastructure: enterprise firewalls, SD-WAN, switching, and wireless - design, administration, and troubleshooting, with strong routing/switching fundamentals (VLANs, routing protocols, QoS) and VPN.
- Knowledge in network and cloud security: segmentation design, firewall policy management, DNS, TLS certificate management, WAF/CDN (e.g., Cloudflare), encryption at rest and in transit, and cloud security posture management (CSPM).
- Experience with security monitoring, detection, and vulnerability management: enterprise SIEM/log analytics, EDR, and FIM platforms - detection content development, alert tuning, response integration - plus enterprise scanning, risk-based prioritization, and remediation workflow design.
- Knowledge with identity, endpoint, and end-user platforms: least-privilege RBAC, MFA-inclusive authentication, identity lifecycle and privileged access management (PAM), directory and identity platforms (e.g., Microsoft Entra ID, AWS IAM), endpoint security, MDM, password management platforms, and vault-based secrets management.
- Demonstrate ability in reliability engineering: SLO/error-budget practice, observability tooling, database backup/recovery, replication, and point-in-time restore (e.g., PostgreSQL, SQL Server, MySQL).
- Track record of technical leadership: mentoring, architecture or design review, or engineering standards ownership.
Take Your Career To The Next Level!- Experience in payments, fintech, banking, or another regulated financial domain; hands-on PCI DSS assessment participation across multiple annual cycles.
- SRE practice depth (SLO/error-budget programs, chaos or resilience testing); FinOps/cloud cost-management practices; multi-account/landing-zone architecture.
- Zero-trust or SASE architecture; detection engineering depth (e.g., MITRE ATT&CK); securing or supporting AI/ML workloads (OWASP LLM Top 10) aligned with VizyPay's enterprise AI roadmap.