skip navigation
skip mega-menu

Senior Infrastructure Engineer - DfE - SEO

Government Digital & Data -

Full-time (Permanent)
£41,458 London minimum - £45,492 plus additional allowance
Published on
13 June 2025
Deadline
25 June 2025

Location

London (SW1P 3BT), Bristol (BS2 0EL), Coventry (CV1 2WT), Darlington (DL1 5QE), Leeds (LS1 4AP), Manchester (M1 2WD), Newcastle (NE1 8QH), Nottingham (NG2 1AW), Sheffield (S1 2FJ)

Please note – Nottingham, Leeds, Bristol and Newcastle currently have site controls in place. Therefore, these location options are only available to existing DfE employees already assigned to these office locations.

About the job

Job summary

The Department for Education is seeking to recruit IT Infrastructure Engineers to work across multiple endeavours, predominantly in the Microsoft Azure public cloud. We continually seek new & innovative opportunities in our cloud estate for efficiencies, economies of scale and new value to users across established cloud computing platforms to make them better for users, increase value for money and reduce complexity.

Specialist Identity Infrastructure Engineers in the Department for Education design, build, operate and support the organisation’s centrally managed Identity Directory Services that underpin the Department’s Digital services. If you are successful, you will work within DfE’s Cyber and Information Security division as part of a team providing specialist support including the following.

  • Identity management and administration. Security, management, governance and automation of DfE’s centrally managed Identity Directory Services, Microsoft Active Directory and Azure Entra. Includes design, build, operate and maintain core Directory Services, ensuring that they remain available, secure, and that they continue to meet requirements.
  • Managed infrastructure and securing identity services. Build, operate and maintain cloud and on-premises infrastructure resources for business applications. Back-up and restore, security vulnerability management, capacity management, service optimisation, incident resolution, request fulfilment, service controls, and asset management.
  • Service improvement. Develop new, and enhance existing infrastructure services within the identity workspace, managing processes to simplify infrastructure, enhance security, improve reliability & performance, avoid costs, scale & expand, prevent legacy, meet new requirements, or address emerging problem statements.

Job description

As a Senior Infrastructure Engineer specialising in Identity and Access Management, you will work within a team of security specialists and engineers maintaining, building and operating Directory Services solutions as directed and according to policy. You will:

  • Provide management, administration, operation and maintenance of Active Directory, Azure Entra and Microsoft Certificate services.
  • Manage IDAM related Azure services, such as Enterprise Applications and Identity Protection, advising and troubleshooting services.
  • Manage and administer Service Desk queue specific to restricted identity and certificate requests.
  • Assist in the development of upgrade plans and paths, future design, working with colleagues across wider DfE family.
  • Contribute to business cases for new technology or refresh within Identity and Cryptography, including analysis of existing technologies, development of proposals for change and improvement.
  • Undertake management of activities for securing Directory Services, enhancements and system changes including assessment of risks.
  • Troubleshoot Directory Services risk assessments, implementing changes to address known risks.
  • Liaise with business colleagues on release planning and scheduling of Directory Services integrated solutions, including communication of progress.
  • Ensure that post release reviews are conducted.
  • Advocate user-centric, agile approaches which focus on rapid, effective delivery of high-quality digital services.
  • Work with and support third parties in providing infrastructure services.
  • Work with technical and security architects to translate architectural designs into operations.
  • Share knowledge of tools and techniques with the wider team and community, growing awareness, inclusivity and balance.
  • Take a proactive role in the identification, evaluation and management of appropriate changes to team managed services (including automation).

Security Vetting

If you are successful, you must be prepared to undergo the Security Check (SC) clearance process. Please see the guidance here for further information.

Person specification

Essential Criteria:

  • Experience of building, managing, configuring and maintaining Microsoft Identity and Access Management systems and services including Active Directory, Azure Entra and Microsoft Certificate services.
  • Experience of applying security management to identities, such as role-based access control, disaster recovery, Local Administrator Password Solution (LAPS), security log monitoring, patch management, policy-based security settings, authentication methods, external identities, privileged identity management, identity protection, identity score remediation.
  • Experience of building, configuring, operating and maintaining infrastructure resources in Microsoft Azure environments such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), commercial-off-the-shelf (COTS) software, tenants, management groups, subscriptions, identity & access, network topology and connectivity, certificate services, cryptographic key management, availability & performance monitoring, developer collaboration software, virtual desktop, virtual machines and update management.
  • Experience of using automation techniques to configure services, automate processes and extract information. This may include using software, tooling, scripting and other automation techniques such as Azure Automation, PowerShell, Azure Command-Line Interface (CLI), JavaScript Object Notation (JSON), Bicep, Terraform, Python and Ansible.
  • Experience of administering security controls, options and configuration settings to protect cloud computing services, and to mitigate against security threats and vulnerabilities.
  • Experience of proactive problem management and troubleshooting ie availability and performance monitoring, reviewing incidents to spot patterns and trends, and breaking down IT infrastructure problems into component parts to identify and diagnose and remediate root causes.

Desirable Criteria:

  • Microsoft Azure verified credentials, certification or qualifications.
  • Experience of building, managing, configuring and maintaining Public Key Infrastructure including offline root CA management, Issuing Server configurations and administration, distribution server management, certificate lifecycle management, certificate revocation list lifecycle management, Disaster Recovery.
  • Experience of defining integration builds to combine IT infrastructure components to create a consolidated solution, and co-ordinating & testing build activities across systems.
  • Experience of collaborating with, and conveying technical concepts to, both technical and non-technical stakeholders.
  • An understanding of the benefits of service levels and service frameworks and how to operate within them to deliver, operate and maintain IT infrastructure services.
  • Experience of working with and applying design standards, methods and tools; and developing systems designs for review to ensure the selection of appropriate technology, efficient use of resources and integration of multiple systems and technology.
  • Experience of reviewing requirements and specifications, defining test conditions and analysing and reporting test activities and results.

Desirable criteria will only be assessed at interview, in the event of a tie break situation, to make an informed decision.

More jobs at Government Digital & Data

Lead Business Analyst-Department for Transport
£51,997
Full-time (Permanent)
Technical Architect Vehicle Certification Agency-SEO
£57,400
Full-time (Permanent)
Software Engineer - ONS - HEO
£32,452
Full-time (Permanent)
IT Support Engineer - Met Office - EO
£26,954 - £29,531
Full-time (Permanent)
DDaT Senior BI Design & Integration Manager - MoD - SEO
£43,080
Full-time (Permanent)
Lead Applied AI Engineer (i.AI) - CO - G6
£67,126 - £103,924
Full-time (Permanent)
DDAT Lead Technical Architect - MoD - G7
£57,670 - This post is eligible for a Digital Skills Allowance of up to £15,300 per annum
Full-time (Permanent)
Interaction Design Industrial Placement 2025 - Met Office - AO
£25,606
Full-time (Permanent)
Lead DevOps Engineer - DWP - G6
£72,664 - £89,995
Full-time (Permanent)
Software Development Engineer In Test (Automation Test Engineer
Full-time (Permanent)
Software Developer - HM Courts and Tribunals Service - SEO
The national salary range is £41,463 - £45,276, London salary range is £47,657 - £52,040.
Full-time (Permanent)
Interaction Designer - Planning Inspectorate - SEO
£45,219 - £49,462
Full-time (Permanent)
Digital, Information & Technology (DIT) Senior Software Developer - MoD - SEO
The base salary for this grade is £44,590, Offers above this will be made up of DSA , Digital Skill allowance of up to £11,400
Full-time (Permanent)
Interaction Designer - Ofgem - HEO
London £36,824-£48,561 National £34,123-£45,831.
Full-time (Permanent)
Code First Girls Opportunities sponsored by the IPO (GFiE Scheme) - IPO - EO
£28,883
Full-time (Permanent)
Security Monitoring Associate - Planning Inspectorate - HEO
£36,396 - £39,424
Full-time (Permanent)
Senior Software Developer - DBT - G7
(including allowances) London £63,248 to £79,133, National £59,634 to £75,618.
Full-time (Permanent)
Security Architect Data Services and Analytics (DSA) - HO - SEO
£44,720 National, £48,720 London plus up to £12,680 allowance
Full-time (Permanent)
Lead Enterprise Architect - Competition & Markets Authority - G6
£73,730 - £79,813 a DDAT allowance of up to £8750 may be applicable
Full-time (Permanent)
Lead Test Engineer - Companies House - SEO
Base salary is £41,571 - £45,784 with an additional DDaT allowance of £4,350 - £11,000 available
Full-time (Permanent)
Lead Interaction Designer - GDS - G7
The base salary of this grade is £67,126 for other locations. Offers made above this will be made up with a specialist pay allowance.
Full-time (Permanent)
Lead Software Developer - Companies House - SEO
The basic salary is £41,571 - £45,784 with an additional, non-pensionable digital allowance of up to £11,000
Full-time (Permanent)
Senior Software Developer - MoJ - G7
£56,532 - £69,338 plus allowance
Full-time (Permanent)
Developer - HMRC - HEO
£36,320 - £39,234
Full-time (Permanent)
Technical Architect - Welsh Government - SEO
£45,974 - £54,431
Full-time (Permanent)
Lead Technical Architect Chief Technology Office (CTO) - HO - G7
£60,300 - £64,300 location dependant plus allowance up to £20,100
Full-time (Permanent)
Principal Salesforce Architect - Ofgem - G6
London £65,835-£86,547 National - £61,446-£80,425.
Full-time (Permanent)
Development Operations (DevOps) Engineer - MoD - SEO
£44,590, Offers above this will be made up of DSA , Digital Skill allowance of up to £11,400
Full-time (Permanent)
Infrastructure Engineering Specialist - GCHQ - EO
£44,044 plus additional allowances
Full-time (Permanent)
Lead Product Manager FTC 8 months - Ofqual - G7
£50,882 - £62,011
Full-time (Permanent)
Product Manager - Ofqual - SEO
£41,113 - £48,088
Full-time (Permanent)
Senior Data Engineers - FCDO - SEO
£44,500 - £49,500
Full-time (Permanent)
Enterprise Business Architect (Army) - MoD - SEO
£44,590 This post may be eligible for a Digital Skills Allowance of up to £11, 400 per annum
Full-time (Permanent)
Principal Technical Architect - MoD - G6
£70,540 This post is eligible for a Digital Skills Allowance of up to £18,000 per annum
Full-time (Permanent)
Test Manager - Welsh Revenue Authority - SEO
£45,974 - £54,431 plus additional allowance £3,150 - 6,143
Full-time (Permanent)
Lead Interaction Designer - DWP - G6
£72,664 - £77,740
Full-time (Permanent)
Software Developer - HSE - HEO
£36,235 - £39,611
Full-time (Permanent)
Lead DevOps Engineer - DWP - G6
£72,664 - £89,995
Full-time (Permanent)
Senior Infrastructure Engineer - DfE - SEO
£41,458 £45,492 (London minimum) This post is eligible for a Digital, Data and Technology (DDT) capability based pay (CBP) allowance.
Full-time (Permanent)
Technical Architect - HO - SEO
£44,720 - £52,130 You may be eligible for an additional allowance up to £12,680
Full-time (Permanent)
Cyber Security Risk Manager - HMRC - SEO
£44,110 - £47,664
Full-time (Permanent)
Army Network Architect - MoD - HEO
£36,530
Full-time (Permanent)
Senior DevOps Engineer - DWP - G7
£55,557 - £78,517
Full-time (Permanent)

Subscribe to our newsletter

Sign up here