This posting reached its closing date on 2026-10-08 — the employer may no longer accept applications.
Serco Plc

Cloud Platform Engineer (IaC, Network & Security Operations)

Serco Plc Prague, Prague, Czechia

Facilities Services · 1,001-5,000 employees

20 h ago
Senior (5-10 yrs) Full-time Czechia
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The role involves building and operating a core Azure platform using infrastructure-as-code and managing cloud and hybrid network services. Additionally, the engineer will lead security operations, including vulnerability management, security monitoring, and incident response for platform services.

What they look for

Azure Infrastructure-as-code Terraform Bicep Kubernetes AKS CI/CD GitOps Python PowerShell Bash Networking Cybersecurity operations Vulnerability management SIEM Incident response

Requirements

Candidates must have strong hands-on experience with Azure, infrastructure-as-code tools like Terraform or Bicep, and production Kubernetes operations. Proficiency in CI/CD, scripting, and cybersecurity operations is essential for this technical role.

Full description

Role purpose

Build and operate the core Azure platform as infrastructure-as-code, providing the reliable, automated foundation that application and AI teams deploy onto. A hands-on engineering role focused on cloud and platform engineering, automation, cloud and hybrid networking, and operational security.

Key Responsibilities

• Implement and maintain Azure infrastructure as code across environments.

• Build and operate AKS clusters, networking, and shared platform services.

• Provide operational support and troubleshooting for cloud and hybrid network services, including Azure VNets, routing, DNS, VPN/ExpressRoute connectivity, Private Link, network security controls and associated connectivity issues, coordinating with external network providers where required.

• Develop and maintain CI/CD pipelines and GitOps deployment workflows.

• Implement observability, alerting and operational automation.

• Support cost optimisation through autoscaling, right-sizing and scale-to-zero patterns.

• Take an AI-first approach to the work, using agentic AI tooling as the default way of building and delivering.

• Work in an iterative, board-tracked flow (Azure DevOps Boards or GitHub Projects), with peer code review as standard practice.

• Keep clear architecture and technical documentation current as part of the definition of done.

Security Operations responsibilities

In addition to the core platform engineering responsibilities, this position provides the dedicated technical Security Operations capability for Platform Services.

  • Own and support the operational vulnerability management process, including identification, technical assessment, prioritisation, reporting and remediation follow-up.
  • Operate and maintain security monitoring capabilities and investigate security alerts and incidents.
  • Support incident response activities, including containment, eradication, recovery and lessons learned.
  • Perform technical security assessments of systems, infrastructure and cloud environments.
  • Implement and maintain technical security controls aligned with corporate security standards.
  • Review infrastructure and platform changes to ensure technical security requirements are appropriately implemented.
  • Coordinate technical remediation activities with IT teams and third-party suppliers.
  • Support internal and external audits by providing technical evidence and remediation input.
  • Perform security health checks and identify control weaknesses, technical debt and opportunities for operational improvement.
  • Monitor emerging threats and vulnerabilities and recommend appropriate technical actions.
  • Maintain operational security documentation, procedures and technical standards.
  • Work closely with the GRC function while maintaining a clear separation of duties: this role is responsible for technical implementation and day-to-day security operations; GRC retains governance, risk acceptance, policy ownership, compliance monitoring and independent assurance.

Must-have experience

• Strong hands-on Azure cloud and platform engineering experience.

• Infrastructure-as-code proficiency (Terraform or Bicep).

• Production Kubernetes / AKS operations experience.

• CI/CD and GitOps experience (Azure DevOps or GitHub Actions).

• Scripting and automation skills (for example Python, PowerShell, Bash).

• Strong understanding of enterprise and Azure networking, including TCP/IP, DNS, routing, VPN, firewalls, VNets, peering and hybrid connectivity, with hands-on troubleshooting experience.

• Experience in cybersecurity operations, security engineering, or equivalent hands-on technical security responsibilities.

• Strong understanding of vulnerability management and technical security assessment practices.

• Experience with security monitoring / SIEM and incident response activities.

• Understanding of network security, system hardening and secure configuration practices.

• Ability to analyse technical security risks and communicate findings clearly to technical and non-technical stakeholders.

Nice to Have

• Experience operating platforms that host AI or data workloads.

• Advanced Azure networking exposure, including ExpressRoute, Private Link, network security controls and complex hybrid connectivity.

• Cost-control and FinOps tooling exposure.

• Experience supporting audits, compliance activities and remediation programmes.

• Experience with Microsoft security technologies, endpoint protection and identity security

Key Security Operations deliverables

• Reduction of technical security debt and timely remediation of identified vulnerabilities.

• Timely investigation and resolution of security incidents and alerts within the scope of Platform Services.

• Continuous improvement of operational security controls and monitoring capabilities.

• Effective technical remediation tracking and reporting.

• Technical support for audits, compliance initiatives and security projects