About the Role
We're looking for an Infrastructure Engineer to help us manage, secure, and modernise our on-premise and cloud infrastructure. You'll work across a hybrid estate — supporting existing on-premise systems while playing an active role in our ongoing migration to modern cloud and hybrid platforms, and in the day-to-day administration of Microsoft Entra ID. This is a hands-on engineering role with genuine scope to shape how infrastructure is built and secured across the group.
What you’ll be doing
On-Premise Infrastructure
- Administer and maintain our server estate (physical and virtualised), including patching, capacity management, and lifecycle planning
- Support and help decommission legacy/EOL systems (servers, SQL Server instances, and applications) as part of the group's estate rationalisation programme
- Manage Active Directory across multiple domains, supporting ongoing consolidation and identity modernisation work
- Administer core infrastructure services: DNS, DHCP, file/print, backup and disaster recovery, VOIP Telephony
- Support the group's migration from VMware vSphere7 to vSphere8/9 or to Hyper-V/Azure, including build, testing, and cutover activity
Entra ID & Cloud Identity Administration
- Own day-to-day administration of Microsoft Entra ID: user and group lifecycle, licensing, app registrations, and enterprise applications
- Support Entra ID tenant consolidation across all group brands, including domain and UPN/primary SMTP alignment
- Configure and maintain Conditional Access policies, MFA enforcement, and password policy in line with NCSC guidance
- Administer Privileged Identity Management (PIM) and just-in-time (JIT) access for privileged roles
- Support hybrid identity sync (AD to Entra ID) and troubleshoot synchronisation issues
Cloud & Security
- Support Microsoft 365 administration alongside Entra ID (Exchange Online, SharePoint, Teams)
- Assist with Azure infrastructure (App Services, Functions, storage, networking) supporting group applications and data platforms
- Contribute to the group's Cyber Essentials Plus programme, including remediation of findings and ongoing control maintenance
- Operate and tune endpoint and network security tooling (e.g. Microsoft Defender, Sophos, ThreatLocker, Ivanti Patch Management, SIEM alerting)
- Support security patching, vulnerability remediation, and hardening across both on-premise and cloud infrastructure
- Participate in incident response and root-cause investigation for infrastructure and security incidents
General
- Produce and maintain clear documentation for infrastructure, configurations, and standard operating procedures
- Work within change management (CAB) processes for planned infrastructure changes
- Provide 2nd/3rd-line escalation support and mentor junior team members where required
- Collaborate with the wider IT team on projects spanning infrastructure, security, and identity
You will also demonstrate:
- Strong problem-solving skills, with a structured and analytical approach to diagnosing and resolving issues.
- A proactive mindset, with the confidence to identify improvements, challenge existing ways of working and drive solutions through to completion.
- A strong security mindset and understanding of the importance of maintaining secure, resilient and well-managed infrastructure.
- Excellent communication skills, with the ability to explain technical issues and solutions clearly to both technical and non-technical stakeholders.
- The ability to work effectively in a changing environment, managing multiple priorities while maintaining a high standard of delivery.
- A collaborative approach, with a willingness to share knowledge, support colleagues and contribute to the wider IT team and Group objectives.
What we’re looking for
- Educated to Degree Level with a Minimum 5 years of experience working in a similar capacity as an Infrastructure Engineer or have a minimum of 10 years’ experience working in an IT Infrastructure role
- Proven experience administering Windows Server environments and Active Directory at scale
- Hands-on experience administering Microsoft Entra ID (Azure AD) — users, groups, Conditional Access, and app registrations
- Hands-on experience with virtualisation platforms (VMware and/or Hyper-V)
- Practical understanding of core networking (DNS, DHCP, VLANs, firewalls)
- Some exposure to Azure or another public cloud platform (IaaS/PaaS fundamentals)
- Working knowledge of endpoint security, patch management, and vulnerability remediation
- Strong troubleshooting skills and a methodical approach to problem-solving
- Clear communicator, comfortable working with both technical peers and non-technical stakeholders
What We Offer
Opportunities for professional development and career progression
A supportive, values-driven and inclusive working environment
Competitive salary and benefits package
32 days annual leave, increasing with service
Pension
Life Assurance
Healthcare Cashback Plan
Enhanced Family Friendly policies
Additional employee benefits including access to our Cycle to Work Scheme, Employee Discount Scheme, Employee Recognition awards, Employee Assistance Programme.
A Bit About Us
For more than three decades, the Keystone Group has grown to become one of the UK and Ireland’s largest family-owned construction product manufacturers. Driven by a relentless focus on innovation and customer excellence, the Group employs over 2,000 employees across 28 sites, supplying cutting-edge building solutions to growing markets in the UK & Ireland, Europe, Australia and North America. Its portfolio includes market-leading brands in the steel, light & environmental and timber sectors.