Infrastructure Engineer

Assist Point Inc
Dallas, TX, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Proxmox Microsoft Windows Audit Trail Backup Devices Client Server Models Ubuntu (Operating System) CentOS Client Access Licensing CompTIA Security+ Data Integrity Data Center Infrastructure Management (CIM) Debian Linux
+49 more
Linux Desktop Virtualization Disaster Recovery Distributed Data Store Domain Name System (DNS) VMware ESX Servers HAProxy Web Servers Hypervisor Identity and Access Management Information Security Management Intrusion Detection and Prevention Virtual Private Networks (VPN) Kernel-Based Virtual Machine Network Security Linux Kernel Virtual Desktops Network Intrusion Detection Systems Quick EMUlator (QEMU) Role-Based Access Control Cloud Services Ansible Bacula Prometheus Zero Trust Network Access Virtual Local Area Networks Virtual Machines Virtualization Technology Software Vulnerability Management Wireless Access Point Zabbix Ceph (Software) Data Logging Google Cloud Load Balancing Saltstack Grafana Containerization Kubernetes Low Latency Iptables ZFS File System Firewall Services Module Veeam Terraform User Identification Docker Elk Stack Vulnerability Analysis

Job description

We are seeking a high-level Infrastructure Expert to design, deploy, and manage a secure, scalable cloud ecosystem. You will be responsible for building the backbone of our Virtual Desktop Infrastructure (VDI). Your primary mission is to ensure 99.99% uptime, automated data redundancy, and seamless client-server communication in a Linux-heavy environment., Virtualization Mastery: Design and manage Virtual Machine (VM) clusters using KVM, QEMU, Proxmox, or VMware ESXi. Virtual Desktop Deployment: Build and maintain secure, low-latency Linux/Windows Virtual Desktops for remote client access. Data Integrity & Recovery: Architect automated, off-site backup solutions and Disaster Recovery (DR) protocols using tools like Restic, Bacula, or Veeam. Network Security: Implement robust firewall rules (IPTables/NFTables), Load Balancers (HAProxy), and secure VPN tunnels for client-server isolation. Automation: Use Ansible, Terraform, or SaltStack to automate the deployment of new client environments., HIPAA Technical Safeguards: Implement and maintain the ā€œTechnical Safeguardsā€ required by HIPAA ($45 \text{ CFR } \S 164.312$), including unique user identification, emergency access procedures, and automatic log-offs. Data Encryption at Rest & Transit: Ensure all PHI (Protected Health Information) is encrypted using AES-256 at the storage level and TLS 1.3 during transmission across the client-server architecture. Audit Logging & Monitoring: Configure centralized, immutable logging (e.g., ELK Stack or Graylog) to track every access point, modification, or deletion of sensitive data for mandatory 6-year retention. Business Associate Agreement (BAA) Alignment: Architect systems that adhere to the specific security requirements outlined in our BAAs with Google Cloud and our Texas healthcare clients. Advanced Security Requirements Identity & Access Management (IAM): Implement Role-Based Access Control (RBAC) and Zero Trust Architecture to ensure the principle of ā€œLeast Privilege.ā€ Vulnerability Management: Perform regular automated vulnerability scans and coordinate with the team for rapid patching of the Linux kernel and web server binaries (CVE monitoring). Intrusion Detection: Setup and manage HIDS/NIDS (Host/Network Intrusion Detection Systems) such as Wazuh or OSSEC. Certifications (Preferred but not Mandatory) HCISPP (HealthCare Information Security and Privacy Practitioner), CompTIA Security+ or CISSP

Requirements

Do you have experience in Windows?, OS: Expert-level mastery of Windows / Ubuntu Server, CentOS/AlmaLinux, and Debian. Virtualization: Deep experience with Hypervisors and Containerization (Docker/Kubernetes is a plus). Storage: Knowledge of distributed storage solutions like Ceph or ZFS for data reliability. Networking: Strong understanding of DNS management, SSL/TLS automation, and VLAN/VXLAN for client isolation. Monitoring: Experience setting up Prometheus, Grafana, or Zabbix to predict hardware failures before they happen. The Ideal Candidate Profile Psychology: You don’t just ā€œfixā€ things; you build systems that don’t break. You understand that in the IT business, downtime is a loss of reputation. Communication: You can explain complex ā€œHard ITā€ architecture to ā€œSoft ITā€ teams and management. Experience: 5+ years in Data Center management, Cloud Service Provider (CSP) environments, or high-level Systems Administration.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo Ā· LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 Ā· LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard Ā· WWC 2025

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade Ā· LIVE

3:37 min

Why differing legacy workflows complicate monitoring tool migrations

Mathias Palmersheim Mathias Palmersheim Ā· Europe 2026 Virtual

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 Ā· Coffee With Developers

Videos

See all

Related articles

See all