
IT Infrastructure Engineer
Location: Hybrid
Salary: 117K - 130K
POSITION SUMMARY
The IT Infrastructure Engineer designs, operates, secures, and continuously improves the company’s hybrid
information technology infrastructure, including enterprise networking, cloud connectivity, servers, virtualization,
storage, backup, identity integrations, and core infrastructure services. This role is responsible for the reliability,
recoverability, performance, lifecycle, and secure configuration of both on-premises and cloud-based systems.
This is a hybrid position based at the Watsonville, CA Headquarters, with weekly onsite presence required to
support local network, server-room, connectivity, and hardware lifecycle activities. The engineer also supports
infrastructure serving remote employees, cloud workloads, and company locations.
The role collaborates closely with IT Operations, Security, application owners, and external service providers. The
engineer uses automation, monitoring, documented standards, and disciplined change practices to reduce
operational risk and improve service reliability. The role owns secure infrastructure configuration and lifecycle
controls while partnering with the security function on architecture, vulnerability remediation, monitoring,
incident response, and risk management.
ESSENTIAL FUNCTIONS
Reasonable Accommodations Statement
To accomplish this job successfully, an individual must be able to perform, with or without reasonable
accommodation, each essential function satisfactorily. Reasonable accommodations may be made to help enable
qualified individuals with disabilities to perform the essential functions.
Essential Function Statements
Design, administer, and support hybrid infrastructure including servers, virtualization, storage, backup,
cloud resources, network services, and private connectivity.
Administer enterprise wired and wireless networks, switching, routing, firewalls, VPN, and zero-trust
network access technologies.
Plan and execute operating system, hypervisor, firmware, network, and infrastructure software
maintenance using documented testing, rollback, approval, and communication procedures.
Develop and maintain infrastructure automation using scripting, REST APIs, infrastructure-as-code, and
configuration-management practices.
Store infrastructure configurations and automation in version control and participate in peer review,
testing, and controlled deployment processes.
Implement and maintain monitoring, centralized logging, alerting, health dashboards, and capacity
reporting for critical infrastructure and services.
Administer backup and recovery platforms and regularly validate recoverability through documented
restoration and disaster-recovery testing.
Maintain infrastructure diagrams, dependency maps, runbooks, standards, reference configurations,
lifecycle plans, and support documentation.
Implement secure configurations, least-privilege administration, segmentation, encryption, logging, and
vulnerability remediation in partnership with the security team.
Support infrastructure-related security incidents by assisting with investigation, containment, recovery,
evidence preservation, and corrective actions.
Provide Tier 2 and Tier 3 support for infrastructure incidents and requests, perform root-cause analysis,
and remediate recurring issues.
Monitor infrastructure capacity, utilization, support status, warranties, certificates, licensing, technical
debt, and end-of-life replacement requirements.
Apply cloud governance standards for resource organization, naming, tagging, access, logging,
networking, lifecycle management, and cost accountability.
Evaluate proposed infrastructure technologies and solutions for reliability, supportability, security,
integration, scalability, and total lifecycle cost.
Coordinate technical work performed by infrastructure vendors, carriers, managed service providers, and
professional services partners.
Create operational documentation and provide cross-training to reduce single points of failure within the
IT Operations team.
Participate in scheduled maintenance windows and infrastructure incident escalation as required.
Recommend and implement improvements that increase reliability, recoverability, security, efficiency,
and operational maturity.
Stay current with evolving infrastructure technologies and industry best practices.
Other duties as assigned.
Competency Statements
Accountable – Takes ownership of responsibilities, decisions, and outcomes and follows corrective actions
through completion.
Independent – Works reliably with limited supervision while escalating risks, dependencies, and decisions
appropriately.
Collaborative – Works effectively with IT peers, security teams, business stakeholders, vendors, and
service providers.
Detail Oriented – Demonstrates precision in documentation, configuration, testing, change execution,
and validation.
Technical – Applies strong troubleshooting, diagnostic, systems-thinking, and root-cause analysis skills.
Curious – Continuously develops technical knowledge and identifies practical ways to improve
infrastructure operations.
Customer Oriented – Balances user and business needs with reliability, security, supportability, and
company standards.
Resilient and Solutions-Oriented – Responds constructively to incidents, ambiguity, changing priorities,
and technical setbacks.
Risk-Aware – Considers security, availability, recoverability, compliance, and business impact when
making technical decisions.
Operationally Disciplined – Uses documentation, testing, peer review, change controls, and validation to
reduce avoidable production risk.
SKILLS & ABILITIES
Windows and Linux server administration in physical, virtualized, and cloud-hosted environments.
Enterprise virtualization platforms such as VMware, Hyper-V, or equivalent technologies.
Network configuration and troubleshooting including TCP/IP, routing, switching, VLANs, DNS, DHCP,
firewalls, wireless, and private connectivity.
Backup and recovery platforms such as Cohesity or Veeam, including restoration and recovery testing.
Microsoft Azure and Entra ID administration in a hybrid identity and infrastructure environment.
Experience with AWS or another public-cloud platform is preferred.
Infrastructure automation using PowerShell, Python, REST APIs, or equivalent technologies.
Familiarity with infrastructure-as-code tools such as Terraform, Bicep, Ansible, or equivalent.
Experience with Git-based version control, peer review, and controlled deployment workflows.
Infrastructure monitoring, centralized logging, alerting, dashboards, and performance/capacity analysis.
Identity and access fundamentals including role-based access control, multifactor authentication, SAML,
OIDC, and SCIM.
Experience with VPN and zero-trust network access platforms, preferably Cloudflare Zero Trust or
7/30/26
equivalent.
Understanding of enterprise storage, file services, object storage, data lifecycle, permissions,
synchronization, retention, and migration concepts.
Knowledge of infrastructure security baselines, least privilege, vulnerability remediation, network
segmentation, encryption, and secure administrative practices.
Experience with change management, root-cause analysis, technical documentation, operational
runbooks, and lifecycle planning.
Strong written and verbal communication skills, including the ability to explain technical risks and
recommendations to nontechnical stakeholders.
Strong organizational skills and the ability to prioritize operational work, incidents, maintenance, and
project deliverables.
Experience supporting multisite, manufacturing, warehouse, or regulated environments is preferred.
Other Requirements
Education: Bachelor’s degree in Computer Science, Information Systems, or a related field, or an
equivalent combination of professional experience, training, and relevant certifications.
Experience: Minimum of 5 years of progressive experience in IT infrastructure engineering, systems
administration, network engineering, or a comparable role.
Ability to work onsite at Watsonville HQ on a weekly basis and participate in scheduled after-hours
maintenance or incident escalation when required.
Apply for this job
*
indicates a required field
