JobMatch
← Back to jobs

Head of Systems

Moneybase

RemoteBirkirkara, MaltadirectorFull-time
Posted
today
Source
LinkedIn (remote, Europe)

Skills

Machine LearningLeadershipTerraformSecurityAnsibleRoadmappingAzureLinuxNext.jsAI

Description

The Head of Systems owns CC Moneybase's infrastructure end to end: cloud, on-premises, network and security. This is a hands-on technical leadership role. You set the direction, and you are also the person who can log into the firewall, read the Terraform and fix the problem at 2am You will keep our platforms secure, available and fast, modernise how we run them, and build a small team that owns its systems rather than waiting for instructions. Key responsibilities Leadership and ownership - Set and deliver the infrastructure roadmap, agreed with the CEO, covering modernisation, automation, resilience and cost. - Own the infrastructure budget, licences and vendor relationships, and keep spend lean and justified. - Lead, coach and develop the IT Systems Manager and, through them, the two systems engineers. Identify skills gaps and close them. - Build a culture of ownership: every system has a named owner, documentation and a runbook. - Act as the senior technical escalation point for complex incidents, and lead post-incident reviews that fix root causes. Cloud: Microsoft Azure - Run and optimise our Azure estate: virtual machines, networking, storage, identity (Entra ID) and governance. - Drive cost optimisation through right-sizing, reservations and removal of waste, reported monthly. On-premises and virtualisation - Oversee VMware vSphere, ESXi and vCenter, including VM management, performance monitoring, patching and upgrades. - Own physical servers, virtualisation hosts and storage platforms through their full lifecycle. - Manage hybrid connectivity and operations between on-premises and Azure so they work as one estate. Linux and server administration - Maintain and secure Linux servers across on-premises and cloud, including patching, hardening, troubleshooting and performance tuning. Network, edge and security - Manage Fortinet FortiGate firewalls: security policies, VPNs, routing, high availability and firmware upgrades. - Administer Cloudflare: DNS, WAF, DDoS protection, SSL/TLS and related security configuration. - Configure and troubleshoot load balancing across Azure Load Balancer, Application Gateway, FortiADC, NGINX and HAProxy. Corporate IT and end-user services - Own the corporate IT environment, setting the standards and direction for secure, reliable and well-managed IT services. - Oversee end-user computing, including devices, operating systems, software deployment, patching and endpoint configuration. - Establish and oversee identity and access management, including user provisioning, access controls, MFA, and joiner, mover and leaver processes. - Define endpoint management and configuration standards using Microsoft Intune, Microsoft 365 and Microsoft Entra ID. - Make sure corporate IT security controls, including endpoint protection, encryption, device compliance and vulnerability management, align with Information Security policies. - Oversee the IT Systems Manager's delivery of IT support and services, including service levels, escalation management and continuous improvement. - Oversee IT assets, software licensing, suppliers and lifecycle planning to control cost and use resources well. - Drive standardisation and automation of IT processes to improve efficiency, consistency and scalability. - Make sure technical documentation, operational procedures, access controls and business continuity arrangements are kept up to date. - Set performance expectations, review operational risks and service reporting, and give direction on corporate IT improvements and technology lifecycle decisions. Resilience and disaster recovery - Own infrastructure availability, backup and disaster recovery, and test recovery on a set schedule. - Deliver the infrastructure security controls and operational resilience evidence the business needs, working with Risk, Compliance and Information Security. Automation and Infrastructure as Code - Move provisioning and configuration to code using Terraform, Ansible or equivalent, across cloud and on-premises. - Standardise and automate routine operational tasks to cut manual effort and configuration drift. AI-assisted security and monitoring - Evaluate and implement AI-driven tools that continuously check configurations across Azure, VMware, Linux, Windows and network, and flag misconfigurations and vulnerabilities. - Use the AI and machine learning capabilities in our SIEM, EDR and monitoring platforms to improve anomaly detection and incident response. What you bring Essential - 8+ years in infrastructure or systems engineering, with at least 3 years leading a team. - Deep, hands-on Azure experience: compute, networking, storage, Entra ID, governance and cost management. - Strong VMware vSphere, ESXi and vCenter experience in production. - Confident Linux administration, plus working knowledge of Windows Server. - Hands-on with Fortinet FortiGate or an equivalent next-generation firewall, and with load balancers in high-availability setups. - Practical Infrastructure as Code experience with Terraform, Ansible or similar, used in production, not just tested. - Experience running Cloudflare or a comparable edge, DNS and WAF platform. - A track record of designing and testing backup and disaster recovery. - Experience running corporate IT and end-user services, including Microsoft Intune, Microsoft 365, Entra ID identity and access management, and joiner, mover and leaver processes. - Able to explain technical risk and trade-offs clearly to a non-technical CEO. Desirable - Experience in financial services, payments or another regulated environment. - Hands-on with SIEM and EDR platforms, including their AI and anomaly detection features. - Certifications such as Azure Administrator or Solutions Architect, VCP or Fortinet NSE. Experience counts more than certificates.

JobMatch aggregates public listings. Always apply through the original posting.