Quick Overview
Job Description
Onsite Role
Must have active and current DV Clearance
Background
We require the implementation of a modern, resilient virtualisation platform to replace and consolidate existing physical and virtual server infrastructure. This will require a new two-site Microsoft Hyper-V cluster upon which to mitigate existing physical server estate. Furthermore, the provisioning of new supporting infrastructure for network monitoring applications, and the implementation of a Public Key Infrastructure (PKI) solution to enhance security across the network.
The work will be delivered as a fixed package of services with agreed deliverables and acceptance criteria.
Objectives
- Establish a resilient, highly available, two-site Hyper-V cluster using pre-purchased, newly supplied hardware.
- Migrate approximately 20 existing physical and 20 existing virtual VMware and Hyper-V hosted devices to the new platform.
- Upgrade and patch migrated systems where appropriate, compliant with the latest local governance standards.
- Provision virtual infrastructure to host the two monitoring applications.
- Design and implement a Microsoft-based Certificate Authority and PKI solution.
- Support penetration testing and remediation activities as required.
- Provide comprehensive technical documentation relating to this package for pre-approvals, testing and handover along as well as knowledge-transfer activities for existing ICT support staff.
Workstreams
Hyper-V Cluster Design and Implementation
Activities include:
- Review supplied server hardware specifications and design cluster architecture in accordance with Microsoft best practice.
- Adapt design, if required, subject to feedback from key stakeholders.
- Configure equipment, including but not limited to: operating systems, services, clustering, failover, networking, quorum, replication, resiliency and high availability.
- Validate cluster performance and failover operation.
- Undertake implementation testing.
Deliverables for this workstream:
- Detailed solution design, capable of supporting the Objectives and that has been approved by all stakeholders.
- Fully operational two-site Hyper-V cluster, matching the solution design.
- Configuration documentation.
- Test and validation documentation, completed with key stakeholders.
Evaluation and migration of existing physical and virtual estate
Activities include:
- Undertake discovery and assessment of existing physical servers and virtual machines, determining dependencies, performance metrics and necessary maintenance tasks, such as upgrades.
- Complete migration planning and scheduling, with appropriate documentation submitted for stakeholder review.
- With approval, and aligned to the plan and schedule, migrate physical and virtual estate, upgrading systems where required and applying security updates and patches. All new configuration to reflect Microsoft best practise and local governance requirements.
- Migration testing and service validation with stakeholder engagement.
- Provide any documentation and knowledge transfer that would assist with the maintenance and/or understanding of the production environment.
- Support penetration testing and remediation activities if requested.
Deliverables for this workstream:
- Detailed assessment report that includes key information about each server to be migrated.
- Migration strategy and migration schedule, agreed with key stakeholders and including legacy system decommissioning recommendations.
- Fully migrate server estate onto the platform completed in Workstream 1, with penetration testing/vulnerability assessment remediation activity also undertaken if applicable.
- Test and validation documentation, completed with key stakeholders.
- Any additional relevant information handed over to local ICT resources that supports ongoing maintenance and upkeep.
Monitoring Platform Infrastructure
Activities include:
- Provision 2x new virtual servers on the new Hyper-V platform; each capable of hosting the required network monitoring/vulnerability scanning applications.
- Install and configure operating systems, apply security hardening and patching to Microsoft best practise and local governance requirements.
- Configure storage, networking and access requirements to suit the applications.
- Validate platform readiness for application deployment alongside local ICT resources.
- Support penetration testing/vulnerability assessment and remediation activities if required.
- Update documentation and knowledge transfer that would assist with the maintenance and/or understanding of these environments.
Deliverables for this workstream:
- Produce 2x new virtual server infrastructure to agreed specifications, with penetration testing/vulnerability assessment remediation activity also undertaken if applicable.
- Test and validation documentation, completed with key stakeholders.
- Any additional relevant information handed over to local ICT resources that supports ongoing maintenance and upkeep.
Public Key Infrastructure (PKI) Design and Deployment
Activities include:
- Review and document existing authentication and certificate requirements across the network estate.
- Design PKI hierarchy and certificate architecture and plan for deployment and adoption for approval by key stakeholders.
- Provision new virtual server environments, if necessary, to a replica standard and requirements as in Workstream 3.
- Deploy and configure Microsoft certificate services, Certificate Authorities and templates on the necessary infrastructure, following the approved design.
- Complete integration with other tools and services; for example, Active Directory and network vendor equipment.
- Support penetration testing/vulnerability assessment and remediation activities if required.
- Configure certificate auto-enrolment where appropriate.
- Deploy certificates to Windows systems and supported network devices, following the approved plan and schedule.
- Implement certificate lifecycle management processes.
- Produce documentation to include all component architecture, configuration, management processes and the operational and recovery procedures.
- Provide appropriate knowledge transfer to local ICT resources in order that this facility can be competently maintained.
Deliverables for this workstream:
- PKI design documentation including a summary of the requirements assessment and schedule.
- Completed and operational Certificate Authority infrastructure, with penetration testing/vulnerability assessment remediation activity also undertaken if applicable.
- Deployment of certificates to all applicable devices; a secure estate.
- Validation by key stakeholders.
- Certificate deployment, security configuration, maintenance and procedural handover documentation.
- National Security vetting (DV)is required, and you will need to undertake additional Police Vetting (NPPV3).
- On-site attendance is mandatory for all practical activities.
- Available working hours are between Monday and Thursday, 0800-1600 and Friday 0800 - 1530. Flexible working and remote working arrangements may be accommodated subject to prior agreement.
- Delivery time shall be determined and agreed upon prior to any formal engagement.
description added
Similar jobs
- BO
Senior Enterprise Infrastructure Engineer
NewBoku
London🇬🇧5 hours agoSOC 2AzureCloudflare+8Technology - VI
Senior Infrastructure Engineer
NewVIQU IT Recruitment
London🇬🇧Hybrid1 hour agoTechnology - SA
Infrastructure Engineer
NewSalt
London🇬🇧On-site1 hour agoLESSTechnology - HA
NatSec Cloud Engineer
NewHackajob Ltd
London🇬🇧Hybrid4 hours agoTechnology - DC
Infrastructure Engineer
NewData Careers
Oxfordshire🇬🇧On-site4 hours agoTechnology - SJ
AWS Cloud Engineer - Selby Jennings
NewSelby Jennings
London🇬🇧Hybrid18 hours agoAWSKubernetesTerraformTechnology