Principal Infrastructure Automation & AI Ops Engineer

JobgetherBrussels (Firmensitz, recherchiert)Job.bopublié le 09/10/2026
Indispensable :PythonGitAWSAzureCloudDevOpsCI/CDAISecurityLeadRemote

Accountabilities: Infrastructure Automation & Endpoint Engineering: Define the architecture and standards for Windows endpoint management using Microsoft Intune. Automate device provisioning, configuration, patching, compliance, software inventory, and retirement. Develop Windows Autopilot workflows that enforce standard-user deployments, reduce local administrator exposure, and enable self-healing remediation for recurring endpoint issues.

Identity, Zero Trust & Access Management: Lead Entra ID identity architecture and automate joiner, mover, and leaver workflows across identity, Microsoft 365, and IT service management platforms. Advance Conditional Access policies from audit to full enforcement, strengthen Zero Trust controls, and develop AI-assisted access analysis to identify excessive privileges, outdated permissions, and segregation-of-duties risks. Support privileged access automation, including credential rotation and session monitoring.

Microsoft 365 Platform Engineering: Architect and automate administration across Entra ID, Intune, Exchange Online, SharePoint Online, Teams, and Conditional Access using Microsoft Graph APIs and PowerShell. Establish configuration baselines, detect configuration drift, and strengthen SharePoint governance, versioning, and compliance practices.

Infrastructure-as-Code & Automation Engineering: Establish enterprise-wide automation standards using Terraform, Bicep, and reusable scripting frameworks. Develop CI/CD pipelines, API integrations, and modular automation solutions connecting endpoint, identity, cloud, networking, and IT service management platforms. Transform high-volume manual processes into automated service catalog workflows.

AI Ops & Intelligent Automation: Deliver production-ready AI-assisted operations across endpoints, identity, networking, cloud infrastructure, and service desk functions. Implement anomaly detection, event correlation, intelligent ticket classification and routing, and predictive monitoring for certificates, patch compliance, and firewall licensing. Design automated remediation workflows with appropriate authentication, authorization, audit logging, approval controls, and rollback mechanisms, retaining human approval for high-risk changes.

AI-Driven Data Security Integration: Collaborate on early-stage enterprise data security initiatives, integrating AI-assisted detection and remediation capabilities with endpoint, identity, and IT service management automation. Help establish scalable architectural patterns for intelligent data protection workflows.

Observability & Security Guardrails: Build a unified telemetry and observability architecture spanning endpoint, identity, network, cloud, Microsoft 365, and IT service management environments. Implement secure secrets management using solutions such as Azure Key Vault, AWS Secrets Manager, or HashiCorp Vault. Eliminate hardcoded credentials, minimize standing privileged access, enforce least-privilege permissions, and maintain complete audit trails for automated actions.

Technical Leadership & Architecture Governance: Act as a technical authority across Infrastructure and Operations, defining architecture standards and leading design reviews. Mentor engineers, develop reusable engineering practices, and collaborate with cloud, network, security, identity, and service desk teams to drive adoption without relying on direct reporting authority.

Operational Excellence & Measurable Outcomes: Focus on eliminating repetitive work, preventing incidents, reducing operational risk, and improving engineering capacity. Within the first 6–12 months, target automation of 60–80% or more of repeatable endpoint tasks, improved or sustained patch and compliance rates, automated identity lifecycle workflows, full Conditional Access enforcement, reusable infrastructure modules adopted across teams, proactive infrastructure monitoring, and measurable reductions in incident detection and resolution times.

Requirements:

Professional Experience: At least 10 years of experience in infrastructure, systems, or platform engineering, with demonstrated expertise in designing and implementing automation solutions in large enterprise environments. Candidates should have a strong engineering mindset and experience building scalable architectures rather than simply executing predefined administrative procedures.

Endpoint Management: Expert-level knowledge of Microsoft Intune and Windows endpoint engineering, including Windows Autopilot, device lifecycle automation, compliance enforcement, patch management, and local administrator controls or Local Administrator Password Solution (LAPS).

Identity & Access Management: Strong hands-on experience with Microsoft Entra ID, single sign-on (SSO), multifactor authentication (MFA), Conditional Access, Zero Trust, identity lifecycle management, and SCIM- or API-based provisioning.

Programming & Automation: Advanced proficiency in PowerShell, Python, and/or Bash, with strong experience integrating REST APIs and webhooks. Solid knowledge of Git, infrastructure-as-code tools such as Terraform or Bicep, configuration management tools such as Ansible, and CI/CD pipeline development.

Microsoft 365 Administration: Deep expertise in Microsoft 365 platform engineering, including Microsoft Graph API, Exchange Online, SharePoint Online, Teams, Intune, and enterprise configuration governance.

Security & Endpoint Protection: Experience with endpoint detection and response (EDR) platforms, preferably CrowdStrike Falcon, alongside vulnerability management, software inventory reconciliation, patch compliance reporting, and remediation automation.

Network Authentication & Certificates: Understanding of 802.1X authentication, enterprise public key infrastructure (PKI), certificate authorities, certificate deployment through mobile device management (MDM), and network access control (NAC) troubleshooting.

AI Ops & Intelligent Workflows: Demonstrated experience implementing AI-assisted or event-driven automation in production environments, including anomaly detection, event correlation, automated remediation, and intelligent operational workflows. Ability to incorporate security guardrails, approval mechanisms, auditability, and rollback procedures into automated processes.

Cloud & IT Service Management: Experience with AWS platform engineering and account hygiene is an advantage. Familiarity with Freshservice or comparable IT service management platforms, such as ServiceNow or Jira Service Management, including administration, workflow automation, and API integrations, is preferred.

Privileged Access, Backup & Network Automation: Experience with CyberArk or equivalent privileged access management (PAM) solutions, Commvault or comparable backup platforms, Python- or Ansible-based network automation, and observability or telemetry pipelines is beneficial.

Emerging Technologies & Certifications: Familiarity with large language model (LLM) or AI agent frameworks, enterprise AI governance, and AI-driven security tooling is desirable. Experience with data loss prevention (DLP) or enterprise data security platforms is a plus. Relevant certifications, such as Microsoft 365 Certified: Enterprise Administrator Expert, HashiCorp Terraform Associate, or professional-level AWS or Azure certifications, are advantageous.

Leadership & Collaboration: Strong architectural judgment, problem-solving skills, and the ability to communicate complex technical concepts clearly. Comfortable leading design discussions, mentoring engineers, influencing cross-functional teams, and balancing innovation with security, reliability, and operational accountability.

Engineering Mindset: Able to design a solution, implement the automation, secure it, measure its effectiveness, and roll it back safely when needed. Success is measured by business and operational outcomes rather than ticket volume.

Candidates are encouraged to apply even if they do not meet every listed qualification. Relevant transferable experience, a willingness to learn, and a strong alignment with the role's core responsibilities are equally valuable. We are committed to an inclusive and diverse workplace and welcome applicants from a broad range of professional backgrounds. Applicants must be authorized to work in the location of employment.

Benefits:

Flexible Work Environment: Home-office-based position in Bengaluru, India, offering a remote working arrangement.

Full-Time Opportunity: A permanent-style, full-time role with the opportunity to shape enterprise infrastructure strategy and engineering practices.

Technical Ownership: Significant architectural responsibility and the opportunity to establish automation standards across multiple infrastructure and operations domains.

AI & Innovation Exposure: Hands-on involvement in production AI Ops, intelligent remediation, enterprise automation, and emerging AI-driven security capabilities.

Professional Growth: Opportunities to deepen expertise in cloud engineering, infrastructure-as-code, identity security, observability, and enterprise AI governance.

Cross-Functional Collaboration: Work closely with experienced professionals across infrastructure, cloud, network, security, identity, and IT service management teams.

Meaningful Impact: Help reduce operational risk, eliminate repetitive administrative tasks, strengthen security controls, and improve enterprise-wide service reliability.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1