About this role
At IBM Infrastructure & Technology, we design and operate the systems that keep the world running. From high-resiliency mainframes and hybrid cloud platforms to networking, automation, and site reliability. Our teams ensure the performance, security, and scalability that clients and industries depend on every day. Working in Infrastructure & Technology means tackling complex challenges with curiosity and collaboration. You’ll work with diverse technologies and colleagues worldwide to deliver resilient, future-ready solutions that power innovation. With continuous learning, career growth, and a supportive culture, IBM provides the opportunities to build expertise and shape the infrastructure that drives progress. The CISO Remediation Team is looking to add a cybersecurity Remediation Engineer as part of the overall Cyber Defense organization. In this role, you will contribute to and, over time, drive the technical resolution of security risk across the IBM enterprise, operating at the intersection of engineering, infrastructure operations and security architecture. You will help teams recover from incidents, remediate vulnerabilities, and implement durable, scalable security improvements. This role is focused on implementing and driving technical remediation, not primarily identifying issues. Successful candidates typically have hands-on experience administering, operating, securing, or engineering enterprise technology environments such as operating systems, networks, cloud platforms, identity systems, virtualization platforms, databases, or applications. Experience limited to monitoring, alert triage, incident coordination, compliance, or assessment activities without direct responsibility for implementing technical changes may not provide sufficient background for this role. Depending on the engagement and experience level, you may remediate issues directly, partner with engineering teams to drive fixes, or design repeatable remediation patterns. This role is not a primary SOC, detection, or application security pipeline ownership role, but partners closely with those teams to drive remediation outcomes. The ideal candidate enjoys solving complex technical problems, has experience operating and securing enterprise technology environments, and communicates effectively with both technical and non-technical stakeholders. This role spans multiple technical domains. Candidates are not expected to be experts in all areas; strong candidates demonstrate deep expertise in one or two domains and working knowledge of adjacent areas. Areas of specialization may include: Identity & Active Directory Security: Active Directory and Entra ID administration, Group Policy, privileged access management, authentication services, identity hardening, and recovery operations Scripting, Automation & Infrastructure as Code: Python, Ansible, Terraform, or similar tooling Cloud & Virtualized Environments: IBM Cloud, AWS, Azure, GCP; virtualization and container platforms Operating Systems & Networking: Windows or Linux; network segmentation, SDN, and isolation techniques Security Infrastructure & Controls: Endpoint protection platforms, firewall technologies, identity systems, vulnerability management platforms, privileged access management solutions, and security automation tooling Key Duties: Support containment, recovery, vulnerability remediation, and post-incident corrective actions by identifying root causes, implementing technical fixes, hardening configurations, deploying security controls, and validating risk reduction outcomes. Partner with product, engineering, and infrastructure teams to implement remediation plans and improve the security posture of their environments. Drive the implementation of secure configurations across infrastructure, operating systems, cloud platforms, identity systems, and applications. Create technical documentation outlining remediation guidance and security best practices. Develop or implement automation and tooling to accelerate remediation, configuration management, vulnerability reduction, and security operations at scale. 4-8 years of experience in infrastructure engineering, systems administration, cloud engineering, network engineering, platform engineering, SRE, DevOps, or security engineering roles with direct responsibility for operating and securing production technology environments. Experience troubleshooting, administering, and securing production technology environments, including hands-on remediation activities such as system hardening, patch management, access control remediation, network segmentation, configuration management, security control deployment, infrastructure upgrades, and cloud security improvements Ability to work independently or as part of a team while operating effectively in ambiguous, fast‑moving environments Strong problem‑solving skills with attention to detail and a proactive mindset Strong interpersonal and communication skills with the ability to work effectively across engineering, security, and business teams; and explain technical remediation steps to non-technical stakeholders Ability to collaborate effectively and, with experience, influence remediation outcomes across federated teams Ability to leverage automation and AI-assisted tooling to improve remediation effectiveness and operational efficiency Knowledge of vulnerability management and remediation techniques across infrastructure, cloud, identity and/or application environments Prior experience as a systems administrator, network engineer, cloud engineer, platform engineer, site reliability engineer (SRE), infrastructure engineer, or similar hands-on operational role; experience supporting incident recovery or post-incident remediation is highly desirable. Experience with cloud platforms, CI/CD pipelines, containerization, and Kubernetes. Experience using automation and AI to reduce mean time to remediation (MTTR). Familiarity with Agile development environments. Foundational understanding of cybersecurity frameworks and regulations and how they inform risk‑based remediation decisions. (e.g., NIST CSF, NIST 800-series, ISO 27001, PCI.) United Kingdom Infrastructure & Technology Hybrid Professional Hursley, GB (8660) IBM United Kingdom Limited