Infrastructure and Cloud Engineer (L3)

Company: White Cube
Apply for the Infrastructure and Cloud Engineer (L3)
Location: London
Job Description:

Job title: Infrastructure and Cloud Engineer (L3)

Reporting to: Senior IT Service Delivery Manager

Working hours: 10am–6pm, Monday–Friday (hybrid – 4 days in the office)

Location: White Cube Bermondsey (with other locations as required)

About White Cube

White Cube was set up by Jay Jopling in 1993 as a project room for contemporary art. The gallery has since grown into one of the most influential commercial galleries in the world, representing internationally renowned artists such as Georg Baselitz, Tracey Emin, Antony Gormley, Mona Hatoum, Anselm Kiefer, Liu Wei, Park Seo Bo, Doris Salcedo and Jeff Wall.

White Cube’s exhibition programme extends across locations in London, Hong Kong, Paris, New York, Seoul and online.

The Role

We are seeking an experienced and proactive Senior Infrastructure and Cloud Platform Engineer to act as the technical lead for White Cube’s cloud and infrastructure estate. This is a senior third‑line (L3) role, working alongside our existing L3 engineer to remove single points of failure, mature our cloud platform, and lead the migration of remaining on‑premises workloads into Microsoft Azure and Microsoft 365.

The role is pivotal to White Cube’s technology strategy. The successful candidate will own the design, security, resilience and day‑two operations of our Microsoft‑first cloud stack — including Microsoft 365, Entra ID, Intune, Azure Virtual Desktop, Microsoft Sentinel and our wider Azure footprint — while also providing senior technical input across our AWS workloads, network, identity and endpoint platforms. The role will mentor the Service Delivery team, shift resolution left through knowledge transfer and SysAid, and help retire legacy on‑premise systems on plan.

Key Responsibilities

  • Act as a technical authority for White Cube’s Microsoft cloud platform — Microsoft 365, Entra ID, Intune, Autopilot, Autopatch, Azure Virtual Desktop, Microsoft Sentinel SIEM and the wider Azure estate — ensuring resilience, security and availability.
  • Lead the migration of remaining on‑premise workloads to cloud, including VMware vCentre / Horizon to Azure Virtual Desktop, on‑premise Active Directory and domain controllers to Entra ID, Cisco ASA to a Zero Trust Network Access model, Print Servers to Universal Print, and the decommissioning of legacy file and document platforms.
  • Own day‑two operations and engineering for our AWS workloads, ensuring our cloud‑hosted applications remain secure, well‑governed and cost‑optimised.
  • Manage and harden identity, endpoint and security platforms — Entra ID, Intune (Windows), JAMF (macOS), SentinelOne EDR, DNSFilter and Bitwarden — with a strong focus on conditional access, Zero Trust and audit‑readiness.
  • Provide senior third‑line escalation support, partner with the existing L3 engineer to eliminate single points of failure, and act as a named owner / admin across critical services.
  • Design and implement automation and infrastructure‑as‑code (PowerShell, Bicep / ARM, Terraform or similar) for provisioning, configuration and patching across cloud and endpoint estates.
  • Implement monitoring, alerting and performance tuning across the cloud and network estate — including the Meraki SD‑WAN — and integrate observability into Microsoft Sentinel and SysAid.
  • Mentor and upskill the Service Delivery team, embed knowledge in SysAid, and shift incident resolution left so that more issues are resolved at first touch rather than escalated.
  • Contribute to the IT governance framework — standards, runbooks, RACI ownership, change control and vendor management — in line with ITIL 4 service management practice.
  • Stay current with Microsoft and AWS platform innovations, and recommend improvements to architecture, cost utilisation and security posture.

Essential Skills and Experience

  • Proven senior engineering experience in a Microsoft‑first cloud environment, ideally including a hybrid‑to‑cloud migration programme.
  • Deep, hands‑on expertise across Microsoft 365 (Exchange Online, SharePoint, OneDrive, Teams), Entra ID (conditional access, identity governance), and Microsoft Intune / Autopilot for Windows endpoint management.
  • Strong Azure engineering skills — IaaS, PaaS, networking, identity, governance, cost management — and proven experience designing and operating Azure Virtual Desktop at scale.
  • Solid experience as an AWS engineer or solution architect, sufficient to own and govern an existing AWS workload (IAM, networking, monitoring, automation, security).
  • Strong understanding of identity‑led security: Entra Conditional Access, MFA, PIM, zero trust principles, and SIEM operations (Microsoft Sentinel or equivalent).
  • Experience administering and integrating endpoint and security platforms such as SentinelOne EDR, DNSFilter, JAMF (macOS) and modern password / secrets management tooling.
  • Strong scripting and automation skills (PowerShell essential; Bash / Python / Bicep / Terraform desirable).
  • Networking fundamentals — routing, firewalls, VPN / ZTNA, Wi‑Fi, ideally including hands‑on Meraki experience.
  • Excellent problem‑solving and troubleshooting skills with a proactive, solutions‑driven mindset.
  • Strong communication skills, comfortable working with senior stakeholders, vendors and non‑technical users in a fast‑moving creative business.
  • Familiarity with ITIL 4 service operations — incident, problem, change — and with operating inside an ITSM platform such as SysAid or ServiceNow.
  • Experience leading retirement of legacy platforms (VMware, on‑premises AD, Cisco ASA, on‑premises file/document stores).
  • Exposure to Sage Intacct or similar cloud finance platforms.
  • Familiarity with Universal Print and modern print‑from‑anywhere architectures.
  • Experience with backup and disaster recovery for Microsoft 365 and Azure workloads.
  • Experience mentoring junior or service‑desk engineers and building a structured shift‑left programme.
  • Familiarity with MySQL and SQL Server administration.

Certifications (Desirable)

  • Microsoft Certified: Identity and Access Administrator Associate (SC‑300) or Security Operations Analyst (SC‑200).
  • Microsoft 365 Certified: Enterprise Administrator Expert (MS‑100 / MS‑101) or equivalent.
  • AWS Certified Solutions Architect – Associate (or higher).
  • ITIL 4 Foundation.

#J-18808-Ljbffr…

Posted: May 17th, 2026