At Enery, we're powering the future…literally.
We are an independent renewable energy provider dedicated to delivering reliable, affordable, and long-term green energy to our customers. We have scaled rapidly to over 1.1 GW of operating capacity, with a development pipeline of close to 10 GW across around 10 CEE countries — alongside a leading position in revenue optimization for utility-scale renewable and storage assets. Present in 10 countries across Central and Eastern Europe, our reach reflects our commitment to making a meaningful climate impact across the region.
But we're more than just energy and infrastructure. With a diverse, multidisciplinary team representing over 30 nationalities, we value transparency, ownership, and continuous learning. We move fast, collaborate across disciplines, and celebrate wins, big and small, together.
At Enery, ESG isn't a checkbox. It's embedded into every decision we make, from project development and construction to long-term operations.
As Senior IT Administrator, you will own Enery's network and cloud infrastructure end to end — the firewalls and VLANs across our offices and power plants, the Azure hub-and-spoke architecture that every administrative path runs through, our AWS governance baseline, and the IT/OT boundary that protects the plants themselves. This is a single-owner role in a small team: you will inherit a real estate, document it properly, and decide where it goes next. You report to the Head of IT & AI.
Key Responsibilities
- Own the network end to end: site and office firewalls, the VLAN and IP plan, the wireless estate, per-country ISP relationships, and the routing between all of it
- Own our Azure landing zone: hub-and-spoke architecture, hub firewalls, the per-country jump hosts, site-to-site routing, and the per-country allow-lists that govern who reaches what
- Own AWS governance: Organizations and OUs, IAM baseline and SCPs, MFA enforcement, GuardDuty, Security Hub, CloudTrail and centralised logging across all accounts
- Own the IT/OT boundary: industrial firewalls at each plant boundary, default-deny rulesets, boundary log capture into our SIEM, and the brokered administrative paths into plant networks — working alongside our OT engineer and our network integrator
- Own backup and recovery: immutable backup for our critical systems, restore testing against agreed RPO/RTO targets, and the integrity checks that prove the backups work
- Produce the evidence, not just the control: network segmentation and zone documentation, firewall rule audits, certificate inventories, the annual rule review.
- Manage the infrastructure vendors — network integrator, hardware vendors, ISPs — from technical scope through delivery and acceptance
- Hold privileged access to a high standard: administrative account hygiene, break-glass procedures, and reviews that you can hand to an auditor
- Carry your share of day-to-day IT: escalations from the service desk, new-site build-outs, and the occasional onboarding
Key Requirements
- 7+ years in IT infrastructure and network administration, at least 3 of them owning an estate rather than working tickets inside someone else's
- Deep network engineering: enterprise firewalls (Cisco preferred), routing and switching, VLAN and zone design, ACLs, site-to-site VPN, remote-access VPN
- Azure infrastructure in production: hub-and-spoke networking, Azure Firewall, network security groups, jump-host patterns, Entra ID and conditional access
- Working AWS administration: Organizations, IAM, SCPs, VPC networking, and the security services that sit on top (GuardDuty, Security Hub, CloudTrail)
- Backup and disaster recovery as an owned discipline — you have defined RPO/RTO with business owners and run restore tests that were allowed to fail
- Documentation discipline: you accept that a control nobody can evidence does not count, and you write the diagram and the rule audit without being asked twice
- Scripting for automation and reporting — PowerShell or Python
- A pragmatic security posture: you can tell the difference between what a standard names as an obligation and what is merely one technique for meeting it, and you can argue the case
- Fluent English; German is a plus but not required
- Willingness to travel occasionally to our offices and plant sites across CEE
Nice-to-Haves
- OT / industrial network exposure: plant networks, industrial firewalls, Purdue-style zoning, or any of Modbus TCP, OPC UA and IEC 60870-5-104
- Hands-on NIS2, ISO 27001 or IEC 62443 work — particularly the evidence and audit side
- Experience in energy, utilities or another critical-infrastructure sector
- NAC / 802.1X / RADIUS, and a view on where it earns its place against an identity-first model
- ZTNA or SSE platforms (Cisco Secure Access, Microsoft Entra Private Access or comparable)
- SIEM work, especially Microsoft Sentinel — detections, log onboarding, working with an external SOC
- Microsoft 365 and Intune administration
- Infrastructure as code (Terraform / OpenTofu) and Git-based change workflows
- You have taken over an undocumented estate from a departing owner before, and stabilised it