The Systems Engineer (Linux) is the senior technical authority for the Institute's Linux estate, responsible for the build, configuration, hardening, patching and day-to-day operation of Linux servers and cloud. Scope covers Red Hat Enterprise Linux and comparable distributions running on physical hardware, VMware and Nutanix on premises, and as instances in AWS and Microsoft Azure, with build and operating parity maintained between the two so that cloud is not an unmanaged exception.Automation is central to how the role works rather than an aspiration attached to it. The engineer builds and maintains Ansible playbooks, roles and inventories and operates Ansible Automation Platform or AWS where deployed, to automate provisioning, hardening, patching, application deployment and remediation of configuration drift, with automation code held in version control and promoted through a documented path. The role owns recurring patching cycles across the global Linux estate and the remediation activity supporting the enterprise vulnerability management program, with structured pre- and post-change validation, documented rollback and enforced change control.The role also builds and supports the application services hosted on Linux, web and application servers, middleware, containers and runtime dependencies in coordination with application owners, and ensures Linux workloads are protected at build, recoverable by test and covered by disaster recovery. Working an assigned shift within a multidisciplinary infrastructure team and reporting to the Manager IT Infrastructure for that shift, the engineer supports users and application teams, acts as second and third level escalation, hands over open work cleanly at shift boundaries, and provides technical leadership and mentoring to less experienced engineers.**ESSENTIAL DUTIES & RESPONSIBILITIES****Linux Server Estate - Build, Configuration and Lifecycle**· Provision, configure, harden and maintain Linux servers across Red Hat Enterprise Linux, Rocky, Oracle Linux, SUSE and Ubuntu, on premises and in cloud, covering the full lifecycle from build through decommission.· Maintain standardized, automated build pipelines and golden images so that servers are built to a documented standard rather than by hand, with parity between on-premises and cloud builds.· Administer the Linux platform layer, including filesystems and LVM, storage presentation and multipath, networking, system services, kernel parameters and performance tuning, user and Sudo access, and SSH and certificate management.· Administer Linux workloads on VMware, Nutanix and physical server hardware, including firmware currency and OEM support status for physical hosts.· Integrate Linux hosts with enterprise directory and access management, including Active Directory or LDAP integration through SSSD, Kerberos, centralized authentication and privileged access controls.· Manage Linux subscription, repository and package estate, including Red Hat Satellite or equivalent, repository mirroring, and content lifecycle promotion across development, test and production.**Linux Operations and Application Services Support**· Provide operational support for Linux instances working the assigned shift and supporting users and application teams in every region.· Build, maintain and support the application services hosted on Linux, including web and application servers such as Apache, NGINX, Tomcat and JBoss, middleware, containers and runtime dependencies, in coordination with application owners.· Support database hosting on Linux at the platform layer, including filesystem layout, kernel and resource tuning, and backup interfaces, in coordination with database owners.· Act as second and third level escalation for complex Linux, application platform and performance issues, troubleshooting to root cause across operating system, storage, network and application layers, and liaising with vendors.· Monitor system health and capacity through monitoring tooling and manual checks, tune alerting so that what reaches an engineer is actionable, and respond to degradation before it becomes an incident.· Support application deployment and release activity on Linux, including environment preparation, pre- and post-deployment validation and rollback.**Patching, Vulnerability Remediation and Compliance**· Execute recurring patching cycles for the global Linux estate, on premises and in cloud, in line with security and compliance timelines and agreed maintenance windows.· Remediate findings raised by the enterprise vulnerability management program, tracking items through to closure and reporting remediation status, risk acceptance and exceptions with agreed remediation dates.· Maintain hardening baselines such as CIS benchmarks or equivalent, and use Ansible to enforce and remediate configuration drift rather than only to detect it.· Manage kernel update and live-patching strategy, reboot orchestration and cluster-aware patching so that service impact is minimized and clustered workloads are patched safely.· Perform structured pre-patch and post-patch validation covering services, applications and dependencies, and document the outcome of every cycle.· Follow and enforce change control, tested rollback planning and coordination of maintenance windows with application owners, and support internal and external audit with documented evidence.**Automation and Configuration Management with Ansible**· Build and maintain Ansible playbooks, roles, collections and inventories to automate provisioning, hardening, patching, application deployment and remediation of configuration drift.· Operate Ansible Automation Platform or AWX where deployed, including job templates, workflows, credentials, scheduling, inventory sources and role-based access.· Hold automation code in version control with peer review, testing and a documented promotion path across environments, so that automation is maintainable by more than its author.· Extend automation into cloud provisioning and infrastructure-as-code, and integrate with CI/CD pipelines where used by application teams.· Develop Bash and Python scripting where Ansible is not the right tool, and quantify the manual effort removed by each automation delivered.**Cloud Linux Infrastructure - AWS and Azure**· Administer Linux instances in AWS and Microsoft Azure, including compute, block and object storage, images, virtual networking, security groups and resource tagging.· Maintain build, hardening, patching and monitoring parity between cloud and on-premises Linux instances, so that cloud servers are held to the same standard and evidenced in the same reporting.· Manage cloud identity and access as it relates to Linux hosts, including IAM roles and instance profiles, key and secret management, and bastion or session-manager access patterns.· Support assessment, migration and rollback of Linux workloads between on-premises and cloud, including the identity, network, storage and protection consequences.· Monitor and optimize cloud consumption for Linux infrastructure, including right-sizing, commitment planning, removal of orphaned volumes and snapshots, and reporting of variance against budget.**Backup, Resilience and Disaster Recovery**· Ensure Linux workloads are protected at build rather than retrospectively, with backup agents, policies and application-consistent handling configured correctly for file, database and application workloads.· Execute and validate restores of Linux systems and application data, and participate in the scheduled restoration testing cadence with the Storage and Backup Engineer.· Maintain high availability and clustering for Linux workloads where required, including Pacemaker and Corosync, load balancing and replication.· Participate in disaster recovery drills as an executing engineer, covering failover, failback and validation, and maintain recovery runbooks