iBET is seeking a mid-level IT Systems & Security Administrator to strengthen server and network security operations across the institute.
The IT Systems & Security Administrator will report to the Head of IT and play a key role in keeping iBET’s hybrid Windows and Linux infrastructure secure and reliable. This role encompasses a diverse set of responsibilities, including patch management, network security hardening, and ownership of vulnerability triage and post-patch validation as distinct disciplines.
As IT Systems & Security Administrator, you will help iBET keep pace with rising patch volumes and compressed exploit timelines, supporting world-class research infrastructure. You’ll work hands-on across Windows Server and Linux environments, manage VLAN and firewall configurations, and turn ad-hoc patching into a governed, risk-based process.
Your responsibilities will include, but are not limited to:
- Patch management across Windows Server and Linux distros (scheduling, testing, rollback planning).
- Server provisioning, configuration, and lifecycle management (physical + virtualized).
- Backup/restore operations and disaster recovery testing.
- Monitoring server health, capacity, and performance.
- Documentation of server inventory, configurations, and runbooks.
Patch Triage & Validation
- Centralized triage of incoming vulnerabilities – classify by risk/exposure and assign to tiered patch categories.
- Maintain and apply a risk-based tiering model (critical/high/medium/low) to prioritize patch sequencing.
- Own post-patch validation as a workflow separate from implementation – confirm system/integration functionality after patching, coordinating with end users/labs where needed.
- Track risk-acceptance exceptions for delayed or non-patchable systems, per agreed policy.
Network & Security
- VLAN segmentation and maintenance.
- Firewall rule management, review, and audit.
- Apply containment/segmentation as a compensating control for non-patchable or vendor-locked systems.
- Security hardening of servers and network devices.
- Supporting security audits and closing findings (e.g., CVSS-rated issues).
General / Ongoing Responsibilities
- Incident response and troubleshooting (escalation point for infra/network issues).
- Coordinate patch windows with lab operations to align security work with experimental/research timelines.
- Collaboration with the Head of IT on security posture, governance, and escalation of overload risk.
- Occasional support for M365 environment issues when they intersect with infra/network.
- 2-4 years in systems/network administration.
- Solid Windows Server administration (AD, GPO, DNS).
- Working Linux administration (Debian/Ubuntu and/or RHEL).
- Practical firewall and VLAN configuration experience (any major vendor).
- Willingness to develop expertise in patch management workflows, CVE triage, and risk-based prioritization.
- Comfortable with command-line troubleshooting on both platforms.
- Strong stakeholder communication skills – able to balance security urgency with operational/research constraints when scheduling patch windows.
- Fluent in Portuguese and English.
- Nice to have: experience with a patch management platform (server patch deployment, vulnerability scanning, automated patch policies); experience in a research/lab or regulated environment; exposure to Azure or hybrid cloud administration; general ticketing system experience; relevant Microsoft certifications (e.g., Windows Server Hybrid Administrator, AZ-104).
- Opportunity to strengthen and modernize security operations across a cutting-edge biotech R&D environment.
- 12-month contract, full-time, on-site in Oeiras.
- Direct collaboration with the Head of IT on infrastructure and security strategy.
- Professional development and growth opportunities across both Windows and Linux environments.
- Collaborative and innovative workplace culture.
Does this sound like the right challenge for you?