At a Glance
- Tasks: Design and automate secure, cloud-native infrastructure for cutting-edge network APIs.
- Company: Join BT, a leader in mobile network innovation with a collaborative culture.
- Benefits: Competitive salary, generous pension scheme, life assurance, and exclusive discounts.
- Why this job: Make a real impact on the future of network technology while working flexibly.
- Qualifications: Strong Linux skills and experience with Kubernetes and API management.
- Other info: Dynamic work environment with excellent career growth opportunities.
The predicted salary is between 36000 - 60000 ÂŁ per year.
Network-as-a service (NaaS) is a strategic enabler within BT’s mobile network architecture, designed to unlock and expose core network capabilities in a reliable and commercially governed manner. NaaS provides centralized API exposure capabilities, allowing BT to publish and manage GSMA CAMARA aligned APIs in a secure, traceable, and programmatic manner. This role ensures the underlying multi‑site, resilient, automated, secure infrastructure powering NaaS APIs is engineered, governed and operated to carrier‑grade standards.
You will design and automate infrastructure for Kubernetes‑hosted network APIs, API gateways (Apigee/Kong), identity and consent services, routing and aggregator integrations — with a strong emphasis on PKI, certificate lifecycle automation, secrets management (Vault) and gateway-level security.
What you’ll be doing
- Design and operate cloud‑native environments hosting NaaS components (API gateway, identity & consent services, aggregator integrations, TMF‑931 APIs).
- Engineer infrastructure supporting dual‑site deployments on BT’s private cloud ecosystem with active/active or active/standby failover patterns.
- Maintain Kubernetes workloads deployed via Helm charts and environment‑specific configuration pipelines used in NaaS delivery.
- Optimise cluster networking, pod‑to‑pod routing, overlay networks, and VPC connectivity required for NaaS northbound/southbound integration.
- Standardise GitLab‑based deployment automation used across NaaS (e.g., templated Helm chart rollouts, environment switching, version promotion).
- Create automated patterns for repetitive run tasks: certificate rotation, namespace creation, resource onboarding and gateway policy application.
- Configure and operate NGINX (Ingress) and Kong API Gateway for internal/external API exposure, including routing, transformations, policies, plugins, and rate limiting.
- Build automation pipelines for dynamic secrets, lease renewal, token lifecycle and secret‑rotation using Vault Agents or sidecar models.
- Ensure API services and ingress components follow strict Zero‑Trust and mTLS standards.
- Operate Kong API Gateway with automated provisioning of routes, consumers, plugins, certificates, OAuth/OIDC configs, and rate‑limit/security policies.
- Instrument NGINX and Kong with structured logging, metrics, gateway tracing and plugin‑level observability.
- Validate multi‑site GSLB routing for API flows using synthetic probes, ingress/gateway failover testing and API path validation.
What you'll bring
- Strong Linux fundamentals and troubleshooting (system performance, networking, storage).
- Practical understanding of L7/L4 load balancing, service mesh, DNS/GSLB, certificate management and API connectivity patterns into telco/core systems.
- Strong understanding of CA hierarchies, mTLS, certificate lifecycle management, CRL/OCSP, key rotation, HSM/KMS.
- Ability to design automated certificate workflows for Kubernetes, gateways, and service mesh.
- Deep configuration experience (ingress rules, SSL termination, upstream configuration, rewrite/redirect rules) on NGINX including performance tuning, rate limiting, mTLS enforcement, header-based routing etc.
- Understanding of service registration, upstream health checks, traffic routing, consumer management etc.
- Expertise with Kong plugins (JWT, ACL, rate limit, key auth, OIDC, mTLS), declarative configs (Kong YAML), and Ingress Controller.
- Access, use, and disclose information only as required for the job; ensure appropriate safeguards and adherence to Information Security policies.
- Familiarity with Hashicorp Vault.
- Familiarity with ITIL/incident management and change practices (or equivalent experience).
- Excellent verbal and written communication and interpersonal skills.
NICE TO HAVE
- Expertise in automating secret delivery via Vault Agent, Vault Injector or GitLab CI integration.
- Automation mindset: scripting (Python/Bash) + one or more of Terraform/Ansible/Helm/Kustomize/GitOps.
- Experience designing observability for serverless systems (logs/metrics/traces) and implementing distributed tracing and dashboards using open standards and various tooling like Elastic, Grafana etc.
- CAMARA and TMF‑931 familiarity; API aggregator marketplace exposure (e.g., AWS/Vonage/NAC listings).
- Experience with network automation (YANG/NETCONF/RESTCONF, Ansible) and telco workloads.
- Kubernetes certification (e.g., CKA/CKAD).
What’s in it for you
- 10% on target bonus.
- BT Pension scheme, minimum 5% Employee contribution, BT contribution 10%.
- Life Assurance Cover.
- Exclusive colleague discounts on our latest and greatest BT broadband packages, BT TV with TNT Sports and NOW Entertainment.
- From January 2025, equal family leave: receive 18 weeks at full pay, 8 weeks at half pay and 26 weeks at the statutory rate. It’s for all parents, no matter how your family is made up.
- Enhanced women’s health support: including help with menopause symptoms, cancer screenings, period care and more.
- 25 days annual leave.
Infrastructure Engineer in London employer: BT Group
Contact Detail:
BT Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Infrastructure Engineer in London
✨Tip Number 1
Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or even just chat with folks on LinkedIn. You never know who might have a lead on your dream Infrastructure Engineer role!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to Kubernetes, API gateways, and automation. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews like a pro! Research common questions for Infrastructure Engineers and practice your answers. Be ready to discuss your experience with Linux, load balancing, and certificate management. Confidence is key!
✨Tip Number 4
Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you, and applying directly can sometimes give you an edge. Plus, it’s super easy to keep track of your applications that way!
We think you need these skills to ace Infrastructure Engineer in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Infrastructure Engineer role. Highlight your experience with Kubernetes, API gateways, and any relevant automation tools. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how your background makes you a great fit. Don’t forget to mention your understanding of NaaS and cloud-native environments.
Showcase Your Technical Skills: Be specific about your technical skills in your application. Mention your experience with Linux, load balancing, and certificate management. We love seeing concrete examples of how you've tackled similar challenges in the past.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing candidates who take that extra step!
How to prepare for a job interview at BT Group
✨Know Your Tech Inside Out
Make sure you brush up on your Linux fundamentals and Kubernetes knowledge. Be ready to discuss your experience with load balancing, API connectivity patterns, and certificate management. The more specific examples you can provide, the better!
✨Showcase Your Automation Skills
Since this role emphasises automation, be prepared to talk about your experience with tools like Terraform, Ansible, or GitOps. Share any projects where you've automated tasks, especially around certificate workflows or secret management using Vault.
✨Understand the Company’s Needs
Research BT's Network-as-a-Service (NaaS) and how it fits into their mobile network architecture. Understanding their goals will help you tailor your answers and show that you're genuinely interested in contributing to their success.
✨Communicate Clearly and Confidently
Excellent communication skills are a must for this role. Practice explaining complex technical concepts in simple terms. This will not only demonstrate your expertise but also your ability to work well with others in a team environment.