Systems Engineer (Cybersecurity & Infrastructure) job at Quality Chemical Industries Limited
New
Website :
1 Day Ago
Linkedid Twitter Share on facebook
Systems Engineer (Cybersecurity & Infrastructure)
2026-01-31T12:23:37+00:00
Quality Chemical Industries Limited
https://cdn.greatugandajobs.com/jsjobsdata/data/employer/comp_11748/logo/download%20(2).png
FULL_TIME
Kampala
Kampala
00256
Uganda
Pharmaceutical
Computer & IT, Science & Engineering
UGX
MONTH
2026-02-13T17:00:00+00:00
8

Job Summary:

The Systems Engineer (Cybersecurity & Infrastructure) is a senior technical role responsible for designing, securing, and governing QCIL’s server and platform environment. The incumbent will lead infrastructure architecture, virtualization (VMware), enterprise application platform readiness (Microsoft 365, SAP, LIMS, TrackWise), and system security controls required to protect GxP/GMP environments. This role owns standards, technical governance, and disaster recovery design, while the Systems Administrator executes approved operational workstreams.

Reporting Line:

Reports to: Head of IT

Works closely with: Network Engineer (FortiGate / segmentation), OT stakeholders, Application owners, Vendors

Direct reports: Systems Administrator (Infrastructure & Applications)

Primary Objectives (What success looks like)

  • Secure, stable, and scalable server and platform environment with measurable availability and recoverability.
  • Evidence-ready controls for GxP/GMP audits (security, access, backup, DR, change control).
  • Reduced cyber risk through hardening, vulnerability remediation, monitoring, and privileged access control.
  • Predictable, documented system standards and architecture aligned to QCIL business goals.

Key Responsibilities (Technical – Detailed)

A. Infrastructure Architecture & Governance

  • Assess current server, virtualization, storage, identity, and application platform architecture and produce a target-state roadmap.
  • Define and maintain system standards: build templates, naming conventions, IP/DNS standards for servers, patching baselines, backup standards, and logging standards.
  • Approve system changes that affect regulated (GxP/GMP) services, ensuring documented impact assessment and rollback plans.
  • Ensure new technologies align with QCIL architecture and security guidelines before deployment.

B. Cybersecurity for Servers, Identity & Platforms

  • Own server hardening standards (Windows/Linux) and ensure alignment to recognized baselines and QCIL policies.
  • Lead vulnerability management for servers and core platforms: scan review, risk triage, remediation planning, and verification.
  • Administer and tune endpoint/server security tooling (EDR/AV policies for servers), and ensure critical servers are onboarded to SIEM/log monitoring.
  • Implement privileged access controls
  • Partner with the Network Engineer to ensure IT/OT segmentation is enforced for systems
  • Support incident response for system-side events.

C. Virtualization (VMware) & Platform Engineering

  • Own VMware design and lifecycle management.
  • Define VM templates, resource sizing standards, snapshot governance, and host patching schedules with controlled maintenance windows.
  • Design backup and recovery procedures for VMware hosts and critical VMs based on best practices.

D. Core Enterprise Systems (Microsoft 365, SAP, LIMS, TrackWise)

  • Lead infrastructure readiness for core platforms.
  • Coordinate vendor and internal technical teams during upgrades, changes, and troubleshooting of enterprise systems.
  • Define and maintain application dependency maps and connectivity matrices (ports/protocols) for regulated applications.

E. Backup, Disaster Recovery & Business Continuity

  • Own backup strategy and recovery assurance for servers, VMs, and databases: retention, encryption, monitoring, and restore testing.
  • Design, implement, supervise, and test QCIL’s Disaster Recovery Plan for systems.
  • Ensure DR documentation and evidence is audit-ready for GxP/GMP requirements.

F. Compliance, Audit & Documentation

  • Lead technical remediation of audit findings related to systems, access controls, patching, backups, logging, and security configuration.
  • Maintain architecture diagrams, as-built documentation, SOPs/runbooks, and system inventories.
  • Prepare monthly operational reporting: platform health, risks, vulnerability posture, backup/DR status, and improvement roadmap.

Key Performance Indicators (KPIs)

  • Platform availability (uptime) for critical services (AD/DNS, virtualization, core apps).
  • Backup success rate and restore test success rate for critical systems.
  • Vulnerability remediation SLA compliance (critical/high findings).
  • Audit findings closed within agreed timelines with evidence.
  • Mean time to resolve (MTTR) for system incidents and reduction of recurring issues.

Minimum Qualifications & Experience

  • BSc degree in IT, Computer Science, Engineering, or related field.
  • Minimum 5 years in Systems Administration/Engineering with demonstrated ownership of VMware and Windows Server environments.
  • Hands-on experience supporting enterprise platforms (Microsoft 365, SAP or similar ERP, LIMS, TrackWise or regulated quality systems).
  • Experience with vulnerability management and security tooling (EDR, SIEM concepts, hardening).

Certifications (Preferred)

  • Microsoft (e.g., Windows Server / Azure / M365) certifications.
  • VMware (VCP) or equivalent virtualization certification.
  • Security-related certification (e.g., Security+, vendor security training) – advantage.
  • ITIL Foundation – advantage.

Core Technical Skills

  • Windows Server (AD DS, GPO, DNS, DHCP), Linux administration, scripting/automation basics (PowerShell).
  • VMware vCenter/ESXi, HA/DRS, capacity planning, troubleshooting performance bottlenecks.
  • Backup and recovery tooling and methodology; DR planning and testing.
  • Database fundamentals (SQL Server/Postgres) including backup/restore, permissions, performance monitoring.
  • Security hardening, vulnerability remediation workflows, logging/monitoring concepts, and incident support.

Behavioral Competencies

  • Strong analytical problem-solving; evidence-based troubleshooting.
  • Excellent documentation discipline and change control mindset (especially for GxP systems).
  • Ability to communicate technical risk and options to non-technical stakeholders.
  • Collaborative leadership; mentoring Systems Administrator and working across teams.
  • Assess current server, virtualization, storage, identity, and application platform architecture and produce a target-state roadmap.
  • Define and maintain system standards: build templates, naming conventions, IP/DNS standards for servers, patching baselines, backup standards, and logging standards.
  • Approve system changes that affect regulated (GxP/GMP) services, ensuring documented impact assessment and rollback plans.
  • Ensure new technologies align with QCIL architecture and security guidelines before deployment.
  • Own server hardening standards (Windows/Linux) and ensure alignment to recognized baselines and QCIL policies.
  • Lead vulnerability management for servers and core platforms: scan review, risk triage, remediation planning, and verification.
  • Administer and tune endpoint/server security tooling (EDR/AV policies for servers), and ensure critical servers are onboarded to SIEM/log monitoring.
  • Implement privileged access controls
  • Partner with the Network Engineer to ensure IT/OT segmentation is enforced for systems
  • Support incident response for system-side events.
  • Own VMware design and lifecycle management.
  • Define VM templates, resource sizing standards, snapshot governance, and host patching schedules with controlled maintenance windows.
  • Design backup and recovery procedures for VMware hosts and critical VMs based on best practices.
  • Lead infrastructure readiness for core platforms.
  • Coordinate vendor and internal technical teams during upgrades, changes, and troubleshooting of enterprise systems.
  • Define and maintain application dependency maps and connectivity matrices (ports/protocols) for regulated applications.
  • Own backup strategy and recovery assurance for servers, VMs, and databases: retention, encryption, monitoring, and restore testing.
  • Design, implement, supervise, and test QCIL’s Disaster Recovery Plan for systems.
  • Ensure DR documentation and evidence is audit-ready for GxP/GMP requirements.
  • Lead technical remediation of audit findings related to systems, access controls, patching, backups, logging, and security configuration.
  • Maintain architecture diagrams, as-built documentation, SOPs/runbooks, and system inventories.
  • Prepare monthly operational reporting: platform health, risks, vulnerability posture, backup/DR status, and improvement roadmap.
  • Windows Server (AD DS, GPO, DNS, DHCP)
  • Linux administration
  • Scripting/automation basics (PowerShell)
  • VMware vCenter/ESXi
  • HA/DRS
  • Capacity planning
  • Troubleshooting performance bottlenecks
  • Backup and recovery tooling and methodology
  • DR planning and testing
  • Database fundamentals (SQL Server/Postgres) including backup/restore, permissions, performance monitoring
  • Security hardening
  • Vulnerability remediation workflows
  • Logging/monitoring concepts
  • Incident support
  • Strong analytical problem-solving
  • Evidence-based troubleshooting
  • Excellent documentation discipline
  • Change control mindset (especially for GxP systems)
  • Ability to communicate technical risk and options to non-technical stakeholders
  • Collaborative leadership
  • Mentoring Systems Administrator
  • Working across teams
  • BSc degree in IT, Computer Science, Engineering, or related field.
  • Minimum 5 years in Systems Administration/Engineering with demonstrated ownership of VMware and Windows Server environments.
  • Hands-on experience supporting enterprise platforms (Microsoft 365, SAP or similar ERP, LIMS, TrackWise or regulated quality systems).
  • Experience with vulnerability management and security tooling (EDR, SIEM concepts, hardening).
  • Microsoft (e.g., Windows Server / Azure / M365) certifications.
  • VMware (VCP) or equivalent virtualization certification.
  • Security-related certification (e.g., Security+, vendor security training) – advantage.
  • ITIL Foundation – advantage.
bachelor degree
60
JOB-697df449f0326

Vacancy title:
Systems Engineer (Cybersecurity & Infrastructure)

[Type: FULL_TIME, Industry: Pharmaceutical, Category: Computer & IT, Science & Engineering]

Jobs at:
Quality Chemical Industries Limited

Deadline of this Job:
Friday, February 13 2026

Duty Station:
Kampala | Kampala

Summary
Date Posted: Saturday, January 31 2026, Base Salary: Not Disclosed

Similar Jobs in Uganda
Learn more about Quality Chemical Industries Limited
Quality Chemical Industries Limited jobs in Uganda

JOB DETAILS:

Job Summary:

The Systems Engineer (Cybersecurity & Infrastructure) is a senior technical role responsible for designing, securing, and governing QCIL’s server and platform environment. The incumbent will lead infrastructure architecture, virtualization (VMware), enterprise application platform readiness (Microsoft 365, SAP, LIMS, TrackWise), and system security controls required to protect GxP/GMP environments. This role owns standards, technical governance, and disaster recovery design, while the Systems Administrator executes approved operational workstreams.

Reporting Line:

Reports to: Head of IT

Works closely with: Network Engineer (FortiGate / segmentation), OT stakeholders, Application owners, Vendors

Direct reports: Systems Administrator (Infrastructure & Applications)

Primary Objectives (What success looks like)

  • Secure, stable, and scalable server and platform environment with measurable availability and recoverability.
  • Evidence-ready controls for GxP/GMP audits (security, access, backup, DR, change control).
  • Reduced cyber risk through hardening, vulnerability remediation, monitoring, and privileged access control.
  • Predictable, documented system standards and architecture aligned to QCIL business goals.

Key Responsibilities (Technical – Detailed)

A. Infrastructure Architecture & Governance

  • Assess current server, virtualization, storage, identity, and application platform architecture and produce a target-state roadmap.
  • Define and maintain system standards: build templates, naming conventions, IP/DNS standards for servers, patching baselines, backup standards, and logging standards.
  • Approve system changes that affect regulated (GxP/GMP) services, ensuring documented impact assessment and rollback plans.
  • Ensure new technologies align with QCIL architecture and security guidelines before deployment.

B. Cybersecurity for Servers, Identity & Platforms

  • Own server hardening standards (Windows/Linux) and ensure alignment to recognized baselines and QCIL policies.
  • Lead vulnerability management for servers and core platforms: scan review, risk triage, remediation planning, and verification.
  • Administer and tune endpoint/server security tooling (EDR/AV policies for servers), and ensure critical servers are onboarded to SIEM/log monitoring.
  • Implement privileged access controls
  • Partner with the Network Engineer to ensure IT/OT segmentation is enforced for systems
  • Support incident response for system-side events.

C. Virtualization (VMware) & Platform Engineering

  • Own VMware design and lifecycle management.
  • Define VM templates, resource sizing standards, snapshot governance, and host patching schedules with controlled maintenance windows.
  • Design backup and recovery procedures for VMware hosts and critical VMs based on best practices.

D. Core Enterprise Systems (Microsoft 365, SAP, LIMS, TrackWise)

  • Lead infrastructure readiness for core platforms.
  • Coordinate vendor and internal technical teams during upgrades, changes, and troubleshooting of enterprise systems.
  • Define and maintain application dependency maps and connectivity matrices (ports/protocols) for regulated applications.

E. Backup, Disaster Recovery & Business Continuity

  • Own backup strategy and recovery assurance for servers, VMs, and databases: retention, encryption, monitoring, and restore testing.
  • Design, implement, supervise, and test QCIL’s Disaster Recovery Plan for systems.
  • Ensure DR documentation and evidence is audit-ready for GxP/GMP requirements.

F. Compliance, Audit & Documentation

  • Lead technical remediation of audit findings related to systems, access controls, patching, backups, logging, and security configuration.
  • Maintain architecture diagrams, as-built documentation, SOPs/runbooks, and system inventories.
  • Prepare monthly operational reporting: platform health, risks, vulnerability posture, backup/DR status, and improvement roadmap.

Key Performance Indicators (KPIs)

  • Platform availability (uptime) for critical services (AD/DNS, virtualization, core apps).
  • Backup success rate and restore test success rate for critical systems.
  • Vulnerability remediation SLA compliance (critical/high findings).
  • Audit findings closed within agreed timelines with evidence.
  • Mean time to resolve (MTTR) for system incidents and reduction of recurring issues.

Minimum Qualifications & Experience

  • BSc degree in IT, Computer Science, Engineering, or related field.
  • Minimum 5 years in Systems Administration/Engineering with demonstrated ownership of VMware and Windows Server environments.
  • Hands-on experience supporting enterprise platforms (Microsoft 365, SAP or similar ERP, LIMS, TrackWise or regulated quality systems).
  • Experience with vulnerability management and security tooling (EDR, SIEM concepts, hardening).

Certifications (Preferred)

  • Microsoft (e.g., Windows Server / Azure / M365) certifications.
  • VMware (VCP) or equivalent virtualization certification.
  • Security-related certification (e.g., Security+, vendor security training) – advantage.
  • ITIL Foundation – advantage.

Core Technical Skills

  • Windows Server (AD DS, GPO, DNS, DHCP), Linux administration, scripting/automation basics (PowerShell).
  • VMware vCenter/ESXi, HA/DRS, capacity planning, troubleshooting performance bottlenecks.
  • Backup and recovery tooling and methodology; DR planning and testing.
  • Database fundamentals (SQL Server/Postgres) including backup/restore, permissions, performance monitoring.
  • Security hardening, vulnerability remediation workflows, logging/monitoring concepts, and incident support.

Behavioral Competencies

  • Strong analytical problem-solving; evidence-based troubleshooting.
  • Excellent documentation discipline and change control mindset (especially for GxP systems).
  • Ability to communicate technical risk and options to non-technical stakeholders.
  • Collaborative leadership; mentoring Systems Administrator and working across teams.

Work Hours: 8

Experience in Months: 60

Level of Education: bachelor degree

Job application procedure
Interested in applying for this job? Click here to submit your application now.

Interested persons who meet the above requirements should hand deliver or send their applications and resumes with supporting documents, with the “Role Name” as the subject to the Qcil Front Desk

Deadline for receiving applications: Friday 13th February 2026

Only short-listed candidates will be contacted. Qcil is an equal opportunity employer and therefore lobbying for the above position will lead to automatic disqualification.

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Uganda
Job Type: Full-time
Deadline of this Job: Friday, February 13 2026
Duty Station: Kampala | Kampala
Posted: 31-01-2026
No of Jobs: 1
Start Publishing: 31-01-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.