You are here: Home » International Open Positions

International Open Positions

Zentiva is a producer of high-quality affordable medicines serving patients in Europe and beyond. With a dedicated team of more than 3,000 people and a network of production sites - including flagship sites in Prague and Bucharest – Zentiva strives to be the champion of branded and generic medicines in Europe to better support people’s daily healthcare needs. At Zentiva it is our aspiration that healthcare should be a right and not a privilege. More than ever, people need better access to high quality affordable medicines and healthcare.
We are currently looking for candidates for the position of:

IT Infrastructure Administrator Senior

Mission Statement:

Senior System Engineer (SSE) is a member of a team responsible to control design, setup, maintenance and monitoring of backend solutions in on premise datacenters and cloud environments that include Microsoft and Linux servers (physical and virtual) and technologies, virtualization, storage and backup and related technologies as well as a variety of specific infrastructure services and applications running on these components.

Your responsibilities:

BackEnd infrastructure management, administration and operation
• SSE controls a design, setup, maintenance, monitoring and administration of backend solutions in on premise datacenters and cloud environments that include Microsoft and Linux servers (physical and virtual) and their operating systems, virtualization, storage and backup and related technologies as well as a variety of specific infrastructure services and applications running on these components.
• SSE performs advanced operational administration and support of infrastructure and works independently and with service providers on troubleshooting incidents and problems.
• SSE performs advanced operational administration and support of infrastructure in order to prevent incidents and problems and assures health and continuity of the service.
• Works within established configuration and change management policies to ensure awareness, approval and success of changes made to the BackEnd infrastructure.
• Selects and proposes tools, policies, and procedures in conjunction with the IT security team to ensure secure data access and functional disaster recovery environment.
• Analyses, evaluates and monitors BackEnd infrastructure and integrity to ensure the BackEnd environment is configured to operate at optimal performance, cooperates on capacity planning.
• Creates, oversees and test security measures (e.g. access authentication and disaster recovery).
• SSE cooperates on design and maintenance of processes, procedures and operational management associated with BackEnd infrastructure operation in hosted, on premise datacenters and cloud environment, maintains relevant technical documentation and SOPs.
• As a member of the BackEnd Infrastructure Team, SSE will analyze technical issues, address Level 2 escalations and work with the project manager on team related projects.
• SSE provides expert technical assistance to other Infrastructure team members to ensure integrity of BackEnd solutions with FrontEnd infrastructure.
• SSE performs other tasks under the direction of the manager within the agreed type of work.
• SSE is a technology leader for other team members - System Engineers.

Innovation & services improvement
• Cooperates with BackEnd service suppliers to plan, configure and install various services (e.g., deployment of new servers & storage capacities).
• SSE suggests improvements to infrastructure performance, capacity and scalability.
• SSE contributes to a research and development of new products and service relevant to areas of responsibility.

Other accountabilities
• SSE assesses technical needs for potential new solutions / projects.
• SSE cooperates on budget development for data centers and cloud services in conjunction with the BackEnd Infrastructure Engineering Team Manager; cooperates on defining and monitoring contractual obligations, performance delivery and service level agreements.

We require:

• University Degree in IT technology field
• Minimum 8 years of experience in field of MS Windows based infrastructure
• Experience working in a complex environment.
• Excellent problem-solving skills and thorough knowledge of server&storage administration and architecture.
• Some experience with hybrid environment (on-premise and private/public cloud), MS Azure is a big advantage.
• Proficient in Czech and English language.

Expert knowledge of one or more of the following areas:
MS Active Directory (AD) and MS Azure Active Directory (AAD):
The scope of work is provisioning of this CRITICAL Active Directory service in the cloud and on-premise datacenters.
• Standard Active Directory administration
o check of logs and prophylaxis,
o handling events raising from the antivirus protection;
o using monitoring system for administration
o check of FSMO roles (Flexible Single Master Operation)
o check intersite replication
o regular backup (respecting AD functionality)
• Administration of underlying Microsoft Windows servers
• Patch management (on the level of MS Windows servers)
o Incident solution on the service and underlying MS Windows operating system as well as on underlying server HW (incident resolution may be fulfilled also by recovery of the service from the backup of the respective MS Windows server. Virtual server image backup of the underlying virtual VM is necessary.
• Content management (GPOs, OU structures, policies, object administration, security measures, permissions, delegation models, … etc.)
• Ability to define and enforce policies and good practices

ADFS technology delivers authentication interface so users are able to authenticate themselves against the applications hosted in cloud environments using internal Active Directory identity.
The primary intention is to use ADFS to deliver Office365 applications to Zentiva users with ADFS. ADFS authentication interface can be also used for accessing other applications supporting ADFS authentication standard.
Ability to analyse incidents, suggest a proper solution, remediation of malfunctions. This incorporates, for example, configuration modifications, implementation of hot-fixes and other activities. It also includes daily checking to prevent possible problems.
Reviews of AAD Connect and ADFS environment, related events, volume and data consistency control, disk storage status and replication.
Load balancing. Federation configuration. Work with certificates.

Some knowledge of the technology and underrunning infrastructure.
Microsoft Bitlocker policy settings, bitlocker policy deployments, implementation of certificates, deployment package for GPO configuration, setting Group Policy, on-site installation of MS Bitlocker, operation incidents, security incidents, security incident reporting.

General knowledge of updates/patches & software packages distribution practices on the servers and workstation.
Knowledge of SCCM architectures and underrunning infrastructures.
The SCCM agents
Patch management based on agreed plan on the daily basis

Monitoring and Logging principles
General knowledge of monitoring and logging (SIEM) principles and architectures, underrunning infrastructures. Preferrably knowledge of IBM Qradar enterprise solution.

Antivirus and security principles
General knowledge of antivirus systems principles and architectures.
Knowledge of ESET Antivirus solution is preferred, however there is a plan to replace the solution by some other technology.

You will enjoy working with us because we can offer you:

• Unique opportunity to work for a successful and growing international company at HQ of the company
• Chance to work with a team of professionals in a challenging but very interesting environment
• Continuous personal development
• An attractive compensation & benefits package including cafeteria (cell phone, group life insurance, supplementary pension plan, flexible benefit progarm, holidays 25 days etc.).
• Flexible working hours and home office, SickDays

Place of work - HQ Prague, Dolni Mecholupy


David Vích