This is the section where round two of the screen actually happens, the closing gate before an
interview hits your inbox. A recruiter takes their time here, and even at that, the current
role still drives around 95% of the result.
That tracks: nothing proves what you can run in production today like the seat you sit in
right now. To earn a "yes", the section has to hit every entry on the
Infrastructure Engineer role profile, one bullet per domain you named in Domain
Expertise above. Every bullet has to come off something you genuinely held in production,
never a ticket that landed on your queue.
1
Compute & Virtualization
You run the compute layer everything else sits on. Hiring managers read real virtualization engineering
behind it, not "spun up some VMs", so this is where an infrastructure hire proves out. Talk
about how you used hypervisor design and live migration, on vSphere and KVM, to bring workloads onto
managed hosts and cut provisioning time.
Techniques
Hypervisor design
Bare-metal provisioning
Live migration
Capacity sizing
Tools
VMware vSphere, ESXi
KVM, Proxmox
MAAS, Foreman
Metrics
Hosts under management
Provisioning time cut
Workloads onboarded
2
Networking & Connectivity
You move traffic across the estate: routing, segmentation, load balancing. Networking is where an outage
hides for hours, so hiring managers want proof you designed and debugged it, not that you
"configured a switch". Show them how you used BGP and VXLAN with L4/L7 load balancing, on
Arista and F5, to hold network availability and cut latency.
Techniques
BGP / OSPF
VLAN / VXLAN
L4 / L7 load balancing
VPN & Direct Connect
Tools
Cisco, Arista, Juniper
F5, HAProxy, Nginx
BIND, Infoblox
Metrics
Network availability
Latency cut
Packet loss reduced
3
Storage & Data Services
You store petabytes safely and get them back fast. Two things ride on it for a hiring manager: getting
data back after a failure, and the cost per terabyte to hold it. Point out how you used snapshot
lifecycles and cross-site replication, on NetApp and Ceph, to hold restore success and cut cost per TB.
Techniques
Block, file, object
Backup & replication
Snapshot lifecycle
RPO / RTO design
Tools
NetApp, Pure, Dell EMC
Ceph, GlusterFS
NFS, iSCSI, S3
Metrics
PB under management
Restore success rate
Cost per TB cut
4
Identity & Security Hardening
You lock the fleet down: baselines, patching, tight access. An unpatched host is how attackers get in,
so hiring managers want to see hardening you actually enforced, not a policy on a wiki. Mention how you
used CIS hardening and a real patch cycle, with Vault and OpenSCAP, to get hosts onto baseline and close
CVEs.
Techniques
LDAP / AD / SSO
OS hardening (CIS)
Patch & vuln cycle
PKI & certificates
Tools
FreeIPA, Active Directory
Vault, sssd
OpenSCAP, Lynis
Metrics
Hosts on baseline
CVEs closed
Audits passed
5
Linux & OS Engineering
You tune a Linux fleet to stay fast and predictable. Hiring managers look here to see whether you can
trace a slow box to root cause, or whether you reboot and hope it goes away. Walk them through how you
used kernel tuning and eBPF-based tracing, across RHEL and Ubuntu, to debug real issues and lift
performance.
Techniques
Kernel tuning (sysctl)
Systemd, cgroups
Filesystem internals (XFS, ext4, ZFS)
strace, perf, eBPF
Tools
RHEL, Ubuntu, Debian
Bash, Python
kickstart, cloud-init
Metrics
Fleet under standard image
Issues debugged
Performance lifted
6
Automation & IaC
You build infrastructure from code, not by hand. Hand-built infrastructure breaks in ways only its
author can fix, so a hiring manager reads code-driven infra as a sign you build for the team, not for
job security. Lay out how you used reusable IaC modules and config management, in Terraform and Ansible,
to bring hosts under code and cut provisioning time.
Techniques
Reusable IaC modules
Configuration management
Plan-based PR review
Idempotent playbooks
Tools
Terraform, Pulumi
Ansible, Puppet, Chef
Packer, cloud-init
Metrics
Hosts under code
Provisioning time cut
Drift incidents down
7
Capacity, Performance & DR
You prove the estate survives a rack or site loss. RPO, RTO, and headroom are numbers a hiring manager
can check, so a real DR drill carries more than "maintained backups". Spell out how you used
capacity modeling and DR drills, tracked in Prometheus and Grafana, to hold RPO and RTO and protect
headroom.
Techniques
Capacity modeling
Headroom planning
DR drills
Performance profiling
Tools
Nagios, Zabbix, Prometheus
Grafana, Datadog
iperf, sar, perf
Metrics
RPO / RTO held
Headroom protected
Performance lifted
8
Tooling & Workflow
You make a big estate changeable without chaos. Companies keep the infrastructure engineers who make
change safe, not the ones who are the only one who knows how it works, so hiring managers look for it.
Tell them how you used documented runbooks and infra PR review, in Git and ServiceNow, to speed change
cycles and cut on-call ramp.
Techniques
Internal CLI / runbooks
Change advisory boards
Infra PR review
Self-serve docs
Tools
Git, GitLab
Bash, Python
ServiceNow, Jira
Metrics
Runbooks maintained
PR cycle time
On-call ramp cut