The OpportunityWe're looking for a Senior IT Security System Administrator to own both sides of a critical mandate: keeping our systems running reliably and keeping them secure. This is a hands-on individual contributor role reporting directly to the IT Director. You'll split your time roughly equally between systems administration Google Workspace, Microsoft 365, endpoint management, identity, and SaaS platforms) and security operations (policy enforcement, access control, compliance, threat monitoring, and incident response).
You'll be the person who implements, monitors, and enforces security controls across a rapidly growing distributed workforce. The ideal candidate is technically sharp, operationally disciplined, and comfortable owning both the "does it work" and "is it safe" questions simultaneously. This role is essential for maintaining the reliability, performance, and security of our systems.
What You Will Own- Administer Google Workspace and Microsoft 365 environments, while facilitating the setup and full migration to Microsoft 365.
- Manage a mix of Windows and Mac endpoints using MDM tools for device enrollment, configuration, compliance, and patch management policies.
- Administer SSO, MFA, and directory integrations; maintain identity provider configuration and authentication policy.
- Administer and manage security toolsets (DLP, EDR, email security, and SIEM logs) to ensure effective threat detection and policy enforcement.
- Provide tier 2/3 support for firm-wide SaaS applications as necessary.
- Monitor, triage, and respond to security alerts across endpoint, email, identity, and cloud environments.
- Support compliance activities and internal audits; maintain evidence and documentation for security controls.
- Contribute to incident response: detection, containment, remediation, and post-incident review.
- Assist with vulnerability management, including patch cadence tracking and endpoint hygiene reporting.
- Identify gaps in security coverage or operational process and drive remediation.
- Stay current on emerging threats, vulnerabilities, and best practices relevant to a remote-first professional services environment.
- Develop dashboards & reports for security metrics, compliance status, and operational health.
- Manage relationships with key vendors and service providers, ensuring service level agreements (SLAs) are met.
- Oversee security operations and ensure compliance with relevant industry standards and internal policies.
- Strategy and planning: Translate business needs into operational capability, capacity planning, DR/BCP design, cloud migration strategy, and lifecycle roadmaps.
What You BringRequired:- Minimum of 7 years experience in IT systems administration, security, operations, or a combined role.
- Proven expertise in managing modern, complex IT environments.
- Enterprise level collaboration suite administration experience (Microsoft 365 and/or Google Workspace)
- Security fundamentals: Identity/access controls, patching, vulnerability management, and secure configuration practices.
- Disaster recovery & backups: Design and testable DR plans, RTO/RPO understanding, and backup validation.
- Working knowledge of EDR, email security (SPF/DKIM/DMARC, anti-phishing), DLP, or SIEM tooling in an operational capacity
- Hands-on MDM/UEM experience across Mac and Windows (Jamf, Microsoft Intune, or equivalent); comfortable managing device compliance at scale
- Demonstrated experience administering SSO, MFA, and an identity provider (Okta, Google Identity, Azure AD / Entra ID, or equivalent)
- Solid understanding of security fundamentals: identity lifecycle management, endpoint hygiene, phishing defense, zero-trust principles
- Experience supporting a fully remote or distributed workforce.
- Excellent communication, leadership, and interpersonal skills.
Preferred (Nice to Have):- Experience in a law firm, legal technology, or professional services environment.
- Exposure to compliance frameworks (SOC 2, HIPAA, NIST CSF, or similar).
- Minimum of 1-3 years of experience in a leadership or management role, overseeing a team of IT professionals.
- Understanding of monitoring and logging tools (i.e. Nagios, Splunk, ELK stack).
- Scripting or automation experience (n8n, Python, Bash, Google Apps Script).
- Experience with cloud security posture management or SaaS security review.
- Demonstrated experience with disaster recovery planning and testing.
Who Thrives Here (Core Values)We don't hire on resumes alone. We hire for competence, character, and mindset.
- Embrace Change: Open to feedback, embracing change, and always asking "what's next?"
- Committed: You care deeply, have your teammates' backs, and show up to build something lasting.
- No-Ego Energy: Positive, professional, and solutions-oriented. Drama stays at the door.
- Ownership: You do what you say, follow through, and treat the business like it's yours.
- Fast & Hungry: You move with urgency, thrive under high expectations, and are motivated by growth and impact.
What We Offer- Base Salary: [Min} and [Max], commensurate with experience
- Eligible for performance-based bonus
- Our job postings reflect the compensation range for the specific market and location of each role. Ranges vary by geography based on local market rates and cost of labor.
- Benefits include: Medical, dental, and vision insurance, 401(k) with company match, HSA, life insurance, disability coverage, paid time off, and parental leave.
The pay range for this role is:
115,000 - 135,000 USD per year (Remote (United States))