Position Summary
The IT Systems Engineer is a full-time role reporting to the Head of Platform. This is a senior individual contributor position and the company's first dedicated IT hire. The role owns the design, build, and day-to-day operation of ENGIN's corporate technology environment, with a primary focus on the Microsoft 365 and Entra ID ecosystem, endpoint fleet management, and identity and access administration. Technical direction is set by the Head of Platform; the IT Systems Engineer brings specialist expertise and carries out the implementation. Strong hands-on Microsoft ecosystem capability is required for this role.
This is a full-time, fully remote position with a preference for candidates based in Calgary or Toronto. Only candidates located in Canada with work authorization (Citizenship, PR, or Open Work Permit) will be considered.
Role/Responsibilities:
- Design, build, and maintain the Microsoft 365 tenant architecture and configuration.
- Administer Entra ID as the organization's identity provider:
- Design and maintain conditional access policy, MFA enforcement, and privileged access controls.
- Maintain group-based entitlement and licensing structures that scale with headcount.
- Support SSO integrations into client environments in coordination with the Development and DevOps teams.
- Own the endpoint fleet end to end across macOS and Windows:
- Procurement, imaging, MDM enrollment, and configuration baseline.
- Patch compliance, disk encryption enforcement, and remediation of non-compliant devices.
- Warranty, refresh cycle, and secure disposal.
- Design and automate joiner, mover, and leaver processes:
- Account provisioning, hardware logistics and shipping, and first-day setup.
- Same-day deprovisioning of accounts and access on employee exit.
- Ensure these processes generate their own records rather than depending on manual documentation.
- Automate recurring administrative work using PowerShell and Microsoft Graph; maintain scripts in version control with documentation.
- Maintain the SaaS application inventory, optimize licensing, manage renewals, and identify unsanctioned applications.
- Provide day-to-day technical support to staff, and produce the runbooks and documentation required for the environment to be maintainable by others.
- Offer suggestions and opinions on technical solutioning; identify and quantify technical debt within the corporate environment.
The ideal candidate will have:
- Minimum Bachelor's Degree in Information Technology, Computer Science, or equivalent practical experience
- 6-10+ years in corporate IT, systems administration, or systems engineering in a professional environment
- Demonstrated experience building or rebuilding a Microsoft 365 environment, rather than maintaining one inherited in good order
- Experience in Microsoft ecosystem administration including:
- Entra ID: conditional access, MFA policy, group and licensing structure, application registrations, and SSO integrations
- Microsoft Intune: device enrollment, configuration profiles, application deployment, patch compliance, and encryption enforcement
- Exchange Online, SharePoint, and Teams administration and governance
- Experience managing a mixed macOS and Windows endpoint fleet
- Automation capability using PowerShell and the Microsoft Graph API
- Experience as the primary or sole IT function at an organization of approximately 30-150 people
- Sound judgment in sequencing change within a live production environment: what to fix first, what to defer, and how to avoid disrupting the business
- Ability to work independently and as part of a team; a self-starter, comfortable working with complex systems, eager to take on a wide range of responsibilities
It would be great if you also have:
- Experience within an organization operating under ISO 27001 or SOC 2, and an understanding of how IT systems produce audit evidence
- Experience with Microsoft Defender and Microsoft Purview
- Experience supporting a technically sophisticated user base of software engineers
- Exposure to common cloud services and an understanding of how corporate identity integrates with cloud workloads
What we offer:
- Fully remote work, with the option of working from one of our offices in Calgary or Toronto.
- Flexible work hours (Core working hours 10:00AM to 3:00PM in your local time zone).
- Autonomy with a wide range of responsibilities, opportunities for advancement, and cross-disciplinary exposure.
- Competitive base salary plus performance incentives.
- Stock options so you can realize the value created with your work in the organization.
- 10 paid sick days per year
- Comprehensive benefits, including health and dental