About the RoleWe're hiring a Lead IT Engineer, Support to own identity, access, and security operations as FSAI takes IT fully in-house. This is the highest-stakes seat in the build: you're taking over Global Admin and Managed Detection & Response responsibility currently held by our outsourced provider, standing up the tools and governance that don't exist today, and setting the technical standard the rest of the team builds on. You report directly to the Head of IT, and you work closely with an IT Engineer, Support who owns endpoint, device, and network operations, so between the two of you, the full stack is covered.
This is a hands-on build role, not a pure architecture or oversight position. You're standing up real systems yourself in the first several months.
Responsibilities Identity & Access Administration
- Own Entra ID, SSO, and access governance end to end
- Lead the reconciliation of employee, contractor, and service accounts across Entra ID, our HRIS, and our contractor platform, closing gaps on stale, orphaned, or unauthorized access
- Build and maintain FSAI's identity and access inventory (systems, owners, user/admin counts, SSO/MFA/SCIM coverage) and run it on a quarterly access review cadence
- Own the privileged access review process for admin roles, taking that responsibility fully in-house from our outsourced provider
- Publish and enforce an SSO/MFA coverage standard across all critical business applications
- Select and roll out an Identity Governance & Administration (IGA) tool (net-new purchase, currently unselected)
Security Operations / Managed Detection & Response
- Own the transition of our outsourced provider's SOC coverage (Managed EDR, Managed ITDR, Managed SIEM) into an internally owned security operations capability. CrowdStrike (Falcon) is confirmed as our EDR platform, deployment and logging rollout are still in progress, this is the single highest-risk handover in the transition, since the outsourced provider currently holds Global Admin here
- Partner with the Security team and Head of IT on tool selection and coverage continuity during the transition
Governance, Risk & Compliance
- Co-author FSAI's core IT policy set (acceptable use, access control, device management, vendor review, incident response) with Security and Legal
- Own the evidence tracker mapping IT-owned controls to system owners, supporting our SOC 2, ISO 27001, and GDPR audit readiness
- Partner with Security and Legal on the due diligence process for new vendors and AI tooling, from intake through security review to contract
- Contribute to ratifying FSAI's IT operating model, RACI, and escalation paths as we formalize how the team runs
Documentation & Process
- Build the runbooks, documentation, and escalation model the team will run on once the outsourced provider steps back
- Rebuild the institutional knowledge currently held outside the company
Cross-Department Partnership
- Act as IT's standing partner to each business function, proactively improving how teams work with technology, not just closing tickets
- Provide hands-on support alongside teams, not from behind a queue
Vendor & Tool Ownership
- Own the transition's core tool stack in partnership with the Head of IT: MDM (FleetDM is the leading candidate, final platform selection in progress), Freshdesk (ticketing/help desk, confirmed), remote access/RMM (TeamViewer One vs. NinjaOne, tool decision still being finalized), and 1Password (password manager, migration off our current tool in progress)
Minimum Qualifications- 5+ years in IT or systems administration, including identity- or security-adjacent work
- Hands-on Microsoft 365 and Entra ID administration experience
- Experience reconciling identity data across multiple systems (HRIS, contractor platforms, directory services) to close access and offboarding gaps
- Familiarity with SOC/EDR/SIEM concepts and vendor management, even if you haven't operated these tools hands-on day to day
- Experience building documentation, runbooks, or operational process from scratch
- Strong experience partnering with non-IT stakeholders and business functions
Preferred Qualifications- Experience standing up an internal IT function previously run by an outsourced MSP
- Identity Governance & Administration (IGA) tool selection or implementation experience
- Experience scaling IT for a company growing from a few hundred to 700+ employees
- Scripting or automation experience (PowerShell, Python) to reduce manual IT work
- CISSP, CISM, Security+, or an identity-platform certification (Microsoft Entra, Okta, SailPoint, or similar)
- Experience supporting SOC 2, ISO 27001, or GDPR audit cycles, including evidence collection and control ownership