Full Job Description
M1 is hiring a senior IT systems engineer to operate, secure, and continuously improve the IT environment our employees depend on every day, including but not limited to identity and access systems, endpoint management, office infrastructure in Chicago, and the org's SaaS productivity stack. M1 is a fintech firm operating in a heavily regulated industry as a self-clearing broker-dealer, so this environment operates under continuous regulatory security and audit obligations. You'll join M1's IT and Security team, own the engineering and security behind this environment, and partner across Compliance, Engineering, and the wider business.
We're looking for people energized by solving real problems and having impact, not just by working with interesting technology. You bring real engineering discipline to your work: version control, testing, documentation, and following through until the work is fully done. You automate the toil worth automating rather than than brute-force the same problem twice. You reach for the right tool for the job, and are comfortable dabbling across the stack: in scripts, APIs, and config-as-code. You embrace and use AI judiciously to learn and to move quickly, and exercise good judgment on outputs.
What You'll Do
• Lead identity and access engineering in Okta, our primary IdP: designing SSO, MFA, provisioning and deprovisioning, groups, and access policies around least privilege and separation of duties.
• Continuously reduce toil across the environment: automating repetitive provisioning, configuration, and reporting, integrating tools so the same work is never done twice by hand, and maintaining the documentation and runbooks that spread knowledge across the team and cut down common support requests.
• Own the security of the IT environment, including but not limited to vulnerability and patch management, endpoint hardening, and a hands-on role in detecting and responding to issues.
• Own the engineering behind workforce enablement: configure and run the SaaS platforms employees depend on and the vendor relationships behind them, manage endpoints (macOS and Windows), and automate onboarding and offboarding so the employee experience scales without adding headcount.
• Keep the control environment healthy and provable: run access reviews, maintain configuration standards, asset inventory, and logging, produce the evidence internal and external auditors rely on, and be ready to show how a control actually works.
• Serve as escalation path for employee IT support and the Chicago office: fix root causes instead of reworking tickets, and keep the office network, meeting room AV, and physical security (badge access, cameras) running and support in person company events.
Qualifications
• 5+ years in IT systems engineering or administration, with a track record of owning and improving major parts of an environment independently.
• Evidence you can go deep: a system you owned end to end and made materially better, and how you found it, what you changed, and how you knew it worked. Going deep somewhere matters more to us than matching every line below.
• Comfortable with scripting and automation (PowerShell, Bash, Python, or similar), REST APIs, and config-as-code, applied with an engineer's discipline - source control, meaningful tests, documentation others can follow, and repeatable, auditable processes.
• Depth in several of: Okta, SSO, MFA, and identity lifecycle; macOS and Jamf; Microsoft 365; SaaS administration and integration; networking; endpoint security and patching; virtualization and VDI; IT asset lifecycle.
• Hands-on experience designing and operating a hardened office environment: networking and on-prem infrastructure (LAN and Wi-Fi, switching, firewalls, VPN) plus physical devices like badge and camera systems, and meeting-room AV.
• Experience in a regulated, security-conscious, or highly available environment; financial services helpful, not required.
Salary Band: $100,000 - $130,000
Our Perks
• Competitive Pay and Stock Options
• Comprehensive health, dental, vision, disability, and life insurance
• Retirement benefit with employer match
• Unlimited PTO
• Transparent and open communication with leadership