Infrastructure & Security Engineer II

Schupan•Kalamazoo, MI
•Hybrid

About The Position

As our Infrastructure & Security Engineer II, you will own the health, security, and evolution of Schupan's Microsoft-based infrastructure across on-premises and cloud environments. Reporting to the VP of Strategy & Technology, you will be the hands-on engineer behind our servers, identity, and Microsoft 365 / Azure estate, and you will put commercial and open-source AI-enabled security tools to work, including automated penetration testing and vulnerability discovery, to find and fix weaknesses across a multi-site enterprise faster than manual methods allow.

Requirements

  • 5+ years of progressive experience in enterprise systems administration and infrastructure, including hands-on security responsibility.
  • Bachelor's degree in Computer Information Systems, Information Technology, Computer Science, or a related field preferred; equivalent combinations of education, certifications, and experience will be considered.
  • Expert-level administration of Microsoft 365, Entra ID, Exchange Online, Intune, and Azure in a hybrid environment.
  • Deep experience with Windows Server, Active Directory, Group Policy, DNS, DHCP, TCP/IP, and VMware vSphere/ESXi; Citrix DaaS experience a plus.
  • Proven track record leading complex server, tenant, and data migrations end to end.
  • Practical experience using AI-enabled security tools to improve enterprise security, such as automated penetration testing, vulnerability discovery, threat detection, or security reporting; building AI models is not required.
  • Strong working knowledge of Microsoft security tooling (Defender, Sentinel, Purview) and cybersecurity principles: identity and access management, least privilege, vulnerability management, logging and monitoring, and incident response.
  • Advanced PowerShell scripting and automation; experience with Microsoft Graph, APIs, or Python preferred.
  • Relevant certifications preferred, such as Microsoft Azure Administrator (AZ-104), Microsoft Security Operations Analyst (SC-200), Microsoft 365 Administrator (MS-102), or Security+/CISSP.
  • Working knowledge of Databricks administration and user management a plus.
  • Ability to communicate technical risks, security considerations, and recommendations clearly to non-technical and executive audiences.
  • Ability to work on site 3–4 days per week at our Wixom, Grand Rapids, or Kalamazoo, MI locations, including at least one full day per week in Kalamazoo.
  • Valid driver's license and willingness to drive regularly between Michigan sites, including trips of two or more hours each way (e.g., Wixom to Kalamazoo); mileage is reimbursed.
  • Frequently lift, carry, and move IT equipment weighing up to 25 pounds and occasionally up to 50 pounds.
  • Install, maintain, and troubleshoot equipment in data centers, telecommunications rooms, and office environments.
  • Prolonged periods of sitting, standing, and working at a computer workstation.

Nice To Haves

  • Citrix DaaS experience
  • Experience with Microsoft Graph, APIs, or Python
  • Microsoft Azure Administrator (AZ-104), Microsoft Security Operations Analyst (SC-200), Microsoft 365 Administrator (MS-102), or Security+/CISSP certifications
  • Working knowledge of Databricks administration and user management

Responsibilities

  • Administer and harden Microsoft 365, Microsoft Entra ID, Exchange Online, Intune, and Azure, including identity governance, Conditional Access, RBAC, and least-privilege access.
  • Manage Windows Server, Active Directory, Group Policy, DNS/DHCP, and virtualization (VMware vSphere/ESXi, Citrix DaaS) across hybrid on-premises and cloud environments.
  • Plan and execute server, tenant, mailbox, file, and data migrations with minimal business disruption, including cutover planning, validation, and rollback.
  • Use AI-enabled commercial and open-source tools to run automated penetration testing, vulnerability scanning, and attack-surface discovery across servers, endpoints, cloud resources, and identity, and drive the findings through to remediation.
  • Build continuous security monitoring, alerting, and reporting using existing tools (e.g., Microsoft Defender, Sentinel, Purview) and automate routine administration, compliance checks, and remediation with PowerShell, Microsoft Graph, and AI-assisted workflows, with appropriate human review and controls.
  • Lead vulnerability management, secure configuration baselines, endpoint protection, and patching across servers, workstations, and cloud resources.
  • Support incident detection, response, and post-incident root cause analysis, and turn findings into lasting preventive controls.
  • Produce clear, recurring security posture and risk reporting for IT leadership and executive stakeholders.
  • Evaluate emerging AI and security tools, recommend adoption, and set guardrails for responsible, secure use of AI in IT operations.
  • Maintain accurate documentation, runbooks, system inventories, and architecture diagrams.
  • Serve as a senior technical escalation point and mentor other IT team members.
  • Travel regularly between Schupan's Michigan sites for on-site work, projects, incidents, and meetings.
  • Perform other duties as assigned by the VP of Strategy & Technology.

Benefits

  • $85,000–$115,000/yr annual salary, based on experience and qualifications
  • Weekly pay
  • 16 days of PTO in your first year
  • 401(k) with match starting Day 1
  • Medical, dental, and vision coverage effective the 1st of the month after hire
  • HSA with company contribution of up to $1,500
  • FSA
  • Wellness premium discount
  • Company-paid life insurance
  • Short- and long-term disability
  • Parental leave
  • Tuition reimbursement
  • Pet insurance
  • Healthcare concierge
  • EAP
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service