IT Systems Engineer

First Due
$100,000Remote

About The Position

First Due is looking for a hands-on IT Systems Engineer to join our small but growing IT team. In this individual contributor role, you’ll own the day-to-day administration of our Microsoft 365 environment and core identity infrastructure. You’ll be an active contributor to the helpdesk team — owning a meaningful share of the incoming IT ticket queue alongside your teammates, while also serving as the senior technical resource who handles the most complex escalations and helps raise the team’s overall capability. You’ll work closely with the Director of Corporate IT on strategic initiatives including SSO and SaaS application governance, identity and access management, endpoint security, and compliance readiness. A near-term priority for this role is systematically onboarding our SaaS portfolio to SSO via Entra ID and building the automation that makes access provisioning reliable and auditable. This is a high-ownership role with real visibility across the organization.

Requirements

  • 4–6 years of hands-on experience in an IT systems or infrastructure role.
  • Solid working knowledge of Entra ID / Azure AD — user and group management, Conditional Access, MFA, app registrations.
  • Experience administering Microsoft 365 workloads (Exchange Online, Teams, SharePoint, OneDrive).
  • Solid experience with Intune for Windows device management; familiarity with macOS MDM platforms (Jamf or Kandji) a plus, as we plan to formalize macOS management going forward.
  • Proficiency with PowerShell for scripting and automation; Graph API experience (PowerShell or REST) a plus.
  • Experience integrating SaaS applications with an IdP via SSO (SAML/OIDC) and automating provisioning via SCIM — ideally at scale across 20+ applications.
  • Exposure to SOC 2 compliance processes — evidence gathering, policy documentation, or control testing.
  • Strong troubleshooting skills and ability to work independently in a remote environment.
  • All applicants must be authorized to work for any US employer in the United States.
  • Hiring is contingent upon candidates successfully passing a criminal background check.
  • As part of the I-9 verification of authorization to work in the US, Locality Media participates in E-Verify.

Nice To Haves

  • Microsoft certifications (MS-102, AZ-104, SC-300, or similar) a plus.
  • Experience with Microsoft Purview (DLP, sensitivity labels, compliance policies, eDiscovery) a plus.
  • Experience governing AI productivity tools (any platform) — access management, acceptable use policy enforcement, or usage visibility — a plus.
  • Background in government technology, public safety, or other regulated environments a plus.
  • Familiarity with FedRAMP compliance requirements or experience supporting a FedRAMP authorization effort a plus.

Responsibilities

  • Build and maintain PowerShell and Graph API scripts to automate onboarding, offboarding, and access provisioning workflows.
  • Identify manual IT processes and reduce toil through scripting and workflow tooling (e.g., Power Automate).
  • Own and systematically expand our SSO integration program — evaluate existing SaaS applications, prioritize SAML/OIDC integrations via Entra ID, and build automated provisioning/deprovisioning workflows (SCIM where supported).
  • Maintain a SaaS application catalog — tracking ownership, license counts, renewal dates, and SSO/MFA status across the organization’s tool portfolio.
  • Serve as a senior technical lead for Entra ID (Azure AD) — partnering with the team to manage user lifecycle, group management, Conditional Access policies, and MFA enforcement.
  • Drive SSO integration across SaaS applications using SAML/OIDC via Entra ID.
  • Implement and maintain least-privilege access principles across the tenant; support ongoing access reviews.
  • Contribute to Zero Trust architecture initiatives in partnership with the IT Director.
  • Administer and mature our MDM platform (Intune) for Windows devices, ensuring device compliance, configuration, and security baselines; contribute to the evaluation and implementation of a dedicated macOS MDM solution (e.g., Jamf or Kandji) as the Mac fleet grows.
  • Manage device lifecycle: procurement, provisioning, compliance enforcement, and decommission.
  • Develop and maintain configuration profiles, compliance policies, and device health reporting.
  • Administer core M365 workloads: Exchange Online, Teams, SharePoint, OneDrive, and Defender.
  • Manage licensing, provisioning workflows, and tenant-wide security configurations.
  • Support email security infrastructure (SPF, DKIM, DMARC) and respond to mail flow issues.
  • Support SOC 2 compliance efforts by maintaining system documentation, generating audit evidence, and remediating findings.
  • Participate in security reviews, vulnerability assessments, and policy enforcement activities.
  • Collaborate with the security function on DLP policies, CASB configurations, and data governance.
  • Support the governance of AI productivity tools across the organization — managing access, tracking usage, and coordinating with department leads as our AI toolset evolves.
  • Establish and maintain an AI application vetting process — evaluate third-party AI tools for data handling risk, enforce acceptable use policies, and maintain visibility into AI usage across the org.
  • Configure Purview sensitivity labels and DLP policies to prevent oversharing of data through AI tools and other collaboration surfaces.
  • Carry an active share of the IT helpdesk ticket queue alongside the team — handling Tier 2/3 issues directly while serving as the go-to escalation point for the most complex cases and coaching teammates through them.
  • Help define and refine helpdesk processes, runbooks, and escalation paths.
  • Contribute to IT documentation, KB articles, and internal training materials.

Benefits

  • competitive pay
  • medical, dental, and vision coverage
  • FSA/HSA
  • 401(k)
  • flexible PTO
  • a fully remote workplace
  • a technology stipend
  • opportunities for advancement
  • other benefits and perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service