This role owns IT and corporate engineering at Flex, end to end. It reports directly to the CTO. We think IT's job is enablement. The measure of this function is not how many tickets it closes or how many controls it can point at. It is whether everyone else at Flex can do their work faster and more safely than they could last quarter. A new hire productive on day one instead of day four. An engineer who gets exactly the access they need in minutes, without asking twice and without being handed the keys to everything. A team that can adopt a new tool because someone reviewed it properly, not because they routed around IT to buy it on a personal card. So we are not looking for a gatekeeper, or for someone whose default answer is no. The right person makes the safe path the easy path, and removes friction permanently instead of absorbing it repeatedly. Which is why this role also owns Flex's corporate security posture. Identity, access, endpoints, and the SaaS estate are one system, and the person who makes access fast should be the person who decides how much access is reasonable. Split those across two teams and employees route around both. You'll set conditional access and MFA policy, own privileged access and endpoint posture, and run third-party OAuth and Workspace grant review. Our security engineers own the product and infrastructure side, the money paths and the code, and you'll work with them constantly. Corporate security is yours to decide, not to implement on someone else's behalf. This is the hard part of the job, and we'd rather say so than leave it as a bonus line. The argument between moving fast and holding a line is now an argument you have with yourself. Day to day, what gets tightened, what gets mitigated, and what we knowingly accept is your call; the large ones come to the CTO, and we'd rather see a close call early than find out you decided it quietly. What we'd ask is that a no comes from a real read of the risk and the business context rather than a standard applied by default. The rest of the work has two halves. The IT half is the fleet, identity, access, the SaaS estate, and the joiner/mover/leaver process, delivered with help from a managed IT partner who handles procurement, device logistics, tier-1 support, and international coverage. You own that relationship, define the SLA, and enforce it. The corporate engineering half is the part we think makes this a good job: writing the automation and internal tooling that means the IT half doesn't scale linearly with headcount. If a process only works because a person runs it by hand every Tuesday, we'd rather you replaced it. You'd be inheriting an estate here, not starting one. The first year is as much untangling what has already accumulated - stale access, tools nobody reviewed, processes that work because someone remembers them - as it is building what comes next. Automate that assessment. Nobody should be reading through a SaaS estate by hand in 2026. Now the shape of this. Flex is around 150 people, and you would be the only person in this function, with vendor capacity underneath you and a direct line to the CTO. That means real autonomy and real scope from week one. It also means this is a hands-on senior individual contributor role, not a management role, and we are not planning a team under it in the near term. If you're looking to build and lead an IT organization right now, this isn't that job, and we'd rather you knew before you applied. We're looking for an IT and corporate engineering builder who wants to own security posture, rather than a security specialist willing to cover IT. Both halves have to interest you. If the enablement work reads as the price of admission for the security work, this will be a frustrating job.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed