系统工程师
Systems Engineer
关于Infiterra
加入我们的使命,通过简化订阅服务交付来推动和变革订阅经济。
Infiterra使IT分销商、托管服务提供商(MSP)和电信公司能够在订阅经济中取得成功。我们的订阅商务平台自动化并统一订阅流程——从报价到账单——提升运营效率、计费准确性和可扩展增长。
作为全球订阅商务领域的领导者,Infiterra结合创新、卓越的性能和值得信赖的专业知识,帮助合作伙伴实现转型和增长。
职位描述
我们正在招聘一名中级系统工程师,负责Infiterra内部IT环境的直接管理。该职位涉及Microsoft 365和Entra ID管理、终端和系统管理、员工IT支持、访问和安全控制以及自动化。
您的任务是为Infiterra员工提供安全、可靠且日益自动化的公司IT服务。您将负责日常企业IT运营,同时提升自动化、身份和访问管理、终端管理、员工生命周期流程和服务质量。
此外,您将有机会帮助该职能从主要的运营支持转变为标准化、安全且日益自动化的内部IT服务。这不是一个L1支持职位——支持是工作的一部分,但该职位的核心是将内部IT工程化并作为可扩展的服务进行运营。
主要职责
身份与访问管理
· 保持企业身份在Entra ID / Azure AD中准确、组织良好且易于审计。
- 构建用户、组和角色,使其清晰映射业务实际运作方式。
- 提供安全、低摩擦的多因素认证(MFA)和单点登录(SSO),并由条件访问策略支持,防止未经授权的访问。
- 在有人需要时立即授予访问权限,并在其不再需要时立即撤销。
- 严格控制特权账户,确保没有遗留或未使用的高权限访问。
- 通过定期审查捕捉并纠正访问偏差,防止其成为风险。
- 作为安全团队的可靠合作伙伴,参与制定和验证访问策略决策。
员工生命周期
· 负责技术入职、角色/权限变更和离职流程,确保无遗漏。
- 让每位新员工从第一天起就能高效工作,确保他们在入职前就拥有账户、设备和应用程序,并在雇佣结束时立即切断访问权限
查看英文原文
About Infiterra
Join our mission to grow and transform the subscription economy by simplifying subscription service delivery.
Infiterra enables IT distributors, Managed Service Providers (MSPs), and telcos to succeed in the subscription economy. Our subscription commerce platform automates and unifies subscription workflows - from quote to bill- driving operational efficiency, billing accuracy, and scalable growth.
Recognized as a global leader in subscription commerce, Infiterra combines innovation, performance excellence, and trusted expertise to help partners transform and grow.
About the Role
We are hiring a mid-level Systems Engineer to take hands-on ownership of Infiterra’s internal IT environment. The role combines Microsoft 365 and Entra ID administration, endpoint and systems management, employee IT support, access and security controls, and automation.
Your mission is to provide secure, reliable and increasingly automated corporate IT services to Infiterra employees. You will own day-to-day corporate IT operations while improving automation, identity and access management, endpoint management, employee lifecycle processes and service quality.
Moreover, you will have the opportunity to help evolve the function from largely operational support into a standardized, secure and increasingly automated internal IT service. This is not an L1 support position — support is part of the job, but the purpose of the role is to engineer and operate Internal IT as a scalable service.
Key Responsibilities
Identity & Access Management
· Keep corporate identities in Entra ID / Azure AD accurate, well-organized and easy to audit.
- Structure users, groups and roles so they map cleanly to how the business actually works.
- Deliver secure, low-friction MFA and SSO, backed by Conditional Access policies that keep unauthorized access out.
- Grant access the moment someone needs it, and revoke it the moment they no longer do.
- Keep privileged accounts tightly controlled, with no lingering or unused elevated access.
- Catch and correct access drift through regular reviews, before it becomes a risk.
- Act as Security's reliable partner in shaping and validating access policy decisions.
Employee Lifecycle
· Own the technical onboarding, role/access changes and offboarding process and run without gaps.
- Get every new employee productive from day one, with accounts, devices and applications ready before they start, and cut off access immediately once employment ends.
Endpoint & Device Management
· Keep every company laptop on the security baseline and current on patches, without employees ever noticing the effort behind it.
- Keep the device fleet fully accounted for, replace ageing hardware before it becomes a problem, and stay audit-ready on compliance reporting.
Corporate Systems & SaaS Administration
· Keep the internal Microsoft / Azure environment and core SaaS applications running reliably, with no unplanned downtime or configuration drift.
- Keep licensing spend, permissions and integrations accurate and well documented, so there's never confusion about who owns what.
Internal Support & Service Management
· Give employees fast, dependable help when something breaks, and make sure they always know exactly where to turn.
- Meet SLAs consistently, so waiting on IT is never the reason work stalls.
- Grow a knowledge base that resolves issues faster over time, instead of solving them from memory each time.
- Fix recurring issues at the root, so ticket volume trends down instead of repeating.
Security & Compliance Operations
· Keep access evidence, endpoint compliance, asset inventories and account lifecycle records ready to hand over for an ISO 27001 or SOC 2 audit.
- Run IT controls reliably day to day, giving Security confidence in the operational layer without having to manage it themselves.
Ideal Candidate Profile
· A Systems Engineer with hands-on Internal IT operations experience, comfortable across Microsoft 365, Azure and endpoint management.
- A structured problem solver who gets to the root cause instead of repeating the workaround.
- A clear communicator who can support colleagues of all technical levels.
- An ownership mindset: you take a process end to end and improve it as you go.
- Able to document decisions, processes and runbooks so the service does not depend on one person.
- Motivated by automation and standardization, and genuinely interested in employee IT and service delivery.
Requirements
· 3–6 years of experience in Internal IT and/or Systems Administration.
- Microsoft Entra ID administration.
- Microsoft 365 administration.
- Windows endpoint administration.
- Windows Server administration.
- PowerShell or equivalent automation.
- Basic networking: DNS, DHCP, VPN, TCP/IP and routing concepts.
- Security fundamentals: least privilege, patching, endpoint protection and access controls.
- IT asset and inventory management.
- IT troubleshooting and incident management.
- Documentation and runbook discipline.
Nice to Have
Experience with the following technologies, tools and applications is considered a strong advantage:
· Microsoft Intune.
- Conditional Access.
- Microsoft Defender ecosystem.
- Apple / macOS device management.
- Azure administration.
- Jira, Confluence and Jira Service Management.
- Experience working in an ISO 27001 or SOC 2 environment.
Benefits
- Fully remote work.
- Work-from-anywhere scheme (travel and work).
- Flexible working hours.
- Learning & development budget.
- Collaborative, tech-driven team culture with international diversity.
If you feel you’re a great fit, please apply!
We’d love to hear from you!
All applications will be treated confidentially. Due to the high volume of applications, only shortlisted candidates will be contacted for an interview.
As part of our commitment to diversity in the workforce, Infiterra is dedicated to Equal Employment Opportunity, ensuring that all individuals are treated with respect and consideration without regard to race, color, national origin, ethnicity, gender, disability, sexual orientation, gender identity, or religion.
Originally posted on Himalayas