IT Systems Engineer New Remote - US Only
San Diego, San Diego County, California, 92189, USA
Listed on 2026-08-02
-
IT/Tech
Cybersecurity, Systems Administrator, Information Security & Data Protection, IT Support
First Due’s mission is to prevent first responder injury or death by providing fire and EMS agencies with transformative, end-to-end software solutions that empower them to run safer, smarter, and more effective operations.
Job Title:IT Systems Engineer
Location
:
Remote - US Only
Country
:
United States
Department
:
Corporate IT
Reports To
:
Director of Corporate IT
Position Type
:
Full-Time
Salary
: $100,000
First Due is looking for a hands-on IT Systems Engineer to join our small but growing IT team. In this individual contributor role, you’ll own the day-to-day administration of our Microsoft 365 environment and core identity infrastructure. You’ll be an active contributor to the helpdesk team — owning a meaningful share of the incoming IT ticket queue alongside your teammates, while also serving as the senior technical resource who handles the most complex escalations and helps raise the team’s overall capability.
You’ll work closely with the Director of Corporate IT on strategic initiatives including SSO and SaaS application governance, identity and access management, endpoint security, and compliance readiness. A near-term priority for this role is systematically onboarding our SaaS portfolio to SSO via Entra building the automation that makes access provisioning reliable and auditable. This is a high-ownership role with real visibility across the organization.
Key Responsibilities:Automation, Scripting & SaaS Governance
- Build and maintain Power Shell and Graph API scripts to automate onboarding, offboarding, and access provisioning workflows.
- Identify manual IT processes and reduce toil through scripting and workflow tooling (e.g., Power Automate).
- Own and systematically expand our SSO integration program — evaluate existing SaaS applications, prioritize SAML/OIDC integrations via Entra , and build automated provisioning/deprovisioning workflows (SCIM where supported).
- Maintain a SaaS application catalog — tracking ownership, license counts, renewal dates, and SSO/MFA status across the organization’s tool portfolio.
Identity & Access Management
- Serve as a senior technical lead for Entra (Azure AD) — partnering with the team to manage user lifecycle, group management, Conditional Access policies, and MFA enforcement.
- Drive SSO integration across SaaS applications using SAML/OIDC via Entra .
- Implement and maintain least-privilege access principles across the tenant; support ongoing access reviews.
- Contribute to Zero Trust architecture initiatives in partnership with the IT Director.
- Administer and mature our MDM platform (Intune) for Windows devices, ensuring device compliance, configuration, and security baselines; contribute to the evaluation and implementation of a dedicated macOS MDM solution (e.g., Jamf for Kandji) as the Mac fleet grows.
- Manage device lifecycle: procurement, provisioning, compliance enforcement, and decommission.
- Develop and maintain configuration profiles, compliance policies, and device health reporting.
Microsoft 365 Administration
- Administer core M365 workloads:
Exchange Online, Teams, SharePoint, One Drive, and Defender. - Manage licensing, provisioning workflows, and tenant-wide security configurations.
- Support email security infrastructure (SPF, DKIM, DMARC) and respond to mail flow issues.
Compliance & Security
- Support SOC 2 compliance efforts by maintaining system documentation, generating audit evidence, and remediating findings.
- Participate in security reviews, vulnerability assessments, and policy enforcement activities.
- Collaborate with the security function on DLP policies, CASB configurations, and data governance.
AI Tool Governance
- Support the governance of AI productivity tools across the organization — managing access, tracking usage, and coordinating with department leads as our AI toolset evolves.
- Establish and maintain an AI application vetting process — evaluate third-party AI tools for data handling risk, enforce acceptable use policies, and maintain visibility into AI usage across the org.
- Configure Purview sensitivity labels and DLP policies to prevent oversharing of data through AI tools and other collaboration surfaces.
Helpdesk & Team Support
- Carry an active…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).