06 Aug
|
APG
|
Bayside Council
06 Aug
APG
Bayside Council
APG & Co is a leader in the Australian fashion industry, designing and managing Sportscraft, SABA and JAG. For over 50 years, APG & Co has curated, grew and evolved these brands to be at the forefront of Australian fashion. We celebrate our history while allowing our brands to express themselves in a contemporary, relevant and authentic way.
The working environment is energetic, professional and passionate. The mission: Bringing Style to Life. APG & Co values working as a collective, thriving on change and playing to win. We are built to last.
The Role
We’re a small, hands‑on IT team at APG & Co looking for a multi‑skilled Systems Engineer who can genuinely span identity, endpoint, M365, Hybrid Active Directory, and security operations – not someone who has spent the last five years pigeonholed into one swim lane.
You’ll be the technical 2IC across our Microsoft stack, splitting your time roughly 50/50 between BAU/Tier 3 escalations and project work (security uplift, new system rollouts, automation). Because we’re small, breadth matters more than deep specialization in any one area.
What You’ll Own
- Identity & Access – Entra ID, Conditional Access, MFA, PIM, app registrations, SSO
- Endpoint Management – Intune policies, compliance, app deployment, Autopilot, Windows and mobile
- Patch & Application Control – Endpoint Central (ManageEngine) for automated patching and application control across all endpoints; we own and manage the setup in‑house and log issues with the vendor when needed
- Microsoft 365 Administration – Exchange Online, SharePoint, Teams, OneDrive (governance, mail flow, sharing, policies)
- Hybrid Active Directory – managing AD as a single hybrid environment across on‑premises and Entra ID: GPOs, DNS, sites & services, replication, Entra Connect / sync, and identity flow between the two
- Windows Server – patching, hardening, file/print, server‑level troubleshooting
- Security Operations – work alongside our external SOC who lead incident triage; you’ll be the internal point of contact, understand Defender XDR well enough to action SOC findings, and contribute to rule tuning, hardening, and Essential Eight uplift initiatives
- Tier 3 Escalations – from the service desk, plus vendor and guest access management
- Project Delivery – leading or contributing to current system rollouts, migrations, and security uplift initiatives
What You’ll Work Alongside
These are managed by partners – you don’t need hands‑on depth, but enough working knowledge to engage credibly and elevate well:
- Network (WAN/LAN) – vendor‑managed
- Virtualisation / IaaS (VMware) – vendor‑managed
- Backup & DR – vendor‑managed; you’ll monitor success and flag issues
- Security Operations Centre (SOC) – external vendor leads incident triage and response
Must‑Have Skills & Experience
- 4–6 years in systems administration / Systems engineer roles, ideally in small‑to‑mid IT teams
- Demonstrable breadth across Entra ID, Intune, M365 admin (Exchange / SharePoint / Teams),
and Hybrid Active Directory – not just one of these
- Solid Windows Server administration
- Valuable working knowledge of Defender XDR – enough to interpret SOC findings, action recommendations, and contribute to security uplift work
- Awareness of Essential Eight and how it shapes day‑to‑day work
- Experience with an enterprise patch / application control tool (Endpoint Central, Intune, SCCM, Tanium, or similar) – specific Endpoint Central experience is a bonus; a strong systems engineer will pick our setup up quickly
- Strong troubleshooting instincts and clear communication – comfortable talking to vendors, business stakeholders, and the service desk
Nice to Have
- PowerShell scripting (Graph, Entra, Intune, Exchange) – happy to develop this on the job
- Microsoft certifications (e.g. MS-102, AZ-104, SC-200)
- Exposure to ITIL / service management
- Familiarity with PAM360 or other privileged access management tooling
- Working knowledge of networking and VMware (enough to elevate well)
What Makes Someone Stand Out
We’re a small team – the person who’ll thrive here is a generalist by choice, comfortable shifting between Conditional Access tuning in the morning, a Hybrid AD replication issue at lunch, and an Intune deployment in the afternoon.
Perks & Benefits
- 50% off all our brands
- Flexible working options – hybrid WFH and beautiful studio/office space
- 4pm Friday finishes and true work/life balance
- Birthday leave + monthly social events, morning teas & more
- Employee Assistance Program for you and your family
- Paid Parental Leave
#J-18808-Ljbffr
📌 Systems Engineer (Bayside Council)
🏢 APG
📍 Bayside Council