Job Description
APG & Co is a leader in the Australian fashion industry, designing and managing Sportscraft, SABA and JAG. For over 50 years, APG & Co has curated, grew and evolved these brands to be at the forefront of Australian fashion. We celebrate our history while allowing our brands to express themselves in a contemporary, relevant and authentic way.
/n
The working environment is dynamic, professional and passionate. The mission: Bringing Style to Life. APG & Co values working as a collective, thriving on change and playing to win. We are built to last.
/n
The Role
/n
We're a small, hands‐on IT team at APG & Co looking for a multi‐skilled Systems Engineer who can genuinely span identity, endpoint, M365, Hybrid Active Directory, and security operations – not someone who has spent the last five years pigeonholed into one swim lane.
/n
You'll be the technical 2IC across our Microsoft stack, splitting your time roughly 50/50 between BAU/Tier 3 escalations and project work (security uplift, new system rollouts, automation). Because we're small, breadth matters more than deep specialization in any one area.
/n
What You'll Own
/n
/n
- Identity & Access – Entra ID, Conditional Access, MFA, PIM, app registrations, SSO
/n
- Endpoint Management – Intune policies, compliance, app deployment, Autopilot, Windows and mobile
/n
- Patch & Application Control – Endpoint Central (Manage Engine) for automated patching and application control across all endpoints; we own and manage the setup in‐house and log issues with the vendor when needed
/n
- Microsoft 365 Administration – Exchange Online, Share Point, Teams, One Drive (governance, mail flow, sharing, policies)
/n
- Hybrid Active Directory – managing AD as a single hybrid environment across on‐premises and Entra ID: GPOs,
DNS, sites & services, replication, Entra Connect / sync, and identity flow between the two
/n
- Windows Server – patching, hardening, file/print, server‐level troubleshooting
/n
- Security Operations – work alongside our external SOC who lead incident triage; you'll be the internal point of contact, understand Defender XDR well enough to action SOC findings, and contribute to rule tuning, hardening, and Essential Eight uplift initiatives
/n
- Tier 3 Escalations – from the service desk, plus vendor and guest access management
/n
- Project Delivery – leading or contributing to new system rollouts, migrations, and security uplift initiatives
/n/n
What You'll Work Alongside
/n
These are managed by partners – you don't need hands‐on depth, but enough working knowledge to engage credibly and elevate well:
/n
/n
- Network (WAN/LAN) – vendor‐managed
/n
- Virtualisation / IaaS (VMware) – vendor‐managed
/n
- Backup & DR – vendor‐managed; you'll monitor success and flag issues
/n
- Security Operations Centre (SOC) – external vendor leads incident triage and response
/n/n
Must‐Have Skills & Experience
/n
/n
- 4–6 years in systems administration / Systems engineer roles, ideally in small‐to‐mid IT teams
/n
- Demonstrable breadth across Entra ID, Intune, M365 admin (Exchange / Share Point / Teams),
and Hybrid Active Directory – not just one of these
/n
- Solid Windows Server administration
/n
- Good working knowledge of Defender XDR – enough to interpret SOC findings, action recommendations, and contribute to security uplift work
/n
- Awareness of Essential Eight and how it shapes day‐to‐day work
/n
- Experience with an enterprise patch / application control tool (Endpoint Central, Intune, SCCM, Tanium, or similar) – specific Endpoint Central experience is a bonus; a strong systems engineer will pick our setup up quickly
/n
- Robust troubleshooting instincts and clear communication – comfortable talking to vendors, business stakeholders, and the service desk
/n/n
Nice to Have
/n
/n
- Power Shell scripting (Graph, Entra, Intune, Exchange) – happy to develop this on the job
/n
- Microsoft certifications (e.g. MS-102, AZ-104, SC-200)
/n
- Exposure to ITIL / service management
/n
- Familiarity with PAM360 or other privileged access management tooling
/n
- Working knowledge of networking and VMware (enough to elevate well)
/n/n
What Makes Someone Stand Out
/n
We're a small team – the person who'll thrive here is a generalist by choice, comfortable shifting between Conditional Access tuning in the morning, a Hybrid AD replication issue at lunch, and an Intune deployment in the afternoon.
/n
Perks & Benefits
/n
/n
- 50% off all our brands
/n
- Flexible working options – hybrid WFH and beautiful studio/office space
/n
- 4pm Friday finishes and true work/life balance
/n
- Birthday leave + monthly social events, morning teas & more
/n
- Employee Assistance Program for you and your family
/n
- Paid Parental Leave
/n #J-18808-Ljbffr
📌 Systems Engineer (Tamworth)
🏢 APG
📍 Tamworth