07 Aug
|
APG
|
New South Wales
07 Aug
APG
New South Wales
APG & Co is a leader in the Australian fashion industry, designing and managing Sportscraft, SABA and JAG.
For over 50 years, APG & Co has curated, grew and evolved these brands to be at the forefront of Australian fashion.
We celebrate our history while allowing our brands to express themselves in a contemporary, relevant and authentic way.
The working environment is agile, professional and passionate.
The mission: Bringing Style to Life.
APG & Co values working as a collective, thriving on change and playing to win.
We are built to last.
The Role
We're a small, hands‐on IT team at APG & Co looking for a multi‐skilled Systems Engineer who can genuinely span identity, endpoint, M365, Hybrid Active Directory, and security operations – not someone who has spent the last five years pigeonholed into one swim lane.
You'll be the technical 2IC across our Microsoft stack, splitting your time roughly ***** between BAU/Tier 3 escalations and project work (security uplift, new system rollouts, automation).
Because we're small, breadth matters more than deep specialization in any one area.
What You'll Own
Identity & Access – Entra ID, Conditional Access, MFA, PIM, app registrations, SSO
Endpoint Management – Intune policies, compliance, app deployment, Autopilot, Windows and mobile
Patch & Application Control – Endpoint Central (ManageEngine) for automated patching and application control across all endpoints; we own and manage the setup in‐house and log issues with the vendor when needed
Microsoft 365 Administration – Exchange Online, SharePoint, Teams, OneDrive (governance, mail flow, sharing, policies)
Hybrid Active Directory – managing AD as a single hybrid environment across on‐premises and Entra ID: GPOs, DNS, sites & services, replication, Entra Connect / sync, and identity flow between the two
Windows Server – patching, hardening, file/print, server‐level troubleshooting
Security Operations – work alongside our external SOC who lead incident triage; you'll be the internal point of contact, understand Defender XDR well enough to action SOC findings, and contribute to rule tuning, hardening, and Essential Eight uplift initiatives
Tier 3 Escalations – from the service desk, plus vendor and guest access management
Project Delivery – leading or contributing to new system rollouts, migrations, and security uplift initiatives
What You'll Work Alongside
These are managed by partners – you don't need hands‐on depth, but enough working knowledge to engage credibly and elevate well:
Network (WAN/LAN) – vendor‐managed
Virtualisation / IaaS (VMware) – vendor‐managed
Backup & DR – vendor‐managed; you'll monitor success and flag issues
Security Operations Centre (SOC) – external vendor leads incident triage and response
Must‐Have Skills & Experience
4–6 years in systems administration / Systems engineer roles, ideally in small‐to‐mid IT teams
Demonstrable breadth across Entra ID, Intune,
M365 admin (Exchange / SharePoint / Teams), and Hybrid Active Directory – not just one of these
Solid Windows Server administration
Good working knowledge of Defender XDR – enough to interpret SOC findings, action recommendations, and contribute to security uplift work
Awareness of Essential Eight and how it shapes day‐to‐day work
Experience with an enterprise patch / application control tool (Endpoint Central, Intune, SCCM, Tanium, or similar) – specific Endpoint Central experience is a bonus; a strong systems engineer will pick our setup up quickly
Strong troubleshooting instincts and clear communication – comfortable talking to vendors, business stakeholders, and the service desk
Nice to Have
PowerShell scripting (Graph, Entra, Intune, Exchange) – happy to develop this on the job
Microsoft certifications (e.g. MS-102, AZ-104, SC-200)
Exposure to ITIL / service management
Familiarity with PAM360 or other privileged access management tooling
Working knowledge of networking and VMware (enough to elevate well)
What Makes Someone Stand Out
We're a small team – the person who'll thrive here is a generalist by choice, comfortable shifting between Conditional Access tuning in the morning, a Hybrid AD replication issue at lunch, and an Intune deployment in the afternoon.
Perks & Benefits
50% off all our brands
Flexible working options – hybrid WFH and beautiful studio/office space
4pm Friday finishes and true work/life balance
Birthday leave + monthly social events, morning teas & more
Employee Assistance Program for you and your family
Paid Parental Leave
#J-*****-Ljbffr
📌 Systems Engineer (New South Wales)
🏢 APG
📍 New South Wales