14 Aug
|
APG
|
New South Wales
14 Aug
APG
New South Wales
APG & Co is a leader in the Australian fashion industry, designing and managing Sportscraft, SABA and JAG. For over 50 years, APG & Co has curated, grew and evolved these brands to be at the forefront of Australian fashion. We celebrate our history while allowing our brands to express themselves in a contemporary, relevant and authentic way.
The working environment is agile, professional and passionate. The mission: Bringing Style to Life. APG & Co values working as a collective, thriving on change and playing to win. We are built to last.
The Role
We're a small, hands‐on IT team at APG & Co looking for a
multi‐skilled Systems Engineer
who can genuinely span identity, endpoint, M365, Hybrid Active Directory, and security operations – not someone who has spent the last five years pigeonholed into one swim lane.
You'll be the technical 2IC across our Microsoft stack, splitting your time roughly ***** between BAU/Tier 3 escalations and project work (security uplift, new system rollouts, automation). Because we're small, breadth matters more than deep specialization in any one area.
What You'll Own
Identity & Access
– Entra ID, Conditional Access, MFA, PIM, app registrations, SSO
Endpoint Management
– Intune policies, compliance, app deployment, Autopilot, Windows and mobile
Patch & Application Control
– Endpoint Central (ManageEngine) for automated patching and application control across all endpoints; we own and manage the setup in‐house and log issues with the vendor when needed
Microsoft 365 Administration
– Exchange Online, SharePoint, Teams, OneDrive (governance, mail flow, sharing, policies)
Hybrid Active Directory
– managing AD as a single hybrid environment across on‐premises and Entra ID: GPOs, DNS, sites & services, replication, Entra Connect / sync, and identity flow between the two
Windows Server
– patching, hardening, file/print, server‐level troubleshooting
Security Operations
– work alongside our external SOC who lead incident triage; you'll be the internal point of contact, understand Defender XDR well enough to action SOC findings, and contribute to rule tuning, hardening, and Essential Eight uplift initiatives
Tier 3 Escalations
– from the service desk, plus vendor and guest access management
Project Delivery
– leading or contributing to new system rollouts, migrations, and security uplift initiatives
What You'll Work Alongside
These are managed by partners – you don't need hands‐on depth, but enough working knowledge to engage credibly and elevate well:
Network (WAN/LAN)
– vendor‐managed
Virtualisation / IaaS (VMware)
– vendor‐managed
Backup & DR
– vendor‐managed; you'll monitor success and flag issues
Security Operations Centre (SOC)
– external vendor leads incident triage and response
Must‐Have Skills & Experience
4–6 years in systems administration / Systems engineer roles, ideally in small‐to‐mid IT teams
Demonstrable
breadth
across Entra ID, Intune,
M365 admin (Exchange / SharePoint / Teams), and
Hybrid Active Directory
– not just one of these
Solid Windows Server administration
Good working knowledge of Defender XDR – enough to interpret SOC findings, action recommendations, and contribute to security uplift work
Awareness of
Essential Eight
and how it shapes day‐to‐day work
Experience with an enterprise patch / application control tool (Endpoint Central, Intune, SCCM, Tanium, or similar) – specific Endpoint Central experience is a bonus; a strong systems engineer will pick our setup up quickly
Strong troubleshooting instincts and clear communication – comfortable talking to vendors, business stakeholders, and the service desk
Nice to Have
PowerShell scripting (Graph, Entra, Intune, Exchange) – happy to develop this on the job
Microsoft certifications (e.g. MS-102, AZ-104, SC-200)
Exposure to ITIL / service management
Familiarity with
PAM360
or other privileged access management tooling
Working knowledge of networking and VMware (enough to elevate well)
What Makes Someone Stand Out
We're a small team – the person who'll thrive here is a generalist by choice, comfortable shifting between Conditional Access tuning in the morning, a Hybrid AD replication issue at lunch, and an Intune deployment in the afternoon.
Perks & Benefits
50% off
all our brands
Flexible working options – hybrid WFH and beautiful studio/office space
4pm Friday finishes
and true work/life balance
Birthday leave + monthly social events, morning teas & more
Employee Assistance Program for you and your family
Paid Parental Leave
#J-*****-Ljbffr
📌 Systems Engineer (New South Wales)
🏢 APG
📍 New South Wales