POSITION SUMMARY:
Pogue Construction is modernizing its technology foundation as our AI team builds and replaces core company software. We are hiring a hands-on engineer to help build and secure the infrastructure this work will grow on — someone who wants to help shape a maturing environment, not simply keep the lights on. The IT Systems Engineer & Security Specialist builds, configures, maintains, and improves Pogue’s core technology environment — servers, cloud, identity, network, and endpoints — to defined standards, while contributing strong, practical security skills across the estate. Reporting to the Director of Infrastructure & Security, this engineer keeps systems reliable, secure, and well-documented across offices and jobsites.
On security, this engineer is Pogue’s hands-on specialist during an interim period — standing up and strengthening the security posture and risk-reduction work now, with strategic risk ownership transitioning to a dedicated Security Owner as that role is filled. The focus is on implementing and maintaining strong security controls, not carrying sole responsibility for security strategy or risk acceptance.
EXPERIENCE:
- 7+ years of systems/infrastructure engineering in a multi-site Microsoft environment spanning on-premises and cloud
- Deep Microsoft Azure and Entra ID experience
- 3+ years of hands-on security operations.
EDUCATION:
- Bachelor’s degree in Computer Science, Information Technology, or similar experience.
PRIMARY RESPONSIBILITIES:
Systems & Infrastructure Engineering:
- Build, configure, maintain, and improve servers, virtualization, storage, cloud (Azure), identity (Entra ID), Intune, and network to defined standards.
- Monitor infrastructure health and resolve performance, availability, and capacity issues.
- Execute infrastructure changes through change management, with rollback paths and clear documentation.
- Identify technical debt and single points of failure; contribute to modernization and automation.
Security Specialist Support (Interim):
- Help stand up and strengthen Pogue’s security posture and risk-reduction work — applying least privilege, segmentation, hardening, logging, and identity-first configuration in daily engineering — until a dedicated Security Owner is hired.
- Remediate open Microsoft 365 baseline controls and support progress toward NIST CSF 2.0.
- Operate and maintain the security stack — Defendify, CrowdStrike, Netwrix, Microsoft Defender/Purview, MFA, Conditional Access.
- Perform vulnerability remediation across the environment and support incident response — containment, evidence preservation, and post-incident follow-up.
- Produce security evidence for audits, cyber-insurance questionnaires, and customer/supplier prequalification.
Standards, Documentation & Vendor Coordination:
- Maintain accurate documentation — configurations, runbooks, diagrams, and dependency notes.
- Contribute to infrastructure, cloud, identity, and network standards within architecture guardrails set by the Director.
- Coordinate technical cases with infrastructure and security vendors; validate recommendations before implementation.
- Support backup, DR, and resilience execution against defined RTO/RPO targets.
Service & Escalation Support:
- Serve as the Tier 3 escalation point for complex server, identity, M365, cloud, network, and infrastructure problems.
- Provide technical guidance to helpdesk, endpoint, and field support staff; convert recurring issues into standards and reduce repeat escalations.
REQUIRED SKILLS:
- 7+ years as a systems / infrastructure engineer building and maintaining multi-site Microsoft environments across on-premises and cloud.
- Deep, hands-on expertise with Microsoft Azure and Entra ID, plus Microsoft 365 and Intune.
- Strong skills across servers, virtualization, storage, and network (routing/switching, firewalls, VLANs, VPN).
- 3+ years of practical security experience: least privilege, MFA/Conditional Access, vulnerability remediation, and incident-response support, with working familiarity of a control framework (NIST CSF 2.0 or CIS).
PREFERRED SKILLS:
- Hands-on time with a modern security stack such as Defendify, CrowdStrike, Netwrix, or Microsoft Defender/Purview.
- Network hardware experience with Ubiquiti/UniFi.
- Relevant certifications — Microsoft Azure Administrator (AZ-104), Identity & Access Administrator (SC-300), Security Operations Analyst (SC-200), or CompTIA Security+.