We’re at the point where demand for our premium, security-led engagements is outpacing the number of people who can lead them. We need a second engineer who can own client delivery end-to-end not shadow it and who brings genuine security depth to the table.
About the Role
You’ll take real accountability for accounts from day one, mentor a developing junior engineer, and free up capacity across the business. This is a hands on senior role, not a management track. You’ll be trusted with our best clients and expected to represent us well in front of them.
Responsibilities
- Own IT and security delivery for a portfolio of clients, end to end from onboarding and BAU support through to project work and incident response.
- Lead security engagements: identity and SSO hardening, email security, endpoint hardening, SaaS posture reviews, and the kind of adversarial-minded defensive work our clients increasingly expect.
- Act as a trusted technical advisor to sophisticated clients investment firms and family offices who value discretion, calm, and clarity as much as technical skill.
- Design and stand up client environments the our way: Mac + Google Workspace first, Jamf/ABM for devices, Cloudflare for DNS and edge, Entra where required.
- Read, maintain, and extend our automation estate (Cloudflare Workers, Notion, Zendesk) so it isn’t a single-person dependency.
- Mentor our junior engineer, raising the bar on attention to detail, security knowledge, and delivery consistency.
- Help turn our recurring, high-value work into repeatable products and playbooks.
Qualifications
- 5+ years in IT/systems engineering or MSP delivery, with real ownership of client relationships and outcomes not just working tickets handed down to you.
Required Skills
- Deep fluency in our stack: macOS, Google Workspace administration, Jamf and Apple Business Manager, and Cloudflare. Comfort with Microsoft Entra / Azure AD (SSO, conditional access, admin consent) is important our clients pull us into that world.
- Genuine security depth, not awareness: identity and access, SSO/SAML/OAuth, email authentication (SPF/DKIM/DMARC) and secure email gateways, endpoint hardening, and SaaS security posture. You can run or co-run a hardening engagement, not just follow one.
- The right temperament for our clients: discreet, composed under pressure, and credible in the room. High autonomy, low ego. You do well in a small, remote, warm-but-direct team.
- Based in the UK, with the flexibility to travel occasionally within Europe.
Preferred Skills
- Relevant security certifications.
- Prior in-house IT or security experience in financial services, or MSP experience serving finance/investment clients.
- Exposure to compliance and due-diligence contexts (Cyber Essentials, SOC 2, LP/investor due diligence, DORA-adjacent work).
- Experience productising services - turning bespoke delivery into repeatable offerings.