IT Engineer

Xenith

Jakarta Barat

On-site

IDR 1,592,638,000 - 2,123,518,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Xenith is seeking a hands-on IT security and systems engineering leader to own the technology stack across the company’s devices and platforms. You will build scalable processes, set standards, write policies, and drive security postures across finance, product, and operations.

You will manage macOS and Windows fleets, lead identity and access governance, and automate repetitive tasks. This role reports to the Head of Engineering and requires strong communication across time zones.

Qualifications

  • 5+ years in IT, endpoint, or systems engineering.
  • Hands-on managing macOS and Windows fleets; stand up MDM from scratch (Jamf, Intune, Kandji or equivalent).
  • Ownership of the identity and access lifecycle – SSO, MFA, offboarding and periodic access reviews.
  • Comfortable on Linux/macOS CLI and able to script repetitive work (Bash, PowerShell or Python).
  • Working knowledge of VPN, firewall and least-privilege access design.
  • Experience administering business SaaS platforms at company scale, including licensing and security settings.
  • Experience operating in regulated/audited environments (PCI-DSS, ISO 27001 or SOC 2) and producing evidence for auditors.
  • Excellent communication and documentation skills in English.

Responsibilities

  • Own endpoint management across macOS and Windows — enrolment, disk encryption, OS and patch policy, remote wipe.
  • Run identity and access lifecycle end to end: joiner, mover, leaver; SSO and password management; provisioning and revocation.
  • Administer core business platforms: licensing, security configuration and cost.
  • Run security operations for the internal estate: endpoint protection, patching, phishing defence, and first response.
  • Own vendor security reviews and respond to counterparty assessments with reusable answers.
  • Produce access reviews, asset records and audit evidence continuously.
  • Maintain network and remote-access posture across offices; enforce least privilege.
  • Own procurement and hardware lifecycle across regions.
  • Support engineers and non-technical teams; set the standard for rapid, clear support.
  • Choose and introduce tooling; prefer market solutions based on cost, fit and maintenance.
  • Automate provisioning, onboarding, environment setup, and internal reporting.
  • Write and own policies, defining what good looks like.

Skills

Endpoint management
macOS and Windows
Identity and access lifecycle
Scripting (Bash/PowerShell/Python)
Security operations
Vendor security reviews
ISO 27001 / PCI-DSS / SOC 2
English communication

Tools

Jamf
Intune
Kandji
Okta
Entra ID
Google Workspace
Bash
PowerShell
Python
VPN

Job description

What we're looking for

We are seeking a hands-on, self-directed engineer to own the technology the company itself runs on. You'll be working closely with one of our portfolio companies in the fintech sector as part of the Engineering department, supporting every team across the business - engineering, product, commercial, operations, finance and people. This company is a leading B2B fintech platform in its field, processing over US$2B across multiple currencies annually.

This is our first dedicated hire for the function, reporting to the Head of Engineering. Basic processes exist, but they were built by whoever had time and none of them scale. You will evaluate and choose the tooling, set the standards, write the policy, and decide what gets fixed first. The role starts inside Engineering, where the need is sharpest, and grows into the function that serves the whole company. If you would rather build an IT function than inherit one, this is that seat.

This role is open to candidates based in either Singapore or Indonesia.

What you'll do
  • Own endpoint management across macOS and Windows for company devices — enrolment, disk encryption, OS and patch policy, remote wipe - keeping every device managed and accounted for

  • Run the identity and access lifecycle end to end: joiner, mover, leaver; SSO and password management; provisioning complete before a start date and revocation on the day someone leaves

  • Administer the core business and collaboration platforms the company runs on, including licensing, security configuration and cost

  • Run security operations for the internal estate: endpoint protection, patch and vulnerability remediation, email and phishing defence, and first response when something looks wrong

  • Own vendor security review, and respond to the security assessments our counterparties send us, building reusable answers rather than starting from scratch each time

  • Produce the access reviews, asset records and audit evidence our compliance obligations require, continuously rather than as a project

  • Maintain network and remote-access posture across our offices, applying segmentation and least privilege, and extend it as the company grows

  • Own procurement and hardware lifecycle - vendor relationships, purchasing standards, warranty, replacement cycles across the regions we operate in

  • Support engineers and non-technical teams alike, and set the standard for how quickly and clearly that support is delivered

  • Choose and introduce the tooling this function needs. We would rather buy what the market already solves well than build it, and we expect you to make that call on cost, fit and maintenance

  • Automate what is left - provisioning, onboarding, environment setup, internal reporting. If something is done by hand three times, we expect you to remove it

  • Write and own the policies that go with all of the above, and be the person who decides what good looks like

What you should have
  • 5+ years in IT, endpoint, or systems engineering, including time as the only person responsible

  • Hands-on experience managing both macOS and Windows fleets, and having stood up an MDM from scratch (Jamf, Intune, Kandji or equivalent)

  • Proven ownership of the identity and access lifecycle - SSO, MFA, offboarding and evidenced periodic access reviews (Okta, Entra ID, Google Workspace or equivalent)

  • Comfortable on a Linux/macOS command line, and able to script your way out of repetitive work (Bash, PowerShell or Python). You don't need to be a developer, but "I’d automate that" should be your first instinct

  • Working knowledge of VPN, firewall and least-privilege access design

  • Experience administering business SaaS platforms at company scale, including licensing and security settings

  • Experience operating in a regulated or audited environment - PCI-DSS, ISO 27001 or SOC 2 - and producing the evidence auditors ask for

  • Comfortable supporting non-technical colleagues as well as engineers, and able to explain technical constraints in plain language

  • Able to work effectively with people you rarely see in person, across multiple timezones and cultures

  • Excellent communication and documentation skills in English

Bonus Points
  • Experience as the first IT or security hire at a growing company

  • Multi-country operations - shipping hardware, managing local vendors, navigating local import and employment requirements

  • Familiarity with a major cloud platform and cloud identity

  • Experience with endpoint detection and response or device compliance tooling

  • Experience applying AI-assisted tools to internal workflows and support

  • A stronger coding or Linux systems administration background

About Us

Xenith is a B2B payment service provider focused on enabling seamless cross-border commerce. With an MSB license in Canada and PJP III license in Indonesia, we offer global merchants a one-stop solution to manage multi-currency payments - with a strong focus on alternative payment methods in emerging markets. Our deep regional expertise and strong partnerships with top local gateways, we simplify the complexity of fragmented payment landscapes, helping global merchants expand faster and more efficiently. At Xenith, we believe in building a culture where people feel empowered, trusted, and challenged to do their best work. Join us as we build the financial infrastructure of tomorrow!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Engineer
IT Engineer

Xenith • Jakarta Pusat

Hybrid
IDR 1,610,594,000 - 2,684,324,000
Lead IT & Security Engineer - Endpoint & Identity
Lead IT & Security Engineer - Endpoint & Identity

Xenith • Jakarta Pusat

Hybrid
IDR 1,610,594,000 - 2,684,324,000
People and Culture Executive
People and Culture Executive

Xenith • Jakarta Barat

On-site
IDR 200,880,000 - 357,120,000
People and Culture Executive
People and Culture Executive

Xenith • Jakarta Pusat

On-site
IDR 111,600,000 - 223,200,000
Senior IT & Security Engineer — Endpoint & IAM Lead
Senior IT & Security Engineer — Endpoint & IAM Lead

Xenith • Jakarta Barat

On-site
IDR 1,592,638,000 - 2,123,518,000
VP of Engineering
VP of Engineering

First Circle • Jakarta Pusat

Remote
IDR 900,000,000 - 1,400,000,000
Macbooks
Health insurance
Training budget
Senior Product Manager (Loan & Debt Management Systems)
Senior Product Manager (Loan & Debt Management Systems)

First Circle • Jakarta Pusat

Remote
IDR 1,609,442,000 - 2,324,750,000
Macbooks
Health insurance
Training budget
+1
Cybersecurity & Compliance Analyst
Cybersecurity & Compliance Analyst

MixWork Pte. Ltd. • Jakarta Selatan

On-site
IDR 360,000,000 - 600,000,000
Flexible Medical Benefit
Daily Allowances
Workstation Provisioning
+1
IT GRC Analyst
IT GRC Analyst

Xendit • Jakarta Pusat

On-site
IDR 60,000,000 - 90,000,000
DevSecOps Engineer (Kubernetes, Terraform & Secure CI/CD) | 4+ YoE, Good English
DevSecOps Engineer (Kubernetes, Terraform & Secure CI/CD) | 4+ YoE, Good English

REC Talents - HR Solution • Indonesia

Remote
IDR 2,145,156,000 - 3,217,733,000
Flexible work arrangements
Professional coaching & mentorship
Career progression opportunities