Pacific Rim Mechanical is seeking a Senior Infrastructure & Security Engineer to own the design, security, administration, and modernization of our hybrid IT environment. This role is responsible for Microsoft 365 security, Azure infrastructure, identity management, endpoint protection, network security, disaster recovery, and infrastructure modernization initiatives.
The ideal candidate will be a highly organized technical leader who proactively manages risk, drives security improvements, maintains operational excellence, and leads infrastructure projects from planning through execution.
The successful candidate will serve as a senior escalation resource while partnering closely with IT leadership to improve security posture, modernize infrastructure, and ensure business continuity across office and field operations.
Role emphasis: This position requires ongoing ownership of security and infrastructure, not just responding to individual tickets or one-off technical issues.
Typical Duties
Microsoft Cloud, Identity & Access Security
- Administer and secure Microsoft 365, Azure, and Entra ID environments.
- Design, implement, and maintain Conditional Access policies and MFA enforcement strategies
- Administer privileged access accounts and administrative security controls.
- Maintain hybrid identity environments between Entra ID and Active Directory.
- Review tenant security posture and implement security best practices.
- Support Intune, Mobile Application Management (MAM), and device compliance initiatives.
Data Protection, Governance & Compliance
- Design and administer Data Loss Prevention (DLP) policies, and data classification
- Administer Microsoft Purview and data governance initiatives.
- Develop controls to prevent inappropriate sharing or movement of company information.
- Manage retention policies and information lifecycle management.
AI Governance & Emerging Technology Security
- Establish governance standards for AI platforms including Microsoft Copilot, ChatGPT, and other AI services.
- Assess AI-related security, privacy, and data exposure risks.
- Develop standards for acceptable AI use throughout the organization.
- Ensure company data remains protected when interacting with AI platforms.
- Evaluate emerging technologies and provide risk-based recommendations.
Endpoint Security, Vulnerability Management & Patch Management
- Manage server and workstation patching programs.
- Oversee third-party application patching and software lifecycle management.
- Monitor vendor security advisories and assess organizational impact.
- Conduct vulnerability assessments and remediation efforts.
- Administer our CrowdStrike endpoint security platform
Infrastructure, Servers & Cloud Operations
- Maintain Active Directory, Group Policy, DNS, DHCP, and file services.
- Manage virtualization platforms including VMware and future virtualization technologies.
- Support Azure resources, Azure Virtual Desktop, storage, networking, and security services.
- Perform server upgrades, migrations, and infrastructure modernization projects.
- Maintain certificate services and certificate-based authentication solutions.
Backup, Disaster Recovery & Business Continuity
- Develop and maintain backup and disaster recovery procedures.
- Validate backup integrity and perform recovery testing.
- Implement immutable and offsite backup strategies.
- Develop and maintain ransomware recovery procedures.
Documentation & Process Ownership
- Create and maintain technical documentation, SOPs, diagrams, and knowledge base articles.
- Maintain server asset inventories and technical standards.
- Track security findings, remediation efforts, vendor action items, and project deliverables.
- Ensure operational tasks and follow-up items are completed without gaps.
Skills, Knowledge, Qualifications, & Experience:
- 7+ years of progressive IT infrastructure and security experience.
- Strong experience with Microsoft 365, Azure, and Entra ID.
- Experience implementing Conditional Access, MFA, and identity security controls.
- Experience with Intune and endpoint management.
- Strong Active Directory administration experience.
- Experience with Microsoft Purview, DLP, and governance tools.
- Experience with VMware or equivalent virtualization platforms.
- Experience administering firewalls, VPNs, and enterprise networking environments.
- Experience with backup, disaster recovery, and business continuity planning.
- Excellent troubleshooting, project management, and documentation skills.
Preferred Qualifications:
- Microsoft Security, Azure, or Microsoft 365 certifications.
- PowerShell scripting and automation experience.
- Experience supporting construction, field service, engineering, or multi-location organizations.
- Experience developing AI governance policies and security controls.
Characteristics of the Ideal Candidate
- Highly organized and detail oriented.
- Proactive rather than reactive.
- Comfortable owning long-term infrastructure and security initiatives.
- Able to balance operational support with strategic projects.
- Strong at documentation and follow-through.
- Effective in working with vendors and consultants.
Salary Range:
$135,000-$160,000 Annually based on experience (FLSA Non Exempt)
Full Benefits
- Matching 401(k)
- Paid Time Off
- Paid Holidays
Equal Opportunity Employer
About Pacific Rim Mechanical
Pacific Rim Mechanical is the premier mechanical contractor in Southern California.
And we got there by strict adherence to one simple philosophy...
Always do the right thing.
Since our company inception in 1987, our core values haven’t changed. We still place the highest priority on honesty, integrity and respect for our customers and employees.