About this role
We're looking for a hands-on infrastructure and security leader to architect, secure, and operate our hybrid enterprise environment. You'll own our defense-in-depth security model and Zero Trust strategy across identity, devices, network, applications, and data. You'll be the one building and running it, not just directing it. This role also has direct oversight of our Network & Systems Administrator. Enterprise Architecture & Zero Trust — Design and implement secure infrastructure across on-prem and Azure environments, applying Zero Trust principles throughout. Identity-driven access, device trust enforcement, and network micro-segmentation Defense-in-depth strategy spanning perimeter, endpoint, identity, and data layers Network & Security Engineering — Own enterprise networking and perimeter/internal security, along with threat detection and response. Enterprise firewall management, including advanced threat protection and application control Network segmentation, access control, and authentication (RADIUS/802.1X) Traffic analysis and anomaly detection, integrated into centralized logging/SIEM Cloud & Identity (Azure) Architect our Azure environment and hybrid identity model. Azure infrastructure: VMs, VNets, load balancers, and hybrid connectivity (VPN/ExpressRoute) Hybrid identity via Entra ID, including conditional access, MFA, and privileged identity management Infrastructure-as-code and automation of cloud provisioning Endpoint & Data Security — Manage endpoint security, MDM, and data protection strategy. Device lifecycle management and MDM/MAM policy enforcement EDR/XDR deployment, tuning, and threat hunting Data classification, encryption, and loss prevention Monitoring & Incident Response — Build observability and lead our response to security and infrastructure incidents. Centralized monitoring, alerting, and performance baselining Incident response, digital forensics, and root cause analysis Disaster recovery and business continuity planning and testing Provide after-hours support for critical UIT issues and service disruptions when necessary. Compliance & Governance — Align infrastructure and controls to relevant regulatory frameworks. NIST, CIS, ISO 27001, and FFIEC alignment Audit support, risk assessments, and architecture/control documentation Automation & Leadership — Reduce manual work and serve as a technical authority for the team. Scripting and automation (PowerShell, Bash, or similar) across routine operations Technical escalation points and mentor to engineering staff Direct oversight of the Network & Systems Administrator