03 Aug
|
Kinterra
|
Toronto
Kinterra is a private equity platform dedicated to building secure supply chains for the modern economy by acquiring and developing critical minerals and related infrastructure assets. With approximately US$1.5 billion in committed capital, Kinterra invests in high-quality, development-stage mining and downstream infrastructure projects to enable the energy transition, support infrastructure expansion, and advance global manufacturing resilience. We work alongside our portfolio companies to unlock value through active ownership, deep technical expertise, and disciplined project development. Our culture is rooted in collaboration, accountability, and excellence in execution. Role Summary The IT Specialist, Systems & Automation is the senior technical lead for end‑user systems, identity, and automation at Kinterra. The role owns the design and operation of Microsoft 365, Entra ID, Intune, and the broader corporate productivity stack across multiple entities — and drives a deliberate shift from manual IT toil toward automated, self‑service, AI‑assisted workflows. This is a hands‑on senior engineering role for a proven IT systems professional (6–8+ years) with depth in M365 architecture, identity and access management, modern endpoint management, and automation. The Specialist works alongside the Junior IT Analyst — who owns desktop, hardware, AV, and Tier 1 portco support — providing senior escalation, owning the systems backbone, and stepping into direct end‑user support only for executive and VIP scenarios. The Specialist coordinates closely with the Network & Security Lead on identity, security, and infrastructure‑adjacent matters, and is expected to bring engineering discipline — version control, peer‑reviewable change, documented runbooks, and configuration‑as‑code — to the IT function. Key Responsibilities: Own Microsoft 365 tenant administration across corporate and portfolio company environments — Exchange Online, SharePoint, Teams, OneDrive. Design and operate Entra ID / Azure AD identity policies — user and group lifecycle, role‑based access, Conditional Access, and authentication flows. Implement and maintain MFA, Conditional Access, identity protection, and privileged identity management in coordination with the Network & Security Lead. Own M365 Security & Compliance configuration: Microsoft Purview, DLP, sensitivity labels, retention policies, and audit logging. Endpoint Management & Intune Architect and operate Microsoft Intune for device compliance, application deployment, configuration profiles, and Conditional Access integration across Windows and macOS. Build and maintain automated provisioning pipelines — Autopilot, scripted configuration, baseline enforcement. Define and enforce endpoint security baselines, patch management cadence, and compliance reporting. Provide Tier 3 escalation for endpoint configuration, policy, and identity issues raised by the Junior IT Analyst. Automation,
Engineering Discipline & Cross‑Stack Troubleshooting Identify repetitive IT operations and replace them with automated, reviewable workflows — onboarding/offboarding orchestration, provisioning scripts, license management, ticket routing, alert triage. Develop and maintain automation in PowerShell, Python, Power Automate, and (where applicable) Logic Apps or Azure Functions. Integrate AI‑assisted workflows (Microsoft Copilot, Claude, ChatGPT, or equivalent) into IT operations where they deliver measurable productivity gains. Apply working knowledge of networking protocols (TCP/IP, DNS, DHCP, VPN, TLS) and security fundamentals (firewall behaviour, segmentation, Conditional Access) to troubleshoot end‑to‑end across identity, endpoint, and network layers. Resolve cross‑stack issues at root cause — closing tickets without escalating every network‑touching M365, Intune, or identity issue to the Network & Security Lead. Onboarding, Offboarding & Identity Lifecycle Own the systems side of joiner / mover / leaver workflows — automated HRIS‑to‑M365 provisioning, license assignment, group membership, and timely access revocation. Maintain standardized onboarding templates, access review cadence, and offboarding playbooks. Coordinate with the Junior IT Analyst, who executes the physical layer (device prep, desk‑side setup, hardware collection). Serve as the senior escalation path for executive and VIP IT needs — providing white‑glove support where the Junior Analyst cannot resolve, or where the scenario warrants senior handling. Support executive travel IT needs at the systems layer: remote access, identity exceptions, and Conditional Access scenarios. Maintain documented exception‑handling and VIP runbooks so coverage is not personality‑dependent. AV — Senior Backup Only Act as backup technical lead for high‑stakes AV scenarios — board meetings, investor presentations, town halls — where additional senior coverage is warranted. Own AV‑adjacent configuration: Teams Rooms tenant policies, identity integration, and Conditional Access exceptions. Maintain authoritative IT runbooks, architecture documentation, and standard operating procedures. Contribute to Business Continuity Planning, Incident Response, and tabletop exercises — particularly for identity, M365, and endpoint scenarios. Drive a measurable reduction in manual IT effort through automation, self‑service, and knowledge base enablement. Develop end‑user‑facing communications for change announcements, planned maintenance, security advisories,
and post‑incident summaries. Partner with the Network & Security Lead on identity, Conditional Access, segmentation, and security tooling integration. Coordinate with the Junior IT Analyst to ensure no service gaps; balance workload and escalation paths. Support IT security reviews and ensure automation tooling meets access control, secrets management, and compliance requirements. Qualifications & Experience Required 6–8+ years of hands‑on experience in IT systems administration, endpoint engineering, or identity and access management — with demonstrated senior ownership. Deep, hands‑on Microsoft 365 administration: Exchange Online, SharePoint, Teams, OneDrive, and tenant‑level configuration. Solid Entra ID / Azure AD expertise: identity policies, Conditional Access, MFA, role‑based access, and integration with downstream applications. Hands‑on Microsoft Intune expertise: device compliance, application deployment, Autopilot, and configuration profiles across Windows and macOS. Strong scripting and automation: PowerShell to a senior level, plus Python or equivalent. Strong understanding of identity and access management, MFA, Conditional Access, and security hygiene. Experience with Microsoft Purview (DLP, sensitivity labels, retention policies) and M365 Security & Compliance. Working knowledge of networking protocols and security fundamentals — TCP/IP, DNS, DHCP, VPN, TLS, firewall rules, and segmentation concepts — sufficient to troubleshoot identity, endpoint, and M365 connectivity issues end‑to‑end and engage credibly with the Network & Security Lead. Strong written communication — runbooks, architecture documentation, change communications, and executive‑facing status updates. Comfort engaging directly with executive and VIP stakeholders when escalation requires it; professional and composed under pressure. Demonstrated ability to operate independently, set technical direction, and mentor a more junior teammate. Nice to Have Microsoft certifications: MS‑102, AZ‑104, SC‑300, MD‑102, or equivalent. Exposure to CI/CD pipelines (GitHub Actions, Azure Pipelines) for IT script and configuration deployment. Experience with multi‑entity or multi‑tenant Microsoft 365 environments (cross‑tenant identity, B2B, cross‑tenant access policies). Experience integrating AI‑assisted workflows or APIs (Microsoft Copilot, Claude, ChatGPT, Anthropic API, OpenAI API) into IT operations. This posting reflects a new current vacancy and Kinterra’s commitment to a fair and transparent recruitment process. We use AI enabled tools to support parts of the hiring process, however they are guided closely by humans. All interviewed candidates will be notified of the hiring outcome within 45 days, and accommodations are available upon request. Estimated salary range for this role, dependent candidate experience, is $110,000-$140,000 #J-18808-Ljbffr
📌 Circular It Specialist (Toronto)
🏢 Kinterra
📍 Toronto