IT Systems & Support Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+42 more
Job description
Canfield Engineering & Integration (CEI) is a fast-growing engineering firm specializing in electrical engineering, instrumentation and controls (I&C), system integration, and construction support for critical-infrastructure clients such as water and wastewater utilities. As we scale, we are hiring an IT Systems & Support Engineer to own the technology backbone that keeps our workforce productive and our data secure.
This is a broad, hands-on technical role centered on Microsoft 365 administration, endpoint management through Intune, and identity and access in Entra ID. Our corporate environment is cloud-first with no on-prem data hosting, so the networking side of this job is mostly field-facing: configuring and troubleshooting network equipment at client job sites so our SCADA programmers and design teams can get connected and stay connected.
You will be the primary point of accountability for day-to-day IT - from provisioning a new hire laptop, to standing up a switch and VPN tunnel, to investigating an endpoint detection alert. This is a support and infrastructure role; it is not a controls-engineering or programming position.
Work Arrangement & Availability
This position is primarily remote. In exchange for that flexibility, responsiveness is non-negotiable: our employees work on billable, client-committed project schedules, and an unresolved IT issue directly costs project hours and client deliverables.
- Availability - Reachable and actively monitoring support channels throughout core business hours, with a reliable home-office setup and connection.
- Response times - Acknowledge and begin triage on work-stopping issues within minutes, not hours; meet defined response targets for standard requests.
- Escalation coverage - Available outside normal hours for outages, security incidents, and critical project deadlines on a reasonable, shared-judgment basis.
- In-office day - One day per week in the Phoenix office for team meetings, planning, and hands-on troubleshooting.
- Field support - Occasional travel to client job sites to configure or troubleshoot network equipment supporting active project work., Microsoft 365 Administration & Identity
- M365 admin center - Own tenant administration across Exchange Online, SharePoint, Teams, and OneDrive - licensing, service health, mail flow, sharing controls, and tenant-wide configuration.
- Entra ID - Manage identity end to end: user and group lifecycle, role assignments, application registrations, SSO integrations, and periodic access reviews.
- Conditional Access - Design, test, and maintain Conditional Access policies covering MFA enforcement, device compliance, sign-in risk, location controls, and legacy authentication blocking.
- Administer Microsoft Defender and Purview capabilities available in the tenant, including email security, safe links/attachments, and data protection settings.
Intune & Endpoint Management
- Deployment - Build and maintain Intune configuration profiles, compliance policies, and app deployments for Windows and mobile devices.
- Automation & provisioning - Understand and build provisioning configurations tailored to device type and application need - an engineering workstation, a field laptop, and a shared device should each deploy with the right baseline, apps, and policies automatically.
- Manage update rings, patch compliance, BitLocker/encryption policy, and endpoint hardening baselines.
- Maintain accurate device inventory and lifecycle planning across hardware, licenses, and warranties.
Network Configuration - Project & Field Support
- Job-site networking - Configure, deploy, and troubleshoot network equipment at client sites in support of our SCADA programmers - getting project networks stood up quickly and reliably.
- Switching & VLANs - Configure managed switches: VLAN design and tagging, trunk and access ports, PoE, and network segmentation that separates control-system traffic from business and vendor traffic.
- Firewall management - Administer firewall platforms - rule sets, NAT, port forwarding, filtering, logging, and firmware maintenance - for both corporate and project-site deployments.
- VPN - Configure and support site-to-site and remote-access VPN so engineers can reach project systems securely from the office or the field.
- Support wired and wireless connectivity, DNS/DHCP, addressing schemes, and internet/cellular circuits at temporary and permanent project locations.
- Partner with I&C engineers and client IT groups on network requirements, addressing plans, and remote-access arrangements for project systems.
- Maintain the corporate office network and its connected devices - Network license servers, Wi-Fi, printers, conference/AV equipment, and others.
Virtualization & Licensing
- Virtual machines - Build, deploy, and support virtual machines for engineering, testing, and simulation workloads, including sizing, snapshots, imaging, and performance troubleshooting.
- Licensing models - Administer network and floating license servers for engineering and controls software - license allocation, checkout troubleshooting, server moves, and renewals - and manage subscription and per-device licensing across the software portfolio.
Endpoint Detection, Monitoring & Remediation
- EDR operations - Monitor endpoint detection and response alerts, triage and investigate suspicious activity, and carry out remediation - isolation, cleanup, reimaging, and root-cause follow-up.
- Incident response - Lead containment, eradication, recovery, and post-incident review for malware, ransomware, phishing, and social-engineering events.
- Maintain and enforce security policies: least-privilege access, MFA standards, acceptable use, data classification, and BYOD/remote-work security.
- Run recurring security-awareness training and simulated phishing, and support client security questionnaires, cyber-insurance requirements, and CMMC/NIST-style control expectations.
End-User Support & Device Lifecycle
- Help desk - Serve as the firm’s primary support resource, resolving hardware, software, printing, and connectivity issues promptly and professionally - with priority given to staff blocked on billable work.
- Onboarding & offboarding - Procure, image, configure, and ship devices for new staff; recover, wipe, and re-provision equipment when employees depart.
- Support engineering workstations and the applications our project teams depend on day to day.
Cloud Data, Backup & Continuity
- Administer cloud file storage and collaboration platforms, including structure, permissions, and capacity planning.
- Own backup, disaster recovery, and business-continuity planning across cloud services and endpoints; test restores regularly so recovery is proven, not assumed.
AI Initiatives & Workflow Automation
- Automation - Help advance the firm’s move toward AI-assisted work - identifying repetitive internal processes and building automated and agentic workflows that reduce manual effort.
- AI security - Apply appropriate safeguards to AI tooling: data handling and retention, tenant and permission boundaries, access controls, and acceptable-use guidance for staff.
Applications, Vendors & Documentation
- Administer business applications and SaaS subscriptions (productivity, project management, ERP/accounting, HR, and engineering tools), including accounts, integrations, and renewals.
- Manage vendors, MSPs, ISPs, and service contracts - controlling cost while holding partners to their SLAs.
- Maintain clear documentation: network diagrams, standard operating procedures, runbooks, and policies.
- Recommend and implement improvements to reliability, security, and efficiency as the firm scales beyond its current 50 employees.
Requirements
- 5+ years of progressive IT experience with hands-on responsibility for end-user support, endpoint management, and network infrastructure - ideally as a sole or lead IT resource in a small-team environment.
- Microsoft 365 admin center - Demonstrated administration experience across Exchange Online, SharePoint, Teams, licensing, and tenant configuration.
- Intune - Proven experience building and deploying configuration profiles, compliance policies, application packages, and update rings at scale.
- Entra ID & Conditional Access - Strong working knowledge of identity administration, MFA, and authoring Conditional Access policies that balance security with usability.
- Network configuration - Practical experience configuring managed switches, VLANs, firewalls, and VPN - including standing up or troubleshooting networks in the field, not just in a controlled office environment.
- Virtualization & licensing - Required - hands-on support of virtual machines and of network/floating licensing models for technical software.
- Endpoint security - Hands-on use of EDR and monitoring, alert triage, patching, and remediation, including response to real security incidents.
- Experience managing backups, disaster recovery, and business-continuity processes.
- Excellent troubleshooting and communication skills, with the ability to explain technology clearly to non-technical staff.
- Self-directed, organized, and dependable in a remote setting - able to prioritize across projects and day-to-day support without close supervision., * Experience supporting enterprise applications, engineering, architecture, or construction firm, including CAD workstations and license servers.
- WordPress & web - Basic website development and maintenance - WordPress/CMS administration, working knowledge of HTML and CSS, plus hosting, DNS, SSL, and uptime configuration. A plus, not a core requirement.
- AI & agentic workflows - Experience building agentic or automated workflows, and a working understanding of AI security safeguards - data governance, prompt and tool permissions, and human review checkpoints.
- Familiarity with SCADA, ICS, or OT network environments and the segmentation practices they require.
- Exposure to compliance frameworks such as NIST CSF, CIS Controls, or CMMC.
- Certifications - CompTIA A+/Network+/Security+, Microsoft (MD-102 / MS-102 / SC-300 / AZ-104), Cisco CCNA, or comparable.
- Bachelor’s degree in Information Technology, Computer Science, or a related field - or equivalent hands-on experience., * Bachelor’s (Preferred)
Experience:
- Hands on IT: 5 years (Required)
- Microsoft 365 Admin Center: 3 years (Required)
Work Location: Hybrid remote in Chandler, AZ 85225
Benefits & conditions
Pulled from the full job description
- Professional development assistance
- 401(k)
- Health insurance
- Retirement plan
- 401(k) matching
- Paid time off
- Vision insurance, * 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Professional development assistance
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Is Software Engineering Over-Saturated?
Fully Remote Software Engineer Jobs
The Most Popular IT Jobs on the Market