IT & Security Administrator / Manager

Hive Robotics
München, Germany
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English, German
Experience level
Senior
Compensation
€ 85K

Job location

München, Germany

Tech stack

Microsoft Windows
Apple Mac Systems
Software Applications
JIRA
Backup Devices
Bash
BitLocker Drive Encryption
Software as a Service
Software Documentation
Computer Security
Linux
Multi-Factor Authentication
Hardware Security Module
Information Technology Operations
Virtual Private Networks (VPN)
Python
Key Management
Open Source Technology
Powershell
Remote Access Technology
Azure
Phishing
Runbook
SharePoint
Software Asset Management
Virtual Local Area Networks
Software Vulnerability Management
Wi-Fi Technology
Scripting (Bash/Python/Go/Ruby)
Data Classification
DATEV
Microsoft InTune
Information Technology
Free and Open-Source Software
DocuSign
Network Server

Job description

As our first dedicated IT & Security Administrator / Manager, you own IT for the whole company. You take our modern cloud-first environment (Microsoft 365, Entra ID, Intune) and make it complete, enforced, and ISO 27001 / NIS2-ready. You run it day to day, shape the decisions behind it, and are the face of IT for the entire team. You report to the SVP Finance & Operations. This role is hands-on by design: devices, networks, and people are in the office. Some remote flexibility is possible once the fleet is fully under management. Verantwortlichkeiten

IT Operations & User Support

  • Be the first point of contact for IT support across the company: fast, pragmatic, and service-oriented
  • Own IT onboarding: workstation setup, accounts, and day-one enablement for every new joiner
  • Administer Microsoft 365 (Exchange, Teams, SharePoint, OneDrive) and our business SaaS stack (e.g. Personio, DocuSign, DATEV interfaces): seats, access reviews, admin hygiene
  • Operate the on-site network and office infrastructure: UniFi servers, WiFi, VLAN segmentation, VPN / remote access, printers, AV, and meeting rooms
  • Provide workstation and network enablement for our on-site production pilot line
  • Prepare and scale our IT systems and processes for the team's growth
  • Steer our external IT service provider and take over responsibilities step by step, in coordination with Operations

Endpoint & Device Management

  • Operate and complete our Intune-based device management across macOS, Linux and Windows: enrollment, configuration profiles, compliance policies, and update rings
  • Enforce full-disk encryption (FileVault / BitLocker) with recovery key escrow across the entire fleet
  • Manage company smartphones (supervised, zero-touch enrollment)
  • Own the hardware lifecycle: procurement, imaging, asset register, secure disposal, and the IT budget behind it, in coordination with Finance & Operations

Identity & Access Operations

  • Administer the Microsoft Entra ID tenant, including users, dynamic groups, Conditional Access, license management, and the automated HR-driven provisioning sync
  • Run the rollout of phishing-resistant MFA (hardware security keys) across the company
  • Make joiner / mover / leaver a same-day process: a new hire is productive on day one, a leaver's access is revoked within the hour

Processes, Documentation & Asset Management

  • Introduce and run a lightweight ticketing and ITSM process (e.g. Jira Service Management) with clear priorities and response targets
  • Build and maintain IT documentation: runbooks, network and system documentation, and a self-service knowledge base
  • Draft and enforce practical IT policies aligned with ISO 27001: acceptable use, password / MFA, onboarding and offboarding checklists
  • Own software asset and license management across our SaaS and desktop software: seats, renewals, cost control, and shadow IT
  • Support open source software compliance together with engineering: license register, SBOM tooling, and scanning in the development pipeline

Security Operations & Compliance Readiness

  • Implement and operate the security baseline: endpoint protection, patch and vulnerability management, email security, backup with regular restore testing for Microsoft 365, and secrets management for our source-code repositories
  • Manage on-site physical security systems: cameras, access control, and alarm infrastructure
  • Support data classification and the secure handling of sensitive and export-controlled information
  • Perform basic security and privacy reviews of new tools and vendors before rollout
  • Maintain the asset and access documentation that ISO 27001 and NIS2 audits require, such as device inventory, access logs, and restore evidence
  • Support security awareness measures, train the team on them, and contribute to incident response processes

Anforderungen

This is a broad and demanding role, and we know that. You do not need to tick every box or master every topic from day one. If the core is there and you have the drive to grow into the rest, we want to hear from you.

Requirements

  • 5+ years in internal IT administration, ideally in a growing company
  • Hands-on device management experience with a modern MDM, Intune strongly preferred (macOS, Linux and Windows)
  • Solid Microsoft 365 / Entra ID administration: users, groups, Conditional Access basics, licensing
  • Working knowledge of security architecture and the regulation behind it, in particular ISO 27001 and NIS2
  • Security-first mindset: you treat an unencrypted or unmanaged device as an incident, not a backlog item
  • Strong service mentality: people enjoy asking you for help, and the project work still gets done
  • Structured working style: you document what you build and turn repeatable tasks into processes, checklists, and tickets
  • Fluent English and German
  • Based in Munich or willing to relocate

Nice to Have

  • Hands-on experience in an ISO 27001 certification or NIS2 implementation project
  • Scripting for fleet automation (PowerShell, Bash, or Python)
  • Business network administration experience (WiFi, VLANs, VPN)
  • Endpoint security / EDR operation experience
  • Prior work in defense, aerospace, security, or another regulated environment
  • Experience with software asset management or open source license compliance (license registers, SBOM tooling)
  • Experience building an IT function from scratch rather than inheriting one

About the company

Hive Robotics is building Europe's first full-stack orchestration platform for unmanned systems: connecting, controlling, and commanding multi-vendor drone and robot swarms. Our RF communication systems are Made in Germany, deployed on active frontlines, and targeting a highly valued tactical communication market with zero sovereign alternatives today., Why Hive * Real ownership from day one in a fast-scaling deep-tech company with products already in serial production and in the field. * Work on sovereign European technology that matters, at the intersection of robotics, RF, and autonomy. * Small, high-caliber team with short decision paths and direct access to founders and architects. * Modern office in Munich with the tooling and equipment you need to do your best work.

Apply for this position