About this Enterprise Engineer role at PhysicsX
About us
The Role
Who we’re looking for
- Someone who has designed and owned enterprise identity (Entra ID/Azure AD) at a company of meaningful size, not just administered an existing tenant.
- A person who treats zero trust as an architecture to build, not a buzzword to reference. Conditional access, device trust and posture validation, and least privilege as defaults.
- Someone who's comfortable owning MDM (Intune, Jamf, or similar) end-to-end: enrollment, compliance policy, patching, and lifecycle, across a mixed-OS fleet.
- A collaborative operator who partners well with security, platform engineering, and the wider business.
- Hands-on experience deploying and operating a SASE platform (e.g., Cloudflare One, Zscaler) in production, including policy design, not just administration of an existing setup.
What you will do
- Own and evolve our Microsoft Entra ID environment: identity architecture, conditional access policies, MFA, PIM, SSO/SCIM integrations, and hybrid identity where relevant.
- Manage enterprise infrastructure as code in Terraform (identity, networking, and security tooling), so that configuration is versioned, reviewable, and repeatable.
- Design and implement zero trust network access, replacing legacy VPN patterns with modern SASE-based access control.
- Own MDM strategy and operations across the device fleet (macOS/Windows/Linux/Mobile): enrolment, compliance baselines, patch management, and endpoint security posture.
- Partner with the platform/DevOps team to keep enterprise IT and cloud (AWS, GCP, Azure) security postures are aligned and consistent.
- Lead access reviews, least-privilege enforcement, and identity governance work to support audits and compliance requirements (e.g., SOC 2, ISO 27001).
What you bring to the table
- 5 - 10 years of experience in enterprise IT, security engineering, or identity/infrastructure roles, with deep, hands-on ownership of Microsoft Entra ID/Azure AD in production.
- Deep Conditional Access policy design experience, not just enabling MFA, but building risk based, device aware access rules.
- Experience with Entra ID Governance: Access Reviews, Identity Protection, Privileged Identity Management (PIM) at scale.
- SSO/SAML/OIDC federation and SCIM provisioning across a meaningful number of enterprise apps.
- Endpoint security tooling experience: EDR platforms (CrowdStrike, Defender for Endpoint, or similar)
- Scripting and automation ability (PowerShell, Python, or Microsoft Graph API) to automate identity and device workflows.
- Experience with hybrid identity (Entra Connect or on prem AD sync).
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP, able to translate control requirements into actual technical implementation (access reviews, logging, encryption, change management), not just pass an audit checklist.
Nice to have skills
- Experience with Cloud IAM and security architecture, AWS IAM Security Center, Google Workforce Identity Federation, and how it interacts with enterprise identity (Entra) via federation.
- Compliance automation experience (Vanta, Drata)
- Experience with Cloudflare Zero Trust.
- Exposure to SIEM/EDR/XDR tooling and correlating identity signals with broader security monitoring.
- Background at an AI or high-growth SaaS company.
- Experience supporting UK/EU data protection requirements (e.g., GDPR) from an identity and access standpoint.
- Certifications (good to have, not required)
- Microsoft Certified: SC-300
- Microsoft Certified: SC-100
- Microsoft Certified: MD-102
- CompTIA Security+
- Certifications from your SASE vendor of choice (e.g., Cloudflare Certified, Zscaler Certified)
- CCNA
What we offer
Build what actually matters
Help shape an AI-native engineering company at a formative stage, tackling problems that genuinely matter for industry and society. This is work with real-world impact - and something you can be proud to stand behind.
Learn alongside exceptional people
Work with a high-caliber, collaborative team of engineers, scientists, and operators who care deeply about doing great work, and about helping each other get better. We come from diverse backgrounds, but we share a commitment to operating at the highest level and addressing some of the most complex challenges out there. If you’re ambitious, thoughtful, and driven by impact, you’ll feel at home.
Influence over hierarchy
We operate with a flat structure: good ideas win - wherever they come from. Questioning assumptions and challenging the status quo isn’t just welcomed, it’s expected.
Sustainable pace, long-term ambition
Building meaningful technology is a marathon, not a sprint. We believe in balancing focused, ambitious work with a life beyond it. Our hybrid model blends time together in our New York office with work-from-home days, giving you the flexibility to work sustainably while staying connected in person.
And it doesn’t stop there …
🚀 Equity options - share meaningfully in the company you’re helping to build.
💰 5% contribution to 401(k) - build long-term security with a strong retirement plan.
🍽️ Free team lunch 1x/week - good food, great company, and space to connect.
🏥 Private health insurance – comprehensive cover for you, offering total peace of mind.
👶 Enhanced parental leave – 3 months full pay paternity and 6 months full pay maternity leave, to provide extra flexibility during the moments that matter most.
☀️ 20 days of Annual Leave (+ Public Holidays) - because taking time to rest matters.
📈 Personal development – dedicated support for learning, development, and leveling up over time.
💪 Gympass / Wellhub (subsidized) – for you and up to 3 family members, supporting both physical and mental wellbeing.
💳 Flexible Spending Account (FSA) – set aside pre-tax dollars for eligible healthcare expenses.
🔎 Watch this space, we’re continuing to build this as we grow…