À propos de ce poste Senior IT & Corporate Engineering chez Flex
About The Role
This role owns IT and corporate engineering at Flex, end to end. It reports directly to the CTO.
We think IT's job is enablement. The measure of this function is not how many tickets it closes or how many controls it can point at. It is whether everyone else at Flex can do their work faster and more safely than they could last quarter. A new hire productive on day one instead of day four. An engineer who gets exactly the access they need in minutes, without asking twice and without being handed the keys to everything. A team that can adopt a new tool because someone reviewed it properly, not because they routed around IT to buy it on a personal card. So we are not looking for a gatekeeper, or for someone whose default answer is no. The right person makes the safe path the easy path, and removes friction permanently instead of absorbing it repeatedly.
Which is why this role also owns Flex's corporate security posture. Identity, access, endpoints, and the SaaS estate are one system, and the person who makes access fast should be the person who decides how much access is reasonable. Split those across two teams and employees route around both. You'll set conditional access and MFA policy, own privileged access and endpoint posture, and run third-party OAuth and Workspace grant review. Our security engineers own the product and infrastructure side, the money paths and the code, and you'll work with them constantly. Corporate security is yours to decide, not to implement on someone else's behalf.
This is the hard part of the job, and we'd rather say so than leave it as a bonus line. The argument between moving fast and holding a line is now an argument you have with yourself. Day to day, what gets tightened, what gets mitigated, and what we knowingly accept is your call; the large ones come to the CTO, and we'd rather see a close call early than find out you decided it quietly. What we'd ask is that a no comes from a real read of the risk and the business context rather than a standard applied by default.
The rest of the work has two halves. The IT half is the fleet, identity, access, the SaaS estate, and the joiner/mover/leaver process, delivered with help from a managed IT partner who handles procurement, device logistics, tier-1 support, and international coverage. You own that relationship, define the SLA, and enforce it. The corporate engineering half is the part we think makes this a good job: writing the automation and internal tooling that means the IT half doesn't scale linearly with headcount. If a process only works because a person runs it by hand every Tuesday, we'd rather you replaced it.
You'd be inheriting an estate here, not starting one. The first year is as much untangling what has already accumulated - stale access, tools nobody reviewed, processes that work because someone remembers them - as it is building what comes next. Automate that assessment. Nobody should be reading through a SaaS estate by hand in 2026.
Now the shape of this. Flex is around 150 people, and you would be the only person in this function, with vendor capacity underneath you and a direct line to the CTO. That means real autonomy and real scope from week one. It also means this is a hands-on senior individual contributor role, not a management role, and we are not planning a team under it in the near term. If you're looking to build and lead an IT organization right now, this isn't that job, and we'd rather you knew before you applied.
We're looking for an IT and corporate engineering builder who wants to own security posture, rather than a security specialist willing to cover IT. Both halves have to interest you. If the enablement work reads as the price of admission for the security work, this will be a frustrating job.
What You'll Do
-
Own IT and corporate engineering end to end: the roadmap, the budget, the vendor relationships, and the outcomes.
-
Manage our external IT partner as delivery capacity, not as a peer function. Define the scope, set the SLA, hold them to it, and own the escalation path when it slips.
-
Design the joiner, mover, and leaver process and the entitlement model behind it. Make onboarding fast enough that a new hire is working on day one, and keep deprovisioning in-house and same-day, because it's the highest-consequence action in IT.
-
Administer and improve our identity and productivity stack (Okta, Google Workspace, and the SaaS estate around them), including SSO, SCIM, and group and role design.
-
Own operational policy: device standards, the access-request workflow, and SaaS onboarding and procurement review. Review tools before people buy them, and make that review fast enough that nobody wants to skip it.
-
Build the automation. Provisioning, access reviews, asset and license reconciliation, and the internal tooling that removes recurring manual work across the SaaS estate.
-
Run the endpoint and MDM program across a distributed, increasingly international company, and keep the fleet in a state you'd be comfortable showing an auditor.
-
Own Flex's corporate security posture. Conditional access, MFA, session and device rules, and privileged access are yours to set. So is endpoint posture, and the review of third-party OAuth and Workspace grants that quietly accumulate at every company this age.
-
Design and deliver the security awareness and training program. Not a once-a-year video, and not the version people click through with the sound off.
-
Partner with our security engineers, who own product and infrastructure security. The line runs between corporate and product, not between operating and deciding. You'll bring them into identity decisions with blast radius, and they'll rely on you for provisioning data they can trust.
-
Work closely with People, Finance, and Legal. Onboarding, offboarding, spend, and audit evidence all run through this function.
-
Be a real internal service. Publish what you own, respond when people ask, and find the friction before it turns into a workaround.
What Makes You A Great Fit
-
You think IT exists to make other people effective, and you can point at specific friction you removed rather than tickets you closed.
-
You write code. Not necessarily production services, but scripts, integrations, and glue that other people end up depending on.
-
You'd rather fix the process than get faster at the workaround.
-
You hold both sides of this honestly. You've said no to something that mattered, and you've also said yes to something a stricter version of you would have blocked, and you can explain both calls.
-
You're comfortable being the only person in a function, and comfortable saying what you need instead of quietly absorbing it.
-
You know you can't be in the loop on every request, and you don't want to be. You build the self-service paths that let people get what they need without going through you.
-
You can hold a vendor accountable without turning the relationship adversarial.
-
You can tell a colleague, including a senior one, that what they've built can't keep the access it has, explain why in plain language, and work alongside them to find a way that works.
-
You're calm when something is broken and several people are watching.
-
You explain technical constraints clearly to people who don't share your background, in writing, across time zones.
What We're Looking For
-
Substantial hands-on experience owning IT or corporate engineering at a growing company, including a stretch where you were the most senior person doing the work. Roughly [6+] years is typical, but we care about what you've owned, not the year count.
-
Deep, hands-on ownership of an identity provider (Okta, Entra, JumpCloud, or similar) at the design layer: SSO, SCIM, SAML, group and entitlement modeling. Not just the admin console.
-
Practical experience running Google Workspace or Microsoft 365 as a platform.
-
Real MDM and endpoint experience across macOS, and ideally Windows, in a remote or hybrid company.
-
Automation ability in at least one scripting or programming language (Python, Go, TypeScript, or similar), and comfort with APIs and identity plumbing.
-
Experience designing an access model and running access reviews, not only fulfilling requests.
-
Real ownership of identity security decisions, not only their execution. You've set MFA or conditional access policy, tightened privileged access, or cleaned up third-party app grants, and you can talk about what you traded away to do it.
-
Track record managing an outsourced IT provider or MSP, or a clear-eyed view of why the ones you've worked with succeeded or failed.
-
Clear written communication. Much of this job is asynchronous and cross-team.
Strongly Preferred
-
Experience in a regulated or audited environment (SOC 2, PCI, or a bank partnership), as the control owner rather than the auditor.
-
Time as the senior security voice somewhere without a security team, or without a CISO to escalate to.
-
Experience supporting employees and contractors across multiple countries, including device logistics and local employment platforms.
-
Experience at a company that grew quickly enough that you had to replace your own early processes.
-
Experience introducing AI tooling internally in a way that was actually adopted and actually governed.
Interested? We'd love to hear from you
At Flex, we value passion, determination, and honesty. Even if you don't fully match the job specifics, we encourage you to apply. Unusual career paths and unique skills can help you stand out. We believe diversity drives our success. Join us at [email protected]
Flex is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, marital or family status, pregnancy, genetic information, or any other characteristic protected by law. If you need an accommodation at any point in the process, tell us and we'll sort it out.