Description
cybersecurity
endpoint provisioning
microsoft defender
servicenow itam
vendor management
incident response
The Director of IT will lead the internal IT function and own our Microsoft tenant end-to-end, working closely with business leaders to develop, implement, and optimize secure, scalable technology across corporate, onsite property management, call center, and construction teams. The individual will be responsible for managing IT support, continuing to build out a Tier 1 helpdesk, and adapting systems and workflows to keep pace with the organization’s growth. This role will enhance cybersecurity practices, govern vendor relationships and costs, transition hardware/software inventory to ServiceNow, and align identity lifecycle to Entra ID integrated with UKG, so we can see each employee’s equipment and software during onboarding and ensure proper recovery and license removal during offboarding.
We run a tight group, and this leader must be strategic and hands-on, ready to jump in with tickets, equipment provisioning (including Intune/Autopilot and Dell factory provisioning), and incident response. The Director will also guide a new Network Engineer/Cybersecurity team member on best practices.
- Develop and implement a comprehensive cybersecurity strategy to protect data, identities, endpoints, email, and networks.
- Develop scalable endpoint and network standards and Intune/Autopilot provisioning patterns (with Dell OEM/factory support) that enable direct-to-user deployment and consistent security baselines.
- Present a single view of assigned equipment and software access for onboarding and offboarding, with auditable license reclamation and hardware recovery.
- Operate and tune Microsoft Defender XDR and Microsoft Sentinel, define incident response playbooks, and oversee investigations and post-incident reviews.
- Coach technicians on customer experience, documentation, and automation; personally assist with escalations when needed.
- Establish SLAs, escalation paths, a major incident framework, and knowledge management.
- Use capacity planning, telemetry, and KPIs to ensure infrastructure, endpoints, service desk, and security functions scale effectively.
- Establish standard images / profiles and Autopilot configurations; leverage Dell factory provisioning for direct-ship devices with minimal IT touch.
- Collaborate with leadership to align IT strategy to growth and operational priorities.
- Translate strategy into clear quarterly plans, deliverables, and executive reporting.
- Serve as primary owner of the Microsoft tenant, responsible for Entra ID (identity governance, SSO, Conditional Access, MFA, PIM), Intune (Windows / iOS / iPadOS / Android), Security & Compliance (DLP/Retention/Records/eDiscovery), and Secure Score improvements.
- Develop and manage the IT budget, including cloud subscriptions, Microsoft licensing, hardware refresh, carrier services, and tools (ServiceNow, security).
- Coordinate regular maintenance, patching, and lifecycle refresh to ensure availability and minimal downtime across corporate and property sites.
- Own all third-party vendor relationships - negotiate terms, track costs, renewal dates, and named users, and drive continuous improvement in service quality and price.
- Mentor the Network Engineer/Cybersecurity hire on firewall hygiene, EDR/alert tuning, detections, forensics, and response best practices.
- Assist on the 2026 rollout of ServiceNow CRM, followed by Helpdesk / ITSM (incidents / requests / problem / change) and IT Asset Management (HAM / SAM) replacing our current inventory and asset tracking platform, Asset Panda.
- Implement joiner-mover-leaver automation with Entra ID Lifecycle Workflows integrated with UKG to:Create/disable accounts, assign/revoke licenses, and manage group / Teams access.Present a single view of assigned equipment and software access for onboarding and offboarding, with auditable license reclamation and hardware recovery.
- Maintain efficient depot, spares, and warranty / RMA management to support field and corporate operations.
- Create/disable accounts, assign/revoke licenses, and manage group / Teams access.
- Track spend and identify opportunities for license rightsizing and reclamation and smarter procurement to reduce total cost of ownership without sacrificing reliability.
- Administer and support the Microsoft 365 suite (Exchange, Teams, SharePoint, OneDrive, Power BI, Planner) and govern Power Platform (Power Apps/Automate) including environments, DLP, connectors, and lifecycle.
- Provide user access management, license optimization, and adoption guidance to maximize business value.
- Integrate monitoring, Intune/device data, and identity data for end-to-end visibility.
- Track entitlements vs. usage, reclaim idle licenses, and maintain audit-ready evidence across all software and devices.
- Identify and remediate risks and vulnerabilities, implement secure configurations, and lead ongoing awareness training.
- Lead the creation and management of a Tier 1 helpdesk to support ERP / line-of-business applications and core productivity tools.
- Perform regular IT and security audits against policy and industry frameworks; maintain remediation backlogs with due dates and evidence.
- Maintain a central vendor catalog and entitlement register (licenses, contracts, device warranties, carrier circuits).
- Design and implement BCP/DR protocols - RPO/RTO definitions, backup and recovery testing, failover runbooks, and crisis communication - scaled for highly dynamic operations across corporate, onsite property management, call center, and construction teams.
- Hold direct relationships with Microsoft (M365, Azure, Fabric) and Dell (procurement and provisioning).
- This role primarily operates in an office environment with occasional travel to project sites or external meetings. Some exposure to outdoor elements may occur during site visits.
- Implement and govern ServiceNow ITAM for hardware (HAM) and software (SAM), with a clean CMDB, lifecycle workflows, and periodic inventories.
- Stand up CMDB relationships, lifecycle states, tagging/barcoding, stockrooms/RMA, and software entitlement tracking with usage insights for cost recovery.
- Ensure audit readiness for software licensing, device custody, access control, backups, and incident response.
- Analyze and optimize IT infrastructure and systems performance to align with the fast-paced needs of the business.