Match your resume skills with our AI powered skill match!
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
You will own and manage the company's IT infrastructure, including endpoint management, identity lifecycle, and security operations. Additionally, you will be responsible for selecting tooling, establishing standards, and automating internal processes to support the entire business.
We are seeking a hands-on, self-directed engineer to own the technology the company itself runs on. You'll be working closely with one of our portfolio companies in the fintech sector as part of the Engineering department, supporting every team across the business - engineering, product, commercial, operations, finance and people. This company is a leading B2B fintech platform in its field, processing over US$2B across multiple currencies annually.
This is our first dedicated hire for the function, reporting to the Head of Engineering. Basic processes exist, but they were built by whoever had time and none of them scale. You will evaluate and choose the tooling, set the standards, write the policy, and decide what gets fixed first. The role starts inside Engineering, where the need is sharpest, and grows into the function that serves the whole company. If you would rather build an IT function than inherit one, this is that seat.
This role is open to candidates based in either Singapore or Indonesia.
Own endpoint management across macOS and Windows for company devices — enrolment, disk encryption, OS and patch policy, remote wipe - keeping every device managed and accounted for
Run the identity and access lifecycle end to end: joiner, mover, leaver; SSO and password management; provisioning complete before a start date and revocation on the day someone leaves
Administer the core business and collaboration platforms the company runs on, including licensing, security configuration and cost
Run security operations for the internal estate: endpoint protection, patch and vulnerability remediation, email and phishing defence, and first response when something looks wrong
Own vendor security review, and respond to the security assessments our counterparties send us, building reusable answers rather than starting from scratch each time
Produce the access reviews, asset records and audit evidence our compliance obligations require, continuously rather than as a project
Maintain network and remote-access posture across our offices, applying segmentation and least privilege, and extend it as the company grows
Own procurement and hardware lifecycle - vendor relationships, purchasing standards, warranty, replacement cycles across the regions we operate in
Support engineers and non-technical teams alike, and set the standard for how quickly and clearly that support is delivered
Choose and introduce the tooling this function needs. We would rather buy what the market already solves well than build it, and we expect you to make that call on cost, fit and maintenance
Automate what is left - provisioning, onboarding, environment setup, internal reporting. If something is done by hand three times, we expect you to remove it
Write and own the policies that go with all of the above, and be the person who decides what good looks like
5+ years in IT, endpoint, or systems engineering, including time as the only person responsible
Hands-on experience managing both macOS and Windows fleets, and having stood up an MDM from scratch (Jamf, Intune, Kandji or equivalent)
Proven ownership of the identity and access lifecycle - SSO, MFA, offboarding and evidenced periodic access reviews (Okta, Entra ID, Google Workspace or equivalent)
Comfortable on a Linux/macOS command line, and able to script your way out of repetitive work (Bash, PowerShell or Python). You don't need to be a developer, but "I'd automate that" should be your first instinct
Working knowledge of VPN, firewall and least-privilege access design
Experience administering business SaaS platforms at company scale, including licensing and security settings
Experience operating in a regulated or audited environment - PCI-DSS, ISO 27001 or SOC 2 - and producing the evidence auditors ask for
Comfortable supporting non-technical colleagues as well as engineers, and able to explain technical constraints in plain language
Able to work effectively with people you rarely see in person, across multiple timezones and cultures
Excellent communication and documentation skills in English
Experience as the first IT or security hire at a growing company
Multi-country operations - shipping hardware, managing local vendors, navigating local import and employment requirements
Familiarity with a major cloud platform and cloud identity
Experience with endpoint detection and response or device compliance tooling
Experience applying AI-assisted tools to internal workflows and support
A stronger coding or Linux systems administration background
Xenith is a B2B payment service provider focused on enabling seamless cross-border commerce. With an MSB license in Canada and PJP III license in Indonesia, we offer global merchants a one-stop solution to manage multi-currency payments - with a strong focus on alternative payment methods in emerging markets. Our deep regional expertise and strong partnerships with top local gateways, we simplify the complexity of fragmented payment landscapes, helping global merchants expand faster and more efficiently. At Xenith, we believe in building a culture where people feel empowered, trusted, and challenged to do their best work. Join us as we build the financial infrastructure of tomorrow!
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 213,567+ Jobs in Software Development
Answer easy questions
213,567+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”