This is a remote position.
Senior System Administrator (IT Infrastructure and Security) Remote (India) | Full-Time
Also searched as: Senior Systems Engineer, IT Infrastructure Engineer, L3 Support Engineer, IT Security Engineer
If you were handed admin rights to every system a 425-person company runs on, what would you harden first?
On a typical day you might take an escalation off the systems engineer in the morning and turn its root cause into a runbook they can run next time, walk the MSP through a segmentation change on a Melbourne campus network after lunch, and end the day confirming with the People team that a leaver's access is actually gone.
About Contour
We started in 2020 with a handful of students and a belief that great education should not be out of reach. Today we operate across three brands with 8,000+ students and 425+ team members: roughly 100 in India and 325 onshore in Australia. The India team runs publishing, student experience, CRM and technology, operations, and people and culture.
The people we hire now will shape how Contour grows. This is one of those roles.
About This Role
You are the senior engineer in Contour's first in-house IT team, and the escalation point above it. You run the systems the company works in: Google Workspace, Slack, HubSpot, Rippling and the LMS; the identity platform and the device fleet; the network, CCTV and door access at each campus; and the security posture across all of it.
You report to the interim IT lead in Melbourne until the handover is complete, then to the VP of Global Enablement and Support. They own the technology budget, vendor contracts and the call on which platforms we standardise on. Risk acceptance sits with the senior leadership team. Everything else is yours: the design, the configuration, the hardening, and the no when a vendor does not pass your review.
Expect roughly two thirds of your week on system ownership, hardening and project work, and one third on escalations. The team is you and a systems engineer who runs the L1 and L2 queue. You mentor them and review their work, but this is a hands-on-keyboard seat. Leading the team as it grows is open to you if you want it: welcome, not required.
The standard here is different in two ways. First, you fix the cause. An escalation you close carries a root cause and, if it has come up before, a runbook. Second, you hold the line on security and can explain why. You have said no to something convenient because it was not safe, and you can walk a non-technical executive through that trade-off without dumbing it down or hiding behind acronyms.
Contour has grown to three brands and two countries on systems that were administered alongside other jobs. The interim IT lead has spent the past few months setting the security baseline and documenting it. You take that handover and make it permanent, then build what comes after: identity done properly, a managed fleet, campuses you can see and control from India, and a change process people trust.
By the end of month three, you will have MFA and 2SV at full coverage, a first access review done, and offboarding revocation confirmed rather than assumed. You will have a change record on every production change, the top repeat escalations written into runbooks and handed to the systems engineer, the findings from our recent security review triaged into a dated remediation plan with the first fixes shipped, and the UniFi stack documented for each campus with SPF, DKIM and DMARC enforced on the domain. The controls you put in place in those first months will still be holding when the company is twice this size.
Where the Work Lives
- Google Workspace: the identity core for staff and where most of the business's data sits. Admin console settings here are security settings: group-driven access, external sharing rules, and audit logs someone reads.
- Slack: where the company talks and where tickets arrive. Most of what you decide gets explained here, to people who do not administer anything.
- Rippling and the identity platform: Rippling is the HR system of record, and we are choosing a dedicated identity and device management platform now. Joiner, mover and leaver flows start in Rippling and end with confirmed access, or confirmed revocation, in every system downstream. You inherit the platform decision and run the rollout across a largely BYOD fleet of several hundred macOS and Windows devices.
- HubSpot and the LMS: the CRM and our own learning platform. Sales, tutors and students work in them, so admin rights, integrations and data flow here protect student data as much as they serve the teams using them.
- UniFi: the network at each campus, managed from one controller with alerts you cannot ignore. Segmentation, firmware and capacity discipline here are what keep a campus network boring.
- 1Password: the enterprise password manager. Shared credentials get retired into it, and break-glass accounts are documented, sealed and tested.
- Suptask: tickets come in through Slack. Each escalation you close records why it happened, so the trend report means something.
- Make.com and Zapier: the automation layer. A scenario that fails silently is worse than the manual step it replaced, so alerting is part of the build.
What You Will Do
- Take the L2 and L3 escalations and stop them coming back. Close what the systems engineer cannot, record the cause, then write the runbook so that ticket type is theirs from then on.Design identity and access. Role-based access, group-driven permissions, SSO where it is available, MFA and 2SV at full coverage. Run the periodic access review and own the technical side of offboarding.
- Administer the workplace stack at senior level. The platforms above plus the approved AI platforms, device management across macOS and Windows, and the systems that finance, sales and tutors work in: hardening, admin rights, audit logging, licence use, and the integrations and data flow between them.
- Run the campus networks, CCTV and door access from India. UniFi design, segmentation, firmware and capacity at each campus; CCTV retention and who can view footage; door access rules and their link to the identity platform. The MSP provides hands on site: you set the scope, run the escalation path, and hold them to their service commitments.
- Own the security posture end to end. Endpoint security (disk encryption, patch levels, endpoint protection, compliance reporting on the fleet), email and domain security (phishing defence, conditional access, SPF, DKIM and DMARC), credential hygiene through 1Password and break-glass handling, and a security assessment of any new system or vendor before we adopt it. When the answer is no, say no.
- Lead incident response for security incidents and outages alike. Contain, investigate, keep the timeline, write the RCA with what changed as a result. Close out the findings from our recent security review and keep the remediation on schedule.
- Put a change record in front of anything touching production. Approver, rollback and verification step, with no exceptions. It exists so the next engineer can see what was done and why.
- Write it down for whoever inherits it. System references for everything you administer, and guides that make sense to someone who was not there when it was built.
- Report to the leadership team in plain terms. Ticket trends, availability, licence use and the seats nobody touches; security posture with the cost of fixing something and the cost of leaving it. Bring recommendations with the risk and the alternative you rejected.
- Build automations that tell you when they break. Make.com or Zapier scenarios with error handling and alerting; the happy path is the easy part. Lead practical AI use across the team: where it helps, where it does not belong, and what it saves.
- Mentor the systems engineer. Review their tickets, coach the diagnosis, correct habits early. Hiring stays with the IT lead for now.
HubSpot is fixed. Everything else is open: if a better tool exists for something we are doing manually, make the case and we will back it.
Requirements
What You Need
- Four or more years in systems administration, systems engineering or senior IT support, including at least two years as the accountable administrator for a core business system: the person who decided how it was configured, and the person paged when it broke.
- Administrator-level Google Workspace or Microsoft 365 at a few hundred users or more. We run Google Workspace, so if your depth is Microsoft 365, show us the concepts carry across.
- Identity and access as a design discipline: SSO, MFA, an identity provider, and least privilege applied by default.
- Security you owned, with evidence: hardening, access reviews, patching, endpoint protection, and at least one security incident you handled from detection to write-up.
- Networking you can diagnose remotely: VLANs, routing, wireless design, and hands-on UniFi or comparable. The campuses are in Australia and you are in India, so working from the controller before you send someone on site is the job.
- Endpoint management across macOS and Windows at fleet scale, including devices the company does not own.
- A change process you have followed for real, including at least one change you rolled back cleanly.
- Scripting to a useful standard: Python, JavaScript or Google Apps Script, and the habit of reading an API reference before asking.
- Plain English for executives. The leadership team funds what it understands, so a trade-off you cannot explain without acronyms is a fix that does not get approved.
- Comfortable working across the India and Australia time difference; the team you support sits in Melbourne.
Nice to Have
- Hands-on UniFi, CCTV or door access control work
- HubSpot, Rippling, Aircall or Notion administration
- Light scripting or automation: Google Apps Script, Zapier or Make.com scenarios, or basic Python
- Time in education or another environment that handles student or minor data
- A diploma, degree or certification in the field: CompTIA A+ or Network+, Microsoft 365 Fundamentals, Google Workspace Administrator
The Kind of People Who Thrive Here
The people who do well here see a gap and close it without being asked, holding the bar even when the clock is short. They give a direct read on the work in front of them, including when it's wrong, and when their own idea doesn't hold up, they say so and bring a better one. They build something that keeps running after they step back. Problems here don't show up on schedule or in the same shape twice, and they'd rather make the right call on limited information than let something break while they wait for a sign-off. That's the job. They name the blocker and the ask the moment they have it, on a call or a text, because decisions get made on the information you bring.
Contour's current cluster heads started as team leads. The path from operator to leader is real here.
What good looks like
- Fast first, then thorough: every ticket gets a quick first response and a fix that holds, in that order.
- Closed means confirmed: a ticket closes when the person who raised it says it works.
- Escalations carry evidence: what you tried, what you saw, what you ruled out, so the senior engineer starts where you stopped.
- Offboarding leaves nothing behind: a leaver's access is gone on the day, with a name against every step.
- Repeat work shrinks: the queue gets lighter over the year because recurring tickets get automated or documented out of it.
Benefits
Fully remote, anywhere in India. No travel: the campus hardware is in Melbourne and you work it through the MSP and the onshore team. Compensation details shared early in the hiring process. You will hear from us within a week of applying, and the process is a written screen, a short video response, a practical task, and two conversations.
Apply with a CV and one paragraph on a request you slowed down, scoped down or refused because it was not safe, and what happened next.