Senior Information Technology System Engineer
- Hiring from
- Argentina, Colombia
- Work type
- Remote
- Posted
Show job descriptionHide job description
Can you own a problem end to end?
Not escalate it. Not document it and pass it on. Own it until it's solved, the client understands what happened, and it doesn't happen again.
If that's how you work, keep reading.
About nDuo
We're a UK-based Managed Service Provider and an Apple Premium Technical Partner. We help regulated businesses, fintechs, banks, hospitality brands and global technology companies run their Apple and Windows fleets securely, compliantly, and without drama.
Our clients include Revolut, Kroo, and a range of fintechs, funds and global tech companies. They ask hard questions and expect real answers. Most operate under regulatory scrutiny, which means the work is genuinely technical and the standard is genuinely high.
We're now building our engineering capability in Colombia, and this is one of the first senior hires into that team.
The Role
You'll work remotely from anywhere in Colombia, supporting our global client base alongside colleagues in London and South Africa.
This is a hybrid engineering and security role. You'll design, build and harden the platforms our clients rely on such as identity, endpoint management, network, and the security controls that sit across all of it. You'll also be the person clients speak to directly when something complex needs solving.
Day to day, that means:
- Building and running secure endpoint estates across macOS and Windows, MDM architecture, configuration profiles, compliance baselines, patching and device lifecycle
- Owning identity and access - SSO, conditional access, MFA, provisioning and deprovisioning workflows, least-privilege design
- Hardening and defending - endpoint protection, vulnerability management, logging and alerting, and responding when something looks wrong
- Supporting compliance - helping clients evidence controls for Cyber Essentials, ISO 27001, SOC 2 and their own regulators
- Automating everything worth automating - if you're doing it by hand twice, you should be scripting it
- Leading projects from scoping through to delivery, including the client conversations that go with them
- Working directly with clients - translating technical detail into language a CTO or a compliance officer can act on
Who Thrives Here
We can teach tooling. We can't teach the things below, so this is the part that matters most.
You solve problems, not tickets. When something lands on your desk that nobody has seen before, your instinct is to dig in, not to hand it back. You're comfortable being the person who works it out.
You manage yourself. You'll be trusted with your own workload, your own priorities and your own deadlines, and trusted to flag it early when something is going wrong.
You talk to clients directly. You can hold a technical conversation with an engineer and a business conversation with a director, and adjust without losing either of them. You write clearly. You don't hide behind jargon.
You find a way through. Vendor won't cooperate. Documentation is wrong. The API doesn't do what it says. You've been there, and you got it done anyway.
You care that it's right. Not because someone is watching. Because you can't stand shipping something half-finished.
What You'll Bring
Essential:
- Minimum 5 years in a senior technical IT or security engineering role
- Advanced knowledge of macOS and Microsoft Windows in a business environment
- Advanced scripting ability - Python, Bash, PowerShell
- Advanced experience with cloud identity providers (Okta, Microsoft Entra ID / Azure AD)
- Strong knowledge of MDM platforms (Jamf Pro, Intune; Kandji, Mosyle or FleetDM also welcome)
- Strong knowledge of Google Workspace and Microsoft 365 administration
- Solid networking knowledge - routing, firewalls, VPN, Wi-Fi; Meraki experience particularly valued
- Practical endpoint and infrastructure security experience - hardening, patching, endpoint protection, access control
- Demonstrable project delivery experience, including client-facing responsibility
- Fluent spoken and written English, and the confidence to use it with clients daily
- Legally able to work in Colombia
Nice to Have
- Experience in an MSP or consultancy - delivering for multiple clients at pace
- Exposure to Cyber Essentials, ISO 27001, SOC 2 or similar frameworks
- Okta Workflows, or comparable identity automation
- Infrastructure as code (Terraform, Ansible) and CI/CD pipelines
- EDR/XDR tooling (Jamf Protect, CrowdStrike, SentinelOne, Microsoft Defender)
- SIEM, logging and alerting platforms
- Incident response experience
- Relevant certifications - Jamf, Okta, Microsoft, CompTIA Security+, or equivalent
Working With Us
Hours. Monday to Friday, aligned to New York business hours - 09:00 to 18:00 NYC time, with an hour for lunch. Three to four hours of overlap with London every day.
Remote, properly. Not remote-with-strings. You work from wherever in Colombia suits you.
Projects. Some are delivered outside business hours or at weekends. These are always planned well in advance and paid on top.
Kit. A MacBook Pro, and whatever hardware and software you need to do the job properly.
Certifications. We pay for them. Jamf, Okta, Microsoft, security certifications - if it makes you better at the work, we'll fund it.
Why This Role
Real autonomy. No layers of sign-off. Weekly rhythms, clear priorities, direct communication.
Work that's actually interesting. Regulated fintechs, global tech companies, complex Apple and Windows estates and technical challenges that come with them.
A team being built, not inherited. You'll help shape how our Colombia capability works, and you'll have direct access to the people making decisions.
Growth. We invest in our people. Certifications, new skills, or broader responsibility, there's a clear path for someone who delivers.