Senior IT Systems Engineer · Scape ScapeWorld Entertainment · Remote We are recruiting in the EEA, the UK and Switzerland only. About us We are Scape, a Swedish game studio of about 30 people, fully remote by choice. We are launching Gravity on Steam Early Access later this year: a precision climbing game where 100 players share one server, one tower, and one long way down. Gravity is the first game inside Scape, a growing platform of multiplayer games where a player's identity carries across all of them; Scape itself follows. Our senior team has shipped and run live games at studios including Arrowhead (Helldivers 2), Avalanche Studios, and Ubisoft. Our IT is moving to code, piece by piece, and we are looking for the person who drives that with us and still answers when someone is locked out. The role Let us start with what IT looks like here. There is no office and no server room. Nearly everything is SaaS, everything signs in through one identity, and we are moving the estate to code: groups, guests, app registrations, DNS and Zero Trust policies increasingly live in Terraform and change through a reviewed pull request, with automation reverting what is changed by hand. Some of it is already there, some is still clickops, some will move and some will stay. Our goal is to automate as much as we can and to bring AI into more and more of our workflows. You look after IT for the whole company, including the team building Lemur, our proprietary multiplayer engine, though nearly everyone you work with day to day is on Scape. You are the first hire into IT, and you own it. Our technical leadership is your main stakeholder for changes, and where IT overlaps with the rest of management you work it out with them. You report to the Technical Director. The other half of the job is people. A colleague cannot get into Jira. A new hire starts Monday and needs everything on day one. A partner needs guest access to a board. Those arrive as Teams messages from a fully remote team, and they need someone who reads the problem behind the message, fixes it, and then fixes the reason it happened. If that half of the job is beneath you, this is the wrong seat. If you like it, read on. In practice, it comes down to three things: You build. Terraform, PowerShell, pipelines and pull requests are your daily tools. You bring the next piece of clickops under code without breaking what runs, and you look for the manual step that a script or an automation can take over. You run the desk. Access, onboarding, guests, mailboxes, admin rights, all remote, all through Teams. Fast, friendly, and closed properly, with the cause fixed and not just the symptom. You keep the admin straight. Every subscription, seat, renewal and invoice is accounted for, on time, in the register. Nothing lapses, nothing is paid twice, and nobody has to chase you. What you will own Our IT as code: Terraform and PowerShell, every change a reviewed pull request, drift reverted rather than argued with, the documentation kept true in the same change, and what is still clickops brought under code one deliberate change at a time Microsoft 365 and Entra ID day to day: accounts set up when HR hands a new starter over to IT, groups, guests, mailboxes and aliases, and the Exchange side the provider cannot reach All our domains and websites: DNS across every zone, registrations and redirects, and the mail records that decide whether our mail is trusted Zero Trust through Cloudflare: Access applications, tunnels and device profiles, and who reaches what from where SSO and integrations: every app signing in through one identity, SAML and SCIM where a tool supports them, and app registrations and admin consent for anything that asks for organisation data. User consent is off by design, so all of it lands with you Automation and AI in our workflows: finding the manual step, scripting it, wiring the tool in, and pushing what we do with AI further, one workflow at a time The security posture in practice: multi-factor authentication with no exceptions, credentials only in the vault, and a leaver closed out the same day across every system, tokens included The request desk, remote: access requests, guest invites, admin rights, and the onboarding and offboarding runs behind them. Answered fast and closed properly. This is a real part of the seat, not a footnote to it Tool administration and its money: every subscription and seat in the register, renewals seen coming, invoices checked, matched and paid on time, and the seat count right. Very structured, no surprises. Spend decisions sit with management; keeping it clean and proposing where to trim is yours You There is no years-of-experience bar here. If you can show us the things below, apply. We would rather meet you than miss you. You have run Microsoft 365 and Entra ID as your daily surface: users, groups, guests, app registrations, admin consent, Conditional Access You have done SSO end to end: connecting apps over SAML or OIDC, SCIM provisioning where it exists, and untangling the sign-in problems that come with them You have written Terraform that runs against something real, in Git the way an engineer does: branches, pull requests, review, and a pipeline that applies on merge. You read a plan and say what it does before you apply it. If you have brought an estate that already existed under code, rather than starting clean, that is the closest thing there is to this job You script rather than click. PowerShell here, and the codebase is PowerShell 7. What you have scripted in before matters less than the reflex Cloudflare, or a serious equivalent: DNS you have genuinely owned, and Zero Trust or a comparable access layer. If you have fixed SPF, DKIM and DMARC on a live mail domain, tell us, because that work is on the list here You like people, and you are good at them over text. A remote first-line desk means understanding a problem from a two-line Teams message, asking the right question back, and leaving the person better off than a ticket number would You are organised with money and paperwork. Invoices, renewals and seat counts are boring until one is missed, and with you none is You lead your area. Given an assignment you find out what it needs, decide, and finish it well, and you bring technical leadership in as a stakeholder rather than waiting for instructions You live in the EEA, the UK or Switzerland, and your working day overlaps CET You are comfortable working in English, written and spoken Helpful, not required Atlassian cloud administration: Jira, Confluence and the user and group side of it Lucid administration: users, teams and the SSO side of it Endpoint management, Intune or an equivalent Azure DevOps pipelines, or another CI that applies infrastructure on merge A games studio, or any company where the engineers hold strong opinions about their tooling What we offer IT here is an engineering job with a review culture, not a queue, and the room to automate whatever bores you. We are a self-motivated team, remote by choice and flexible in how we work, and we run on people helping each other rather than watching each other. No timesheets, no theatre: everyone here is trusted to own their part, and supported when they need a hand. And we are early. Gravity is heading to Steam with everything still ahead of it. Joining now means building something with a real chance of becoming big, and being one of the people it belongs to when it does. Practical Remote. We are a distributed team, and your working day overlaps CET. Full time on a long-term contract Start as soon as you can. Tell us your notice period in the application form. Recruitment is ongoing. Disclosure This application will be evaluated with the help of an AI tool that checks your CV and application against the criteria for this role. A human recruiter always makes the final decision. The AI does not reject or accept anyone on its own. If your application isn't taken forward, you can ask us for an explanation of how the AI was used in that decision. See our Candidate Privacy Policy below for full details, or contact us at privacy@br.ink with any questions.