Confirmo logo

Senior IT Systems Engineer

Hiring from
Czech Republic
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Confirmo is a stablecoin payment infrastructure trusted by market leaders. Founded over a decade ago by crypto natives, we're one of the first crypto payment processors in the world and have built one of the most established infrastructures in the industry. Over the past 4 years, we have been growing exponentially (130+%) and expanding across the U.S., Middle East, and Europe. As part of our continued growth, we are now expanding our internal IT team in Prague.

Overview:

Confirmo has grown fast, and our internal IT has grown with it: dozens of SaaS platforms, a mixed fleet of endpoints, an identity layer they all depend on, and a growing number of people who need the right access on day one and none of it on their last. We need one person to own all of it.

We are looking for a senior, hands-on engineer to take end-to-end, ongoing ownership of the systems that run the company: our SaaS estate and the identity platform behind it, collaboration platforms, endpoints, and internal monitoring. You will design how these things should work, implement it, document it, and keep it running. This is not a helpdesk role. First-line support is handled by a junior colleague; you are the escalation point and decide how support should work. You will be given a problem, not a ticket. You will work closely with the Head of Security, who owns security policy and controls; you own the systems underneath them.

Key Responsibilities:

  • Own the SaaS estate: You are the technical owner and administrator of record for our cloud platforms across engineering, operations, finance, sales, and compliance. For each one you know and maintain who has access, how it is configured and secured, how its data is backed up, and what it costs. You keep our asset and vendor registers accurate and own the access-request workflow.

  • Own identity and access: Google Workspace structure, user lifecycle, group design, and the SSO / SAML / OAuth / SCIM integrations into every connected system. This includes offboarding end to end: access removal, data handover, email forwarding, and licence reclaim.

  • Own collaboration and file platforms: Run our messaging, documentation, and shared-drive platforms day to day. You design their structure, permissions, sharing, and retention, not just approve access to them.

  • Own endpoint management: Run the rollout of MDM across our macOS, Windows, and Linux fleet with an external partner, then take it fully in-house.

  • Own internal monitoring and alerting: Decide where alerts from our platforms go and who owns them.

  • Automate and document: Recurring tasks get scripted against APIs, not clicked through. Every system has its ownership, configuration, and access model written down.

  • Support platform engineering where needed: Infrastructure as code, CI/CD, and secrets management, depending on your interests and our needs.

Your Profile:

  • Senior: 5+ years in IT systems engineering or corporate IT in a cloud-native company. You have owned an identity platform and a SaaS estate before, not just supported one.

  • Deep Google Workspace administration: OUs, groups, shared drives, security settings, third-party app controls, SAML/OAuth, and the admin API.

  • A generalist across SaaS: You can take over any admin console, understand it quickly, and configure it properly.

  • Fluent in modern identity: You can debug a broken SSO or SCIM integration from the logs and design provisioning for a platform you have never seen before.

  • You script: Python, Bash, or similar, against REST APIs to provision, migrate, reconcile, or audit.

  • Comfortable with cloud, IaC, and CI/CD: Not a full-time DevOps engineer, but at home in that world.

  • AI is part of your toolkit: You use AI-assisted tooling daily. This is how our team works.

  • Structured and cost-aware: You design access models rather than let them grow, and you keep licences and spend as tidy as access.

  • Independent: You take an ambiguous problem and drive it to a working result without micromanagement.

  • Excellent English: Our working language, written and spoken.

Any of these is a plus:

  • Experience introducing or running an MDM across a mixed fleet.

  • Experience building or maintaining an asset and vendor register.

  • Experience migrating or restructuring a collaboration platform.

  • Familiarity with ISO 27001 or SOC 2 from the systems and evidence side.

  • Experience in fintech, payments, or crypto.

Location: Hybrid, based in Prague, with 2–3 days a week in our office, Czech is a plus. This is not a fully remote role.

If you are interested in learning more, please submit your CV, and our recruiter will get back to you promptly.

Similar jobs

Apply for this job