Any
$1800-$2400/mo
40
Aug 1, 2026
Read the application steps at the bottom before you send anything. There are three items and all three are quick. Applications missing any of them will not be reviewed.
We're a small MSP based in Colorado. Our clients are mostly in healthcare, manufacturing, and compliance-focused companies who rely on us as their full IT department. 6 people on the team. We're growing and we need an experienced L3 engineer who can own project execution and take escalations off the rest of the team.
We're looking for someone who can take a project scope, think through the best approach, propose a solutions, write a project plan and run with it. Onboard a new client into our full service stack. Pick up a ticket that has already stumped another tea
We value first principles thinking and expert troubleshooting. When you encounter a situation you haven't seen before, we expect you to research it, think it through, suggest your approach, and execute once we align. You won't be following checklists. You'll be solving real problems across a diverse client base.
What you'll be doing
Escalations. You are the technical backstop for the team. Tickets that clear L1 and L2 land with you. Root cause, resolve, and write it up so it doesn't come back.
Project execution. Full client onboardings: RMM deployment, M365 tenant baselining, security hardening, service stack tooling, documentation buildout.
Microsoft 365 security and identity work. Conditional access policies, Entra ID configuration, compliance policies, DLP, MFA. This is the core of what we do and the deepest part of the role.
Intune and endpoint management. Enrollment, compliance policies, app deployment, Autopilot. Migrating endpoints from RMM-only management to Intune-managed. Apple Business Manager and Jamf for macOS environments.
Migration projects. Tenant-to-tenant, Google to M365, SharePoint, Quickbooks to QBO
Network and firewall configuration. IP schema design, VLANs, security policies, VPN setup, typically remote while a local tech racks hardware. Fortinet is our standard. UniFi for switching and wireless.
Automation and scripting. Building and maintaining scripts to streamline internal processes and client environments. You'll also work with AI development tools on internal systems projects.
Documentation of everything you touch in our internal knowledge base.
No two weeks look the same.
What we're looking for
3 to 5 years in an MSP environment at an L3 level. You've managed multiple client tenants simultaneously, worked within a PSA and ticketing system, and understand the pace and context-switching that comes with supporting a diverse client base.
Advanced Microsoft 365 administration and security experience. This is the most important qualification for this role. Not mailbox management. We mean conditional access design, Entra ID, identity governance, compliance policies, and knowing why a policy is scoped the way it is.
Real Intune proficiency. Enrollment, compliance baselines, app deployment, Autopilot. Comfortable migrating endpoints from RMM-only management into Intune-managed environments.
Cybersecurity proficiency. Conditional access policy design, security baselines, MFA enforcement, identity protection. Experience with HIPAA, SOC 2, or other compliance frameworks is important. We serve regulated industries and our clients depend on us to get this right.
Automation and scripting experience. PowerShell, bash, or similar. You look for ways to automate repetitive work in tools like your RMM, PSA, or other platform APIs. Experience with AI coding tools or workflow automation platforms is a strong plus.
Migration experience across different scenarios (tenant-to-tenant, Google Workspace, IMAP).
Networking is helpful, not required. If you have hands-on firewall configuration experience, especially Fortinet, that moves you up the list. If you don't, we'll pair you with our network lead and bring you along.
Strong documentation habits. If you didn't document it, it didn't happen.
Excellent written and spoken English. You'll be communicating with US-based tea
First principles thinker. When something breaks or a project hits an unexpected turn, you research, reason through it, and come back with a recommended path forward.
Self-directed. You'll receive a scope of work and we expect you to execute it, flag blockers, and submit milestones for review without being managed step by step.
Hours
First 90 days: you work our hours. Full US Mountain Time business hours, roughly 8:00 AM to 5:00 PM MT. This is not negotiable and it is how we get you trained, integrated, and trusted with client environments.
After 90 days: minimum 4 hours of daily overlap with Mountain Time, with the rest of your schedule flexible.
Apply only if the first 90 days works for you.
Required within 90 days of hire:
Microsoft SC-300 (Identity and Access Administrator) and MD-102 (Endpoint Administrator). We cover exam fees and study materials. If you already hold either or both, that puts you ahead.
Nice to have
Experience with any of our toolstack: NinjaRMM, HaloPSA, Huntress, ImmyBot, CIPP, Hudu
Apple Business Manager and Jamf for macOS endpoint management
Fortinet NSE certification or equivalent
AI coding tools, workflow automation (n8n, Power Automate, or similar), or building internal tooling. We're an AI-forward team and actively building in this space
What we offer
Full-time remote. $1,500 to $2,000/month depending on experience and certifications. Permanent pay increases tied to certifications earned. Exam fees and study materials covered. Interesting project work across a diverse client base. A team that communicates well and trusts you to own your work.
This role starts with a 60-day trial period so we can both make sure it's a good fit.
How to apply
We're hiring immediately and will begin interviews within days of posting.
Send us these three things.
1. Your resume.
2. A short intro video, one to two minutes. Just you on camera telling us who you are and the kind of work you do. If you already have an intro video recorded, use that one. We are not judging production quality. We only want to hear how you explain things before we get on a call.
3. Short written answers to the three questions below. A paragraph each is plenty. We are reading for how you think, not for length.
Question 1. You're onboarding a 50-person company from Google Workspace to Microsoft 365. What do you do in your first two weeks, in what order, and what are the gotchas you watch for?
Question 2. You're hardening a Microsoft 365 tenant for a client pursuing SOC 2. Which conditional access policies do you put in place first, and why in that order?
Question 3. A ticket is escalated to you. Users at one client intermittently can't authenticate to Microsoft 365, and the L2 has already confirmed it isn't a password or MFA registration issue. How do you work it?
Answer in your own words, from your own experience. If you haven't done one of these, say so and tell us how you would approach it. We would much rather read honest reasoning than a polished answer that isn't yours.