IT Systems Engineer
First Due
| Company | First Due |
| Category | Engineering |
| Location | Remote - US Only |
| Remote | Remote |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 24 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
About First Due
First Due’s mission is to prevent first responder injury or death by providing fire and EMS agencies with transformative, end-to-end software solutions that empower them to run safer, smarter, and more effective operations. Job Title: IT Systems Engineer
Location : Remote - US Only Country : United States Department : Corporate IT Reports To : Director of Corporate IT Position Type : Full-Time Salary : $100,000
Job Summary:
First Due is looking for a hands-on IT Systems Engineer to join our small but growing IT team. In this individual contributor role, you’ll own the day-to-day administration of our Microsoft 365 environment and core identity infrastructure. You’ll be an active contributor to the helpdesk team — owning a meaningful share of the incoming IT ticket queue alongside your teammates, while also serving as the senior technical resource who handles the most complex escalations and helps raise the team’s overall capability.
You’ll work closely with the Director of Corporate IT on strategic initiatives including SSO and SaaS application governance, identity and access management, endpoint security, and compliance readiness. A near-term priority for this role is systematically onboarding our SaaS portfolio to SSO via Entra ID and building the automation that makes access provisioning reliable and auditable. This is a high-ownership role with real visibility across the organization.
Key Responsibilities:
Automation, Scripting & SaaS Governance
Build and maintain PowerShell and Graph API scripts to automate onboarding, offboarding, and access provisioning workflows.
Identify manual IT processes and reduce toil through scripting and workflow tooling (e.g., Power Automate).
Own and systematically expand our SSO integration program — evaluate existing SaaS applications, prioritize SAML/OIDC integrations via Entra ID, and build automated provisioning/deprovisioning workflows (SCIM where supported).
Maintain a SaaS application catalog — tracking ownership, license counts, renewal dates, and SSO/MFA status across the organization’s tool portfolio.
Identity & Access Management
Serve as a senior technical lead for Entra ID (Azure AD) — partnering with the team to manage user lifecycle, group management, Conditional Access policies, and MFA enforcement.
Drive SSO integration across SaaS applications using SAML/OIDC via Entra ID.
Implement and maintain least-privilege access principles across the tenant; support ongoing access reviews.
Contribute to Zero Trust architecture initiatives in partnership with the IT Director.
Endpoint & Device Management
Administer and mature our MDM platform (Intune) for Windows devices, ensuring device compliance, configuration, and security baselines; contribute to the evaluation and implementation of a dedicated macOS MDM solution (e.g., Jamf or Kandji) as the Mac fleet grows.
Manage device lifecycle: procurement, provisioning, compliance enforcement, and decommission.
Develop and maintain configuration profiles, compliance policies, and device health reporting.
Microsoft 365 Administration
Administer core M365 workloads: Exchange Online, Teams, SharePoint, OneDrive, and Defender.
Manage licensing, provisioning workflows, and tenant-wide security configurations.
Support email security infrastructure (SPF, DKIM, DMARC) and respond to mail flow issues.
Compliance & Security
Support SOC 2 compliance efforts by maintaining system documentation, generating audit evidence, and remediating findings.
Participate in security reviews, vulnerability assessments, and policy enforcement activities.
Collaborate with the security function on DLP policies, CASB configurations, and data gover