Level 2 IT Systems Engineer

Location: Remote (Philippines)

What we offer 

  • PHP 80,000 per month 
  • 100% permanent work from home 
  • 13th month pay 
  • HMO coverage commencing after one month 
  • Paid annual and sick leave 
  • Performance bonuses and annual salary reviews 
  • $500 AUD bonus for every Microsoft certification you pass — we pay for the exam, we give you study time, and you keep the certification. The path we’d like you on is MS-102, MD-102 and SC-300. 
  • Supervised incident response experience 
  • A defined progression path to Level 3 

Hours and conditions 

Fixed dayshift, aligned to Australian Eastern time — 09:00 to 17:30. 

Occasional after-hours work, roughly a couple of times a month, [compensated by time in lieu / paid at X]. 

On monitoring: we work inside client environments that hold healthcare and financial data, and we’re contractually accountable for how that access is used. Like the rest of our team — Australia and Philippines both — you’ll work with time tracking and session recording enabled. It’s an audit and client-trust requirement, not a performance-management one. 

About us 

We’re a security-led managed services provider based in Melbourne, Australia. We’ve been operating for 27 years, we’ve been recognised in the BRW Fast 100, and we look after small and medium businesses. We have a team of 22 with 10 in Australia and 12 in the Philippines. 

It isn’t an outsourced back office — our PH engineers own client relationships, run projects, and sit in the same escalation path as everyone else. 

We hire on four things: Ownership, Learning, Communication, and Fun. 

The role 

You’ll deliver remote support and project work across a portfolio of Australian SME clients, working primarily in the Microsoft 365 and modern workplace stack. We still have a few customers with on premise infrastructure. 

We’re a security-focused MSP, predominantly around the ACSC Essential Eight. You’ll be hardening tenants, not just resetting passwords. 

Security and incident response 

Security isn’t a separate team here. It runs through the standard work: Conditional Access and MFA design, Defender configuration and alert triage, privileged access review, Essential Eight maturity uplift, and the tenant hygiene that stops incidents happening in the first place. 

Then there’s the part that almost no Level 2 role anywhere will offer you. 

We respond to a small number of genuine security incidents each year — typically business email compromise, credential theft and data exposure events across our client base. When one happens, our Level 2 engineers are in the response, not watching it. 

What that actually looks like: 

  • You work the incident alongside a senior engineer through a structured response process — preparation, identification, containment, eradication, recovery, and lessons learned. Not improvisation. A method you’ll be taught and then expected to run. 
  • Hands on the real work: pulling and interpreting Entra ID sign-in and audit logs, unified audit log review, identifying inbox rules and OAuth consent grants left behind by an attacker, session revocation and credential rotation, scoping what data was actually accessed. 
  • Structured debrief afterwards. Every incident gets written up and taught back to the team. 

Why this matters for your career: incident response experience is the single hardest thing to get in this industry, because you can’t practise it on demand and most MSPs quarantine it to their most senior people. We think that’s backwards. Engineers who have worked live incidents build better environments, because they’ve seen exactly how environments fail. 

To be clear about the trade: incidents are infrequent and unscheduled. Most weeks are project and support work. But when one lands, you’re in it, you’re supported, and you’ll come out of it a materially better engineer. 

Where this role goes 

We don’t hire Level 3 engineers. We grow them. 

This role comes with a defined path to Level 3: structured escalation exposure, mentoring from our senior engineers, a funded certification path, and progressively larger project ownership. If you want to be a senior Microsoft 365 and security engineer in three years, tell us — that’s exactly who we’re looking for. 

What you’ll be doing 

  • Own client issues end to end — resolve them, or escalate them properly, and keep the client informed either way 
  • Deliver support and small projects across Microsoft 365, Entra ID, Intune and SharePoint 
  • Work on client security posture — MFA and Conditional Access, Defender configuration, Essential Eight uplift 
  • Participate in incident response under supervision when incidents occur 
  • Own the monitoring and backup queues, and the tickets they generate 
  • Act as an escalation point for, and mentor to, our Level 1 engineers 
  • Document your work properly and record your time as you go 
  • Look for ways to improve client environments and our own operations through automation and AI tooling — we actively want engineers who use AI well 
  • Pass one agreed Microsoft certification within six months 

What you’ll need 

  • Minimum 3 years in IT supporting small and medium business environments 
  • Prior client-facing experience in an MSP 
  • Excellent spoken and written English — you’ll be on the phone with customers frequently. 
  • Strong troubleshooting instincts and the confidence to own a problem 
  • Experience using AI tools for troubleshooting, documentation and service delivery 
  • A current Microsoft role-based certification, or a fundamentals certification (MS-900 or AZ-900) plus a clear intent to certify further 

Technical skills 

Core — you should be strong here 

  • Microsoft 365 (Exchange Online, SharePoint, Teams, OneDrive) 
  • Microsoft Entra ID, Conditional Access and MFA 
  • Microsoft Intune 
  • Windows 10 and Windows 11 
  • Networking — routers, switches, firewalls, VPNs, VLANs, DNS, DHCP 
  • RMM and PSA tooling (we run ConnectWise Manage, Automate and ScreenConnect) 
  • Backup platforms (Veeam, StorageCraft, or equivalent) 
  • Endpoint security platforms (Microsoft Defender, Sophos, Huntress and ThreatLocker) 
  • Clear technical documentation 

Advantageous 

  • PowerShell scripting 
  • Windows Server and Active Directory 
  • Hyper-V 
  • Exchange Server, particularly hybrid 
  • Essential Eight, ISO 27001 or similar framework exposure 
  • Power BI, Linux 

To apply 

Send your CV along with a short note covering: the most interesting technical problem you’ve solved in the last year, and where you want your career to be in three years.