Location: Remote (Philippines)
What we offer
- 120,000 PHP/mo
- 100% permanent work from home
- 13th month pay
- HMO coverage commencing after one month
- Paid annual and sick leave
- Performance bonuses and annual salary reviews
- $500 AUD bonus for every Microsoft certification you pass — we pay for the exam, we give you study time, and you keep the certification. The path we’d like you on is SC-300, SC-401, MD-102, MS-700 and MS-102.
- Ownership of live incident response
- Genuine technical authority — you’ll set the standard, not follow one
Hours and conditions
Fixed dayshift, aligned to Australian Eastern time — 09:00 to 17:30.
Occasional after-hours work, roughly a couple of times a month, [compensated by time in lieu / paid at X].
On monitoring: we work inside client environments that hold healthcare and financial data, and we’re contractually accountable for how that access is used. Like the rest of our team — Australia and Philippines both — you’ll work with time tracking and session recording enabled. It’s an audit and client-trust requirement, not a performance-management one.
About us
We’re a security-led managed services provider based in Melbourne, Australia. We’ve been operating for 27 years, we’ve been recognised in the BRW Fast 100, and we look after small and medium businesses. We have a team of 22 with 10 in Australia and 12 in the Philippines.
It isn’t an outsourced back office — our PH engineers own client relationships, run projects, and sit in the same escalation path as everyone else.
We hire on four things: Ownership, Learning, Communication, and Fun.
The role
You’ll be the technical authority on Modern Workplace across our client base — designing and delivering Microsoft 365 solutions, leading migration and uplift projects, and acting as the highest technical escalation point in the team. We still have a few customers with on premise infrastructure.
We’re a security-focused MSP, predominantly around the ACSC Essential Eight. You’ll be hardening tenants, not just resetting passwords.
Security and incident response
Security isn’t a separate team here. It runs through the standard work: Conditional Access and MFA design, Endpoint configuration and alert triage, privileged access review, Essential Eight maturity uplift, and the tenant hygiene that stops incidents happening in the first place.
We respond to a small number of genuine security incidents each year — typically business email compromise, credential theft and data exposure events across our client base. You’ll lead those responses, with our Australian leadership team alongside you and our Level 2 engineers working under you.
What that actually looks like:
- You run the incident through a structured response process — preparation, identification, containment, eradication, recovery, and lessons learned. You own the tempo, the decisions and the evidence trail.
- The technical work: Entra ID sign-in and audit log analysis, unified audit log review, identifying inbox rules and OAuth consent grants left behind by an attacker, session revocation and credential rotation, and scoping exactly what data was accessed.
- The judgement calls that come with it — what to contain and when, what the evidence actually supports, and what the client needs to be told.
- Structured debrief afterwards. Every incident gets written up, taught back to the team, and turned into hardening we apply across the client base.
You’ll also develop the Level 2 engineers who work incidents with you. Building that bench is part of the role, not a favour you do on the side.
Where this role goes
This is the most senior technical role in the Philippines team, and it’s meant to grow beyond that.
You’ll set the technical standard for Modern Workplace across the business, shape how we deliver it, and build the engineers coming up behind you. For the right person there’s a path toward technical leadership — owning our service standards, our tooling decisions and our security practice.
Our company is growing and we will be promoting into team leader roles and roles within our Leadership team.
What you’ll be doing
- Design and deliver secure Microsoft 365 solutions based on what the client’s business actually needs
- Lead SharePoint work end to end — file server and third-party migrations, information architecture, permissions and sharing governance, Teams and SharePoint lifecycle
- Lead Exchange to Microsoft 365 migrations and Modern Workplace uplift projects
- Deploy and manage Intune, Entra ID, Conditional Access, MFA, Defender and Purview across client tenants
- Drive Essential Eight uplift and other security, governance and compliance work
- Get clients Copilot and other AI platforms ready — the permissions and oversharing cleanup that has to happen before a safe rollout, then the rollout itself
- Automate provisioning and administration with PowerShell, PnP PowerShell and Microsoft Graph
- Lead incident response, with Level 2 engineers working alongside you
- Act as the senior escalation point for our Level 1 and Level 2 engineers
- Engage directly with clients — understand their business, scope the work, and recommend solutions that fit
- Review and approve technical designs for complex projects
- Document your work properly — configurations, processes and standards
- Mentor junior engineers and lift the technical standard of the team
- Look for ways to improve client environments and our own operations through automation and AI tooling — we actively want engineers who use AI well
- Pass one agreed Microsoft certification within six months
What you’ll need
- Minimum 6 years in IT, including time in an MSP
- Minimum 3 years at Level 3 or Senior Systems Engineer level
- Deep hands-on Microsoft 365 experience, particularly SharePoint Online
- Prior client-facing experience in an MSP, including scoping and running projects
- Excellent spoken and written English — you’ll be on the phone with clients frequently.
- The judgement to make a call under pressure and own the outcome
- Experience using AI tools for troubleshooting, documentation and service delivery
- A current Microsoft role-based certification — ideally SC-300, SC-401, MD-102, MS-700 or MS-102
Technical skills
Core — you should be strong here
- SharePoint Online — migrations (ShareGate or Migration Manager), information architecture, permissions and sharing governance
- Microsoft 365 (Exchange Online, Teams, OneDrive at scale, Known Folder Move)
- Microsoft Entra ID, Conditional Access, MFA and guest/B2B access
- Microsoft Intune
- Microsoft Purview — sensitivity labels, DLP, retention
- PowerShell, PnP PowerShell and Microsoft Graph
- Networking — routers, switches, firewalls, VPNs, VLANs, DNS, DHCP
- RMM and PSA tooling (we run ConnectWise Manage, Automate and ScreenConnect)
- Backup platforms (Veeam, StorageCraft, or equivalent)
- Endpoint security platforms (Microsoft Defender, Sophos, Huntress and ThreatLocker)
- Clear technical documentation
Advantageous
- Microsoft Copilot deployment and readiness work
- Windows Server and Active Directory
- Hyper-V
- Exchange Server, particularly hybrid
- Microsoft Azure
- Essential Eight, ISO 27001 or similar framework exposure
- Power BI, Linux
To apply
Send your CV along with a short note covering: the most interesting technical problem you’ve solved in the last year, and where you want your career to be in three years.