Senior IT & Security Engineer (AI-Native)
Are you a Senior IT & Security Engineer ready to take your career to the next level? Join WorkFlex, a fast-growing European startup, and make an impact from day one!
🚀 We Don't Have an Office. We Still Have IT.
Most companies scale IT by hiring more admins to answer more tickets. We'd rather hire one engineer who automates the tickets out of existence.
WorkFlex is a remote-only company. Our "office" is ~140 laptops (half Windows, half Mac) spread across beaches, mountains, and home offices around the world. Your mission: build the identity, device, and security platform for a company that holds ISO 27001 and is heading toward C5 / SOC 2 Type 2.
The starting position is rare: no legacy Active Directory, no on-prem servers, no office network. A greenfield with a clear mandate to build.
🌍 The Lifestyle: 183 Days of Workations
We are a remote-only company. You can work from a beach, a mountain, or your home office. We offer 183 days of workations per year because we believe the best solutions come from people who are inspired by their surroundings. Your platform has to survive hotel Wi-Fi and captive portals. You'll be building for exactly the life you're living. Note: for data protection and security reasons, we hire EU-based only for this role.
🛠️ The Workflow: AI-Native IT
At WorkFlex, we operate differently. If your happy place is clicking through admin portals all day, you are the wrong profile.
Automation over administration: You script against the Microsoft Graph API, keep configuration as code, and let agents handle the routine.
Orchestration over grinding: You use Claude Code, self-hosted n8n, and agentic workflows to build internal tooling at a speed that was impossible two years ago.
End-to-end ownership: You design it, you build it, you run it. Spending decisions are made together with the Head of Technology. No committees.
🎯 What You Will Do
Mission #1: Zero-touch mixed fleet. Roll out device management across ~140 laptops in a dozen+ countries: Intune and Autopilot for Windows, Apple Business Manager plus the MDM of your choice for Mac. New devices ship straight from the supplier to the new hire and enroll themselves. This is as much change management as engineering.
Own the full device lifecycle. Procurement, cross-border shipping, retrieval, secure wiping, repairs, replacements, re-deployment. Hardware logistics without an office is hard. Whether the answer is a lifecycle partner or a better process is your call.
Make identity the control plane. Entra ID at the center: Conditional Access, phishing-resistant MFA (passkeys), just-in-time admin access, and a role-based permission model with recurring access reviews.
Own security engineering. Endpoint protection, email security, phishing simulations, patching and vulnerability management, hardening baselines, incident-response readiness. Deep forensics stays with our external partner on retainer.
Own IT onboarding and the whole joiner-mover-leaver lifecycle. HRIS-triggered provisioning (Personio), built with our People & Culture team: accounts, groups, licenses, and hardware ordered automatically by role. A new hire's first day should just work. Offboarding is one trigger that revokes everything, everywhere.
Own the internal SaaS landscape. Tool administration grew organically across teams. You centralize it, then run it for good: inventory, admin ownership, access management, governance, and licensing. SCIM where possible, shadow-IT discovery, license optimization as routine. Functional ownership of each tool stays with the teams.
Own real architecture debates. We hold a few deliberate, non-obvious positions on identity and blast radius. We share specifics in the interviews, not in a public job ad. You get to challenge or harden them.
Evolve our zero-trust network. A self-hosted, WireGuard-based overlay provides defense in depth. DevOps operates it; you shape access policy and device posture. There is no VPN estate to babysit.
Build our internal IT agent. An AI assistant in Teams that handles routine requests and runs safe self-service actions behind approval gates, with a full audit trail.
Feed the auditors automatically. Evidence pipelines (device compliance, access reviews, JML logs) for ISO 27001 surveillance and our path toward C5 / SOC 2 Type 2. The ISMS is already in place.
Set AI guardrails without killing the culture. We use Claude Team, Gemini, and self-hosted n8n heavily, and people choose their own tools. You add the data boundaries that keep it that way.
⭐ What You Need to Succeed
Experience: 4+ years running modern Microsoft-stack IT (Entra ID / M365, ideally Intune). You have designed and operated environments, not just closed tickets in them. Mixed-fleet experience with macOS, or a credible plan to get there.
An engineer's toolkit: Fluent in PowerShell, Python, or TypeScript and comfortable with the Microsoft Graph API. If you do something twice in a portal, you script it before the third time.
Security engineering chops: You have rolled out EDR, hardened email authentication, and know your way around CIS baselines.
AI-native instincts: You are already a power user of Claude and LLM tools. You know how to prompt, chain, and audit AI output, and you know when generated code is robust and when it's a hallucination.
Zero-trust literacy: Conditional Access, device posture, least privilege, break-glass procedures. Familiarity with WireGuard-based tools (NetBird, Tailscale) is a plus.
Communication mastery: You can sit with a non-technical colleague, listen to their frustrations, and translate them into a solution. You can say no without condescension. You are a listener first, an engineer second.
Self-sufficiency: You define your own roadmap based on where you create the most value. You report directly to the Head of Technology. Your peers are Applied AI Engineers who do for single departments what you do for the whole company.
Trustworthiness: You will hold the keys to everything. Least privilege applies to you, too.
EU-based, English C1+. The whole company runs in English.
➕ Bonus Points
Dedicated Apple MDM experience (Jamf, Kandji, Mosyle)
ISO 27001 / C5 / SOC 2 audit experience on the evidence-providing side
Personio or other HRIS integrations; n8n
Device logistics in a distributed company (procurement, drop-shipping, retrieval)
You have been a one-person IT team and built it so it didn't depend on you being awake
📈 What Success Looks Like After Year One
The full fleet is enrolled and compliant, and people barely noticed.
The security baseline (endpoints, email, patching) is deployed, enforced, and boring.
New hires are productive on day one without anyone touching their laptop. Offboarding takes minutes, and the returned laptop is wiped and back in circulation.
Access reviews run on schedule, and the technical controls for C5 / SOC 2 Type 2 are audit-ready.
Most routine requests resolve via self-service or the Teams agent. There is no pager, because you automated around the time zones.
You still spend most of your week building, because the machine runs itself.
🚀 Why join us at WorkFlex
Contribute to building the future of the fastest-growing HR tech startup in Germany backed by prominent customers such as Scout24, Vodafone, BioNTech, and others, as well as funding from top-tier VC and angel investors.
Competitive salary and VSOPs (Virtual Stock Options) to share in our success.
A monthly budget of €200 to spend on 🏢 co-working space and/or 🏃♀️ sports subscriptions.
Work from anywhere in a remote-only company and go on workations for up to 183 days a year.
Merit-based culture with substantial growth opportunities.
Trust-based work – organize your own schedule. We want to celebrate results, not hours spent working.
Collaborative team culture where everyone's input is valued to shape sales efforts, approaches, and processes.
We may use AI-assisted tools to support parts of our recruitment process. These tools help our team review applications more efficiently, and all hiring decisions are made by humans.
- Department
- Engineering
- Role
- Senior IT & Security Engineer
- Remote status
- Fully Remote
About WorkFlex
Founded in 2021, WorkFlex was created to transform how companies manage international travel compliance. Instead of relying on expensive legal consultations and slow processes, our platform makes it easy to stay compliant across business travel, remote work, and expat scenarios – automated, scalable, and stress-free.
Today, over 100,000 trips are processed annually on WorkFlex, and our team continues to grow globally. We’re proud to support 500+ companies including BioNTech, Vodafone, dm, Flix, and Scout24 – and we’re just getting started.