Enterprise IT Engineer

PhysicsX · New York, United States

  • Senior
  • Full-time
  • Posted 2026-09-14
  • Confirmed live on 25 September 2026

Apply at PhysicsX

Job description

About us

Re-architecting Engineering for the Age of Intelligence

PhysicsX is the physics AI company for industrials. The company’s mission is to accelerate hardware innovation by overhauling what industrial engineering and manufacturing look like today. PhysicsX is building a new simulation software stack to deliver deep physics AI enablement across the entire engineering lifecycle. The company partners with leading organisations in aerospace & defence, automotive, semiconductors, materials, and energy & renewables, supporting them on some of their most critical and complex challenges. PhysicsX is headquartered in the United Kingdom, with offices in London, New York, and Singapore and an expanding presence in the Bay Area.

The Role

Who we’re looking for

• Someone who has designed and owned enterprise identity (Entra ID/Azure AD) at a company of meaningful size, not just administered an existing tenant.

• A person who treats zero trust as an architecture to build, not a buzzword to reference. Conditional access, device trust and posture validation, and least privilege as defaults.

• Someone who's comfortable owning MDM (Intune, Jamf, or similar) end-to-end: enrollment, compliance policy, patching, and lifecycle, across a mixed-OS fleet.

• A collaborative operator who partners well with security, platform engineering, and the wider business.

• Hands-on experience deploying and operating a SASE platform (e.g., Cloudflare One, Zscaler) in production, including policy design, not just administration of an existing setup.

What you will do

• Own and evolve our Microsoft Entra ID environment: identity architecture, conditional access policies, MFA, PIM, SSO/SCIM integrations, and hybrid identity where relevant.

• Manage enterprise infrastructure as code in Terraform (identity, networking, and security tooling), so that configuration is versioned, reviewable, and repeatable.

• Design and implement zero trust network access, replacing legacy VPN patterns with modern SASE-based access control.

• Own MDM strategy and operations across the device fleet (macOS/Windows/Linux/Mobile): enrolment, compliance baselines, patch management, and endpoint security posture.

• Partner with the platform/DevOps team to keep enterprise IT and cloud (AWS, GCP, Azure) security postures are aligned and consistent.

• Lead access reviews, least-privilege enforcement, and identity governance work to support audits and compliance requirements (e.g., SOC 2, ISO 27001).

What you bring to the table

• 5 - 10 years of experience in enterprise IT, security engineering, or identity/infrastructure roles, with deep, hands-on ownership of Microsoft Entra ID/Azure AD in production.

• Deep Conditional Access policy design experience, not just enabling MFA, but building risk based, device aware access rules.

• Experience with Entra ID Governance: Access Reviews, Identity Protection, Privileged Identity Management (PIM) at scale.

• SSO/SAML/OIDC federation and SCIM provisioning across a meaningful number of enterprise apps.

• Endpoint security tooling experience: EDR platforms (CrowdStrike, Defender for Endpoint, or similar)

• Scripting and automation ability (PowerShell, Python, or Microsoft Graph API) to automate identity and device workflows.

• Experience with hybrid identity (Entra Connect or on prem AD sync).

• Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP, able to translate control requirements into actual technical implementation (access reviews, logging, encryption, change management), not just pass an audit checklist.

Nice to have skills

• Experience with Cloud IAM and security architecture, AWS IAM Security Center, Google Workforce Identity Federation, and how it interacts with enterprise identity (Entra) via federation.

• Compliance automation experience (Vanta, Drata)

• Experience with Cloudflare Zero Trust.

• Exposure to SIEM/EDR/XDR tooling and correlating identity signals with broader security monitoring.

• Background at an AI or high-growth SaaS company.

• Experience supporting UK/EU data protection requirements (e.g., GDPR) from an identity and access standpoint.

• Certifications (good to have, not required)

• Microsoft Certified: SC-300

• Microsoft Certified: SC-100

• Microsoft Certified: MD-102

• CompTIA Security+

• Certifications from your SASE vendor of choice (e.g., Cloudflare Certified, Zscaler Certified)

• CCNA

What we offer

Build what actually matters

Help shape an AI-native engineering company at a formative stage, tackling problems that genuinely matter for industry and society. This is work with real-world impact - and something you can be proud to stand behind.

Learn alongside exceptional people

Work with a high-caliber, collaborative team of engineers, scientists, and operators who care deeply about doing great work, and about helping each other get better. We come from diverse backgrounds, but we share a commitment to operating at the highest level an

Prepare for the interview

Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.

More at PhysicsX

All open software jobs