The role spans two halves of the same job: the day-to-day IT platform that a global workforce depends on (endpoints across Linux, Windows, and macOS, identity, VPN, backups, MDM, and the SaaS estate) and the security engineering program that protects it, from vulnerability management and incident response through cloud, network, and Kubernetes hardening. Scope of Ownership: Owns the full lifecycle of IT hardware and software across Linux, Windows, and macOS (including the asset inventory and the employee onboarding and offboarding process) together with client's security operations stack: vulnerability management, HIDS/SIEM, secrets and PKI, cloud and network security controls, and identity administration.