Systems Engineer Lead
Job description
About the role
The is responsible for defining and directing the Systems Engineering discipline within Corporate IT, ensuring the stability and performance of critical infrastructure. This role owns the strategic direction for identity infrastructure centered on Microsoft Entra ID, driving efforts to consolidate and standardize configurations across the enterprise. The position requires a technical strategic thinker who brings structure to complexity, actively improving observability, reliability, and operational excellence. You will act as the primary owner for end-to-end identity and access management processes, ensuring they enable business productivity rather than creating friction. This role operates at the intersection of technical execution and leadership, guiding governance and best practices for a distributed IT organization. The position is accountable for transforming fragmented systems into coherent, scalable platforms that support global operations. You will influence engineering culture by treating IT as a disciplined engineering function focused on automation and measurable outcomes. This role reports to the Head of Global IT and serves as the technical leader for the Systems Engineering function across the EU and Americas.
Key facts
What you'll do
You will orchestrate intake workflows to define identity requirements and streamline access requests across regions, reducing manual intervention and errors. Designing and building pipelines will harden Microsoft Entra ID and standardize configurations for business platforms to ensure consistency and security. You will guide review cycles for access policies and audit AI tool permissions, including Copilot and Cursor governance, to maintain compliance and least privilege. Shipping changes that enhance stability and performance is a core responsibility, achieved through careful rollout strategies, monitoring, and feedback loops. You will forge strong partner links with Security, Compliance, and Endpoint Management to align identity, device, and security rules across the organization. Automating lifecycle workflows for joiners, movers, and leavers will ensure robust governance for both human and non-human identities at scale and reduce operational risk. Establishing guardrails for AI platforms involves defining data boundaries, acceptable use policies, and maintaining audit clarity for Langdock usage and related tools. Leading the consolidation of core configurations will transform fragmented setups into coherent structures under strict ownership, improving reliability and maintainability. You will build and lead a team of systems engineers, setting clear expectations, providing mentorship, and supporting career growth and professional development. This role will collaborate closely with product, design, and operations teams to deliver reliable digital experiences that support business objectives.
Requirements
You must hold five or more years of experience in IAM or Systems Engineering, with hands-on work using Azure Entra ID, Okta, or OneLogin to manage complex identity environments. Demonstrating scripting mastery in PowerShell, Bash, or Python is required to automate JML processes and routine tasks, ensuring efficiency and consistency. You must design systems that prevent access issues before they reach the helpdesk, applying cloud identity expertise around SCIM and OIDC for seamless integration and user provisioning. Managing high-level administrative permissions while navigating strict least privilege environments is essential to maintain security and regulatory compliance. You must view technical debt and inconsistent configurations as opportunities to build structure rather than obstacles, driving improvements across the system landscape. You should have a proven track record of owning end-to-end responsibility for systems and processes, taking initiative to identify problems and implement lasting solutions. Strong communication skills are required to align stakeholders, document decisions, and articulate technical concepts to both technical and non-technical audiences. You must be comfortable working in a fast-paced, dynamic environment where priorities evolve based on business needs and emerging risks.
Nice to have
Prior experience guiding AI tooling adoption and scaling internal engineering in complex fintech contexts is valued, particularly where regulatory and security considerations intersect with technology decisions.
Skills & tools
Proficiency with Microsoft Entra ID, AI tools, Copilot, Cursor, Langdock, SSO, and Endpoint Management is required to perform the responsibilities of this role effectively. You should have hands-on experience with infrastructure as code, monitoring tools, and automation platforms that support identity and security operations. Knowledge of CI/CD principles as they apply to system and configuration management is expected. Experience with logging, metrics, and alerting tools will help you drive improvements in observability and incident response. You must be familiar with security frameworks and compliance requirements relevant to financial services and data protection regulations.
Practical notes
This role is based in Barcelona, Spain, with additional consideration for Berlin, Germany, and Sofia, Bulgaria. It engages Corporate IT on a global scale, covering EU and Americas operations as part of SumUp's international footprint. The position offers a compensation range of 65000 to 85000 EUR. Please ensure you are able to commit to full-time hours and are prepared to work closely with cross-functional teams across different time zones. No specific visa sponsorship details are provided in the source material. There are no application deadlines communicated in the source; interested candidates should contact the hiring team directly through official SumUp channels.