Information Technology Specialist

Trailhead Biosystems
Trailhead Biosystems

IT · Full-time

Beachwood, OH, USA

Posted on Oct 8, 2026

Responsibilities

End-User Support & IT Operations

  • Primary internal point of contact for all hardware, software, connectivity, and access issues across on-site and remote employees
  • Manage the MSP relationship: define what goes to them, hold them to SLAs, and escalate appropriately
  • Manage the full device lifecycle: procurement, imaging, deployment, and decommissioning
  • Administer Microsoft 365: Entra ID, Exchange Online, SharePoint, Teams, OneDrive, and associated licenses
  • Own IT onboarding and offboarding workflows, account provisioning, device assignment, access revocation, and litigation hold procedures; this process must be airtight and documented
  • Maintain a current IT asset inventory

Cybersecurity & Information Security

  • Handle the organization's day-to-day security posture; engage the MSP for complex security projects and escalations
  • Administer endpoint protection, patch management, MFA enforcement, and conditional access policies
  • Monitor M365 security and compliance tooling: Purview, Defender for Business, audit logs
  • Conduct periodic access reviews and permission audits; produce findings reports for management
  • Lead first-response on security incidents: containment first, investigation second and coordinate MSP escalation where needed; this includes employee departure scenarios involving potential data exfiltration
  • Manage email authentication controls (SPF, DKIM, DMARC) and anti-phishing policies
  • Manage security and access governance for AI/LLM tools in use across the org, enforce least-privilege access, MFA, and conditional access on AI service accounts, app registrations, and admin roles
  • Gate and process access requests for AI infrastructure (Azure OpenAI, Entra app registrations, Key Vault, etc.) submitted by AI/data engineering staff, approve or deny per policy, and escalate architecture or capability decisions to the appropriate technical owner
  • Support enforcement of the company's AI usage policy, approved tools, data classification for AI inputs, and prohibition of unsanctioned "shadow AI" tools in coordination with outside AI policy/training vendors

Lab & Instrument IT

  • Maintain network connectivity for laboratory instruments and manage isolated VLANs where required
  • Serve as the IT interface for lab instrument vendors and cloud-connected instrument platforms (e.g., SaaS-connected analytical instruments, vendor cloud dashboards)
  • Administer and secure internally hosted lab/process data systems including server-level access control, patching, and credential lifecycle management, with access revoked immediately upon staff or contractor departure
  • Keep instrument computing hardware and software licenses

Access & Device Governance

  • Deploy and administer an MDM solution across the full device fleet
  • Handle permissions governance for end-user systems: M365, SharePoint, shared drives, and SaaS applications
  • Manage data lifecycle for off-boarded employees including legal preservation requirements

Cloud Cost & Vendor Management

  • Monitor cloud and SaaS spend; surface optimization opportunities and eliminate unused licenses
  • Manage all software subscriptions across office and lab environments licenses, renewals, utilization tracking, and vendor relationships for both business software and laboratory-specific applications
  • Coordinate with the Data Infrastructure Engineer on cloud access provisioning
  • Track IT vendor contracts and MSP deliverables; flag renewal dates and surface consolidation opportunities

IT Policy & Documentation

  • Maintain core IT policies: Acceptable Use, Data Classification, Password Policy
  • Document processes and configurations well enough that someone else could operate them

Qualifications

  • 3–5 years of hands-on IT experience in a generalist role
  • Microsoft 365 administration: Entra ID, Exchange Online, SharePoint, Intune/MDM
  • Endpoint security: patch management, MFA/conditional access, Defender for Business or equivalent
  • Experience managing network hardware: switches, enterprise Wi-Fi, firewall rules
  • MDM deployment and administration experience (Intune, Jamf, or Kandji)
  • Strong documentation discipline
  • Clear communicator with both non-technical staff and external technical partners
  • Preferred: exposure to securing AI/LLM tooling and cloud AI services access governance and conditional access, not AI/ML development
  • Preferred: experience with networked lab/scientific instrumentation and vendor-managed cloud platforms