IT & Security Administrator / Manager (m/f/d)
Summary
Own and secure the company’s IT stack (Microsoft 365, Entra ID, Intune) while preparing for ISO 27001 and NIS2 compliance in a fast-growing robotics firm based in Munich.
Hive Robotics is building Europe's first full-stack orchestration platform for unmanned systems: connecting, controlling, and commanding multi-vendor drone and robot swarms. Our RF communication systems are Made in Germany, deployed on active frontlines, and targeting a highly valued tactical communication market with zero sovereign alternatives today.
As our first dedicated IT & Security Administrator / Manager, you own IT for the whole company. You take our modern cloud-first environment (Microsoft 365, Entra ID, Intune) and make it complete, enforced, and ISO 27001 / NIS2-ready. You run it day to day, shape the decisions behind it, and are the face of IT for the entire team. You report to the SVP Finance & Operations.
This role is hands-on by design: devices, networks, and people are in the office. Some remote flexibility is possible once the fleet is fully under management. IT Operations & User Support
Must Have
As our first dedicated IT & Security Administrator / Manager, you own IT for the whole company. You take our modern cloud-first environment (Microsoft 365, Entra ID, Intune) and make it complete, enforced, and ISO 27001 / NIS2-ready. You run it day to day, shape the decisions behind it, and are the face of IT for the entire team. You report to the SVP Finance & Operations.
This role is hands-on by design: devices, networks, and people are in the office. Some remote flexibility is possible once the fleet is fully under management. IT Operations & User Support
- Be the first point of contact for IT support across the company: fast, pragmatic, and service-oriented
- Own IT onboarding: workstation setup, accounts, and day-one enablement for every new joiner
- Administer Microsoft 365 (Exchange, Teams, SharePoint, OneDrive) and our business SaaS stack (e.g. Personio, DocuSign, DATEV interfaces): seats, access reviews, admin hygiene
- Operate the on-site network and office infrastructure: UniFi servers, WiFi, VLAN segmentation, VPN / remote access, printers, AV, and meeting rooms
- Provide workstation and network enablement for our on-site production pilot line
- Prepare and scale our IT systems and processes for the team's growth
- Steer our external IT service provider and take over responsibilities step by step, in coordination with Operations
- Operate and complete our Intune-based device management across macOS, Linux and Windows: enrollment, configuration profiles, compliance policies, and update rings
- Enforce full-disk encryption (FileVault / BitLocker) with recovery key escrow across the entire fleet
- Manage company smartphones (supervised, zero-touch enrollment)
- Own the hardware lifecycle: procurement, imaging, asset register, secure disposal, and the IT budget behind it, in coordination with Finance & Operations
- Administer the Microsoft Entra ID tenant, including users, dynamic groups, Conditional Access, license management, and the automated HR-driven provisioning sync
- Run the rollout of phishing-resistant MFA (hardware security keys) across the company
- Make joiner / mover / leaver a same-day process: a new hire is productive on day one, a leaver's access is revoked within the hour
- Introduce and run a lightweight ticketing and ITSM process (e.g. Jira Service Management) with clear priorities and response targets
- Build and maintain IT documentation: runbooks, network and system documentation, and a self-service knowledge base
- Draft and enforce practical IT policies aligned with ISO 27001: acceptable use, password / MFA, onboarding and offboarding checklists
- Own software asset and license management across our SaaS and desktop software: seats, renewals, cost control, and shadow IT
- Support open source software compliance together with engineering: license register, SBOM tooling, and scanning in the development pipeline
- Implement and operate the security baseline: endpoint protection, patch and vulnerability management, email security, backup with regular restore testing for Microsoft 365, and secrets management for our source-code repositories
- Manage on-site physical security systems: cameras, access control, and alarm infrastructure
- Support data classification and the secure handling of sensitive and export-controlled information
- Perform basic security and privacy reviews of new tools and vendors before rollout
- Maintain the asset and access documentation that ISO 27001 and NIS2 audits require, such as device inventory, access logs, and restore evidence
- Support security awareness measures, train the team on them, and contribute to incident response processes
Must Have
- 5+ years in internal IT administration, ideally in a growing company
- Hands-on device management experience with a modern MDM, Intune strongly preferred (macOS, Linux and Windows)
- Solid Microsoft 365 / Entra ID administration: users, groups, Conditional Access basics, licensing
- Working knowledge of security architecture and the regulation behind it, in particular ISO 27001 and NIS2
- Security-first mindset: you treat an unencrypted or unmanaged device as an incident, not a backlog item
- Strong service mentality: people enjoy asking you for help, and the project work still gets done
- Structured working style: you document what you build and turn repeatable tasks into processes, checklists, and tickets
- Fluent English and German
- Based in Munich or willing to relocate
- Hands-on experience in an ISO 27001 certification or NIS2 implementation project
- Scripting for fleet automation (PowerShell, Bash, or Python)
- Business network administration experience (WiFi, VLANs, VPN)
- Endpoint security / EDR operation experience
- Prior work in defense, aerospace, security, or another regulated environment
- Experience with software asset management or open source license compliance (license registers, SBOM tooling)
- Experience building an IT function from scratch rather than inheriting one