veritree and Job Overview
veritree is an award-winning climate tech start-up based in Vancouver. Launched in 2021, our technology measures and verifies the impact of global restoration efforts from the ground up. We are on a mission to plant 1 billion verified trees by 2030, collaborating with businesses, planting organizations, and consumers who believe in the transformative power of verified restoration projects to create real and meaningful impact for the planet, nature, and people.
veritree is seeking an IT Engineer to support the veritree & tentree’s organizations. This role requires someone with IT experience able to be self-sufficient and manage the IT needs of two separate organizations that share resources. You must be able to work from our shared office several days a week, and as required by either group that you’ll be supporting.
6 Month Key Outcomes
-
Take full ownership of IT operations and end-user support with a smooth handover on both veritree and tentree, becoming the go-to owner for the device fleet, identity, and day-to-day support across the organizations.
-
Fully own and optimize our MDM solutions across the fleet - zero-touch enrollment, enforced hardening baselines, patching running smoothly across all devices - and complete the Windows MDM rollout.
-
Establish a solid security operations baseline - oversee our managed EDR provider, enforce MFA and least-privilege access across Google Workspace and SaaS, and put onboarding/offboarding and incident-response runbooks in place - leveraging AI tools to accelerate documentation and automation.
What You'll Do:IT Operations, Infrastructure & End-User Support
-
Provide responsive, high-quality end-user support across hardware, software, access, and connectivity.
-
Support core IT infrastructure - DNS, VPN, Wi-Fi, networking, SaaS platforms, and productivity tools.
-
Own IT asset, license, and vendor management - procurement, renewals, cost optimization, lifecycle tracking, and tool evaluation.
-
Create and maintain clear documentation, runbooks, and knowledge-base articles to make IT repeatable, auditable, and scalable.
Identity, Access & Endpoint Management
-
Administer Google Workspace and Microsoft 365 - users, groups, identity, licensing, SSO, and security/DLP policies.
-
Own the full onboarding/offboarding lifecycle and enforce MFA, least-privilege, and periodic access reviews across all systems.
-
Own the MDM platforms across the fleet - Mosyle MDM and Apple Business Manager for Apple, plus the Microsoft Intune rollout for Windows - driving zero-touch enrollment, app deployment, OS patching, and enforced hardening/security baselines across macOS and Windows.
-
Standardize device provisioning, inventory, and refresh processes, including mobile/BYOD where applicable.
Security Operations & Governance
-
Oversee our managed EDR provider and security monitoring/logging, and lead incident response end-to-end using MITRE ATT&CK.
-
Run the phishing and email security program (SPF/DKIM/DMARC, simulations, awareness training) and vulnerability management across endpoints, SaaS, and infrastructure.
-
Author and maintain security policies, runbooks, and a risk register, aligned to recognized frameworks (CIS Controls, NIST CSF).
AI & Automation
-
Leverage AI tools (e.g., Claude, ChatGPT, GitHub Copilot) to accelerate documentation, scripting, log/alert analysis, and troubleshooting.
-
Build automations and workflows (scripting, MDM automation, integration platforms) to reduce manual effort and human error.
Requirements
Qualifications
Professional Requirements or Qualifications-
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline - or equivalent hands-on experience.
-
3+ years of experience in IT operations / systems administration, with exposure to security-related fields, and the ability to own the IT function independently.
-
Proven experience managing device fleets via MDM - Apple (Mosyle, Jamf, Kandji, or similar, with Apple Business Manager) and/or Windows (Microsoft Intune / endpoint management), or a demonstrated ability to own an MDM rollout.
-
Strong Google Workspace administration experience (or comparable - Microsoft 365 / Entra ID).
-
Experience working across Linux, macOS, and Windows environments.
-
Demonstrated experience using AI tools (e.g., Claude, ChatGPT, GitHub Copilot) to improve documentation, troubleshooting, scripting, automation, and day-to-day IT operations.
-
Experience building workflow automation using PowerShell, Python, n8n, or similar scripting and integration platforms.
-
Networking fundamentals - DNS, VPN, Wi-Fi, and LAN/WAN.
-
Solid, practical grounding in cybersecurity operations: identity & access management, endpoint protection / EDR, MFA, phishing/email security, and security incident response.
Personal Strengths
-
Self-directed and comfortable owning ambiguity, setting standards, and building programs from the ground up.
-
Strong analytical and problem-solving skills with a security-first, risk-aware mindset.
-
An AI-forward mindset - actively uses modern tools to work smarter, automate the repetitive, and scale their impact.
-
Excellent communicator who can translate technical and security concepts for non-technical colleagues.
-
Able to balance and prioritize IT service delivery against proactive security work.
Nice to Haves (not mandatory)
-
Relevant industry certifications are a strong plus - e.g., CompTIA (Security+, Network+, A+), CISSP, CISM, CEH, SANS/GIAC, or vendor certifications (Apple, Microsoft, Google).
-
Experience self-managing an EDR/SIEM stack (e.g., SentinelOne, CrowdStrike, Splunk, Microsoft Sentinel) rather than solely relying on a managed provider.
-
Experience applying cybersecurity frameworks and methodologies such as MITRE ATT&CK, STRIDE, NIST CSF, or CIS Controls, or working with SIEM platforms such as Splunk, Microsoft Sentinel, or Elastic.
-
Experience with cloud security (AWS, Azure, or GCP) - securing cloud workloads, identities, and configurations.
-
Prior experience as the first / sole IT or security hire in a growing company.
Benefits
Benefits & Compensation Overview
At veritree, we recognize that compensation and performance development are key to attracting and retaining top talent. Our approach is grounded in fairness, transparency, and creating opportunities for growth as both our people and business scale.
Some highlights you can expect include:
-
Competitive salary with a performance-driven framework that ensures fair and consistent compensation reviews, tied to individual impact and business growth
-
Extended health, dental, and vision benefits
-
Additional Health Spending Account (HSA) / Lifestyle Spending Account (LSA) to support your well-being and lifestyle interests
-
A variety of time-off programs, including vacation, personal days, and a 4-week remote work program each year
-
Employee discount with tentree, our sister company
-
A flexible, hybrid work environment designed for collaboration and focus-driven impact
veritree ensures that compensation is reviewed fairly and consistently, with opportunities for salary progression tied to sustained performance. As such, the salary range for this role is $90,000 to $110,000 CAD.
This range is positioned around the 50th-75th percentile of market data we’ve collected, reflecting our commitment to competitive pay. Final offer amounts are based on individual experience and skillset of the candidate demonstrated during the recruitment process.
We reserve the >75th percentile of our salary ranges for internal employees who demonstrate sustained high performance and impact at veritree.
veritree is an equal opportunity employer. We are committed to building a team that represents diverse backgrounds, perspectives, and skills. All employment decisions are made on the basis of qualifications, merit, and business needs.