
A Hub AB · Malmö
Are you ready to play a key role in shaping Lindab Group's Identity & Access Management strategy and digital transformation? As a Service Owner Infrastructure –...
Are you ready to play a key role in shaping Lindab Group's Identity & Access Management strategy and digital transformation? As a
Service Owner Infrastructure – AD/Entra, you will be part of Lindab Group's Infrastructure & Operations (I&O) team, responsible
for the ownership, governance, and continuous development of the company's identity services based on Microsoft Active Directory
and Microsoft Entra ID.
Lindab Group is on an exciting journey to modernize and strengthen its IT capabilities. In this role, you will have a unique
opportunity to drive the evolution of the organization's identity platform, ensuring secure, scalable, and efficient
authentication and authorization services across the enterprise. You will collaborate closely with stakeholders across the
business, security teams, external service providers, and IT colleagues to ensure that identity services support both operational
excellence and business growth.
Your expertise in identity management, service ownership, security, and cloud technologies will be instrumental in delivering
secure and user-friendly services that enable Lindab's digital future.
You will report to the Manager for Infrastructure Services.
resolution and continuous service improvement.
ID, and related authentication services, ensuring service resilience and operational continuity.
IS/IT strategy.
ID.
(MFA), Privileged Identity Management (PIM), Identity Governance, and related capabilities.
improved.
excellence.
organization.
(PIM), and Identity Governance.
TO SUCCEED IN THIS ROLE, WE BELIEVE YOU HAVE THE FOLLOWING SKILLS
Does this sound like the opportunity you’ve been looking for? Join Lindab Group and play a key role in shaping our digital future!
Start: Per agreement
Location: Malmö, Sweden
This recruitment process is handled by A-hub, and at Lindab Group’s request, all inquiries regarding this position will be managed
by A-hub and Linus Nilsson.
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Identity, AI and Data Access Governance Lead is responsible for governing who, and what, can access DTS systems, data, APIs, tools, workflows and AI-enabled capabilities. This is a hands-on governance and control role, reporting into the SVP Security and Compliance. The role ensures that access across DTS is appropriate, auditable, reviewed, least-privileged and aligned with security, privacy, compliance and client commitments. The scope covers traditional human access, external users, privileged access, service accounts, machine identities, API keys, tokens, dataset access, and the emerging governance of AI agents and agentic workflows. The role will work closely with Architecture, Security, Product, Engineering, Infrastructure, Privacy, Legal/DPO, TechOps, Enterprise Technology and the ISMS and Risk Officer to ensure DTS has a clear and controlled model for access across platforms such as WPP Open, Choreograph, InfoSum, Open Intelligence, Resolve and related DTS capabilities. What you'll be doing: 1. IDENTITY AND ACCESS GOVERNANCE FRAMEWORK Define and maintain the access governance framework for DTS. This includes: * Defining access governance standards, processes and control expectations. * Establishing how access should be requested, approved, provisioned, reviewed, revoked and evidenced. * Ensuring access governance covers internal users, external users, clients, partners, vendors, service accounts, machine identities and AI agents. * Aligning identity and access governance with DTS architecture, security, privacy, compliance and data governance requirements. * Ensuring access governance is practical for product and engineering teams to implement. 2. ACCESS REVIEWS AND RECERTIFICATION Own the process for regular access reviews and recertification across DTS. This includes: * Defining the scope, frequency and evidence requirements for access reviews. * Coordinating access reviews for critical DTS systems, production environments, privileged roles, sensitive datasets, client-facing platforms and administrative tools. * Ensuring access review outcomes are tracked, remediated and evidenced. * Identifying stale, excessive, orphaned or poorly owned access. * Escalating overdue, high-risk or unresolved access issues through the appropriate governance channels. 3. PRIVILEGED ACCESS GOVERNANCE Ensure privileged access across DTS is properly controlled, justified and auditable. This includes: * Reviewing access to production systems, cloud environments, security tools, databases, CI/CD tooling, administrative consoles and sensitive platforms. * Supporting least-privilege, just-in-time and time-bound access models where appropriate. * Working with Cloud and Platform Security and Infrastructure to improve privileged access controls. * Ensuring privileged access risks are visible in the DTS risk register where required. 4. EXTERNAL USER, CLIENT AND PARTNER ACCESS GOVERNANCE Govern access for external users, clients, agencies, partners and vendors. This includes: * Defining standards for external user onboarding, approval, permissions, expiry and offboarding. * Ensuring external access has a clear business owner and justification. * Supporting access governance across client workspaces, agency environments, partner integrations and shared collaboration areas. * Working with Product and Engineering to ensure tenant, workspace and client-level isolation is appropriately governed. * Tracking risks related to stale accounts, vendor access, partner permissions and external user overprivilege. 5. SERVICE ACCOUNT, MACHINE IDENTITY AND API ACCESS GOVERNANCE Govern non-human access across DTS systems and platforms. This includes: * Defining standards for service accounts, machine identities, automation users, API keys, tokens, secrets and integration credentials. * Ensuring non-human access has clear ownership, purpose, scope, rotation, expiry and auditability. * Working with Product, Engineering, Cloud Security and Infrastructure to reduce unmanaged credential risk. * Ensuring service accounts and machine identities are included in access reviews. * Supporting stronger governance of API access, token issuance, credential lifecycle and integration permissions. 6. AI AND AGENTIC ACCESS GOVERNANCE Define and oversee the governance model for AI agents and agentic workflows across DTS. This includes: * Defining how AI agents are identified, permissioned, monitored, reviewed and revoked. * Ensuring agents have clear ownership, scoped permissions and auditable actions. * Defining which agent actions require human approval or additional control. * Governing agent access to APIs, tools, datasets, workflows, client environments and production capabilities. * Ensuring agents act within delegated authority and cannot exceed the permissions of the user, system or business process they represent. * Working with Product, Architecture and Security to ensure agentic workflows are designed with clear action boundaries. * Working with the Product, Application and Offensive Security Lead to test whether agent permissions and action boundaries can be bypassed. * Working with Privacy Engineering to ensure AI access models support permitted use, minimisation and data protection requirements. 7. DATA ACCESS GOVERNANCE Govern access to sensitive, client, partner and WPP-owned data across DTS. This includes: * Defining standards for dataset access approval, review, revocation and evidence. * Supporting data classification from an access-control and security-governance perspective. * Ensuring access to sensitive data is role-based, purpose-based, least-privileged and auditable. * Supporting controls for cross-client, cross-market, cross-agency and partner data access. * Ensuring data access governance supports InfoSum, Open Intelligence, Resolve, WPP Open and other DTS data collaboration use cases. * Working with Privacy Engineering on data minimisation, permitted use, retention and privacy-by-design requirements. * Ensuring data access risks are surfaced through the DTS risk process. 8. GOVERNANCE OF ACCESS TO TOOLS, WORKFLOWS AND ACTIONS Ensure access governance extends beyond systems and datasets into tools, workflows and actions. This includes: * Defining governance for access to operational tools, workflow automation, orchestration systems, AI tools and administrative actions. * Ensuring high-risk actions are subject to appropriate approval, logging and monitoring. * Supporting segregation of duties across sensitive workflows. * Ensuring automated workflows and agents have clearly scoped authority. * Working with Security Operations to ensure high-risk access and actions are visible in monitoring and detection processes. 9. AUDITABILITY, EVIDENCE AND REPORTING Maintain clear evidence of access governance and support audit and assurance requirements. This includes: * Producing access governance evidence for SOC 2, ISO 27001, client assurance, internal audit and risk reviews. * Working with the ISMS and Risk Officer to ensure access controls, reviews, exceptions and remediation actions are documented. * Reporting on access review completion, high-risk access, overdue actions and access control gaps. * Supporting client and audit questions related to identity, access, privileged roles, service accounts, AI agents and data access. * Ensuring access governance is repeatable, measurable and auditable. Who you'll be working with: The Identity, AI and Data Access Governance Lead will be accountable for: * DTS identity and access governance standards. * Regular access reviews and recertification. * Privileged access governance. * External user, client, partner and vendor access governance. * Service account, machine identity, API key and token governance. * AI agent identity, permission and action governance. * Dataset and sensitive data access governance. * Governance of access to tools, workflows and high-risk actions. * Access governance evidence for audit, compliance and client assurance. * Escalation of material access risks into the DTS risk process. What you'll need: The successful candidate will have: * Experience in identity governance, access management, IAM, security governance, GRC, data access control or platform security. * Strong understanding of least privilege, role-based access control, attribute-based access control, access reviews, privileged access and segregation of duties. * Experience governing access across SaaS platforms, cloud environments, APIs, data platforms or enterprise technology estates. * Knowledge of identity platforms such as Okta, Auth0, Keycloak, Azure AD / Entra ID or similar. * Understanding of service accounts, machine identities, API keys, tokens, secrets and non-human access governance. * Understanding of AI agents, agentic workflows, delegated authority and tool-access governance would be highly valuable. * Understanding of data classification, dataset access governance, privacy-by-design and audit requirements. * Ability to work across security, architecture, product, engineering, infrastructure, legal, privacy and compliance teams. * Strong organisational skills and ability to coordinate reviews, evidence, remediation and reporting. * Ability to translate complex access issues into clear risks, controls and practical actions. LEADERSHIP EXPECTATIONS The Identity, AI and Data Access Governance Lead is expected to: * Be structured, disciplined and pragmatic. * Bring clarity to complex access and permission models. * Challenge excessive, unclear or poorly governed access. * Work constructively with product and engineering teams to design workable controls. * Avoid creating unnecessary bureaucracy while ensuring access is properly governed. * Treat human, machine and agent access as part of the same control landscape. * Escalate material access risks clearly and early. * Support DTS in building a secure, auditable and scalable access governance model. SUCCESS MEASURES Success in the role will be measured by: * DTS having clear identity, access and data access governance standards. * Regular access reviews completed on schedule with evidence. * Reduction in stale, excessive, orphaned or poorly owned access. * Stronger governance of privileged access and production access. * Clear ownership and review of service accounts, machine identities, API keys and tokens. * Defined governance for AI agent identities, permissions and actions. * Improved auditability of access to data, APIs, tools, workflows and production systems. * Better alignment between identity, security, privacy, architecture, product and engineering teams. * Material access risks being visible through the DTS risk register and Risk Review Board. * Increased confidence that DTS can answer: who or what has access to what, why, and when was it last reviewed? Who you are: You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
Sonata One is a rapidly scaling, regulated fund services and technology (fintech) business. We're The Private Funds Clearinghouse, connecting more than 53,000 investors with 6,500 funds and 180 fund managers around the globe. Our vision is to change the paradigm of private markets investing through harmonising the end-to-end investment process within one platform. Investors benefit from a seamless, one & done experience across the fund lifecycle (from fund selection and subscription through to settlement and reporting) underpinned by a globally compliant KYC passport and 24/5 support. Fund managers can raise capital faster at a lower cost from a wider pool of pre-approved investors. Founded in 2015, Sonata One has a presence in eight locations worldwide including the US, UK and Luxembourg, Guernsey, South Africa and Mauritius. Role Overview: Sonata One is seeking an experienced Cloud & Microsoft 365 Engineer to own the design, implementation, and ongoing operation of our Microsoft cloud estate. You will act as a senior technical owner across identity, endpoint management, collaboration, data governance, security operations, and automation—ensuring our M365 environment is secure, compliant, scalable, and aligned with business outcomes. This is a hands-on engineering role with significant architectural influence: you will translate security and governance requirements (including SOC 2, ISO 27001, and NIST-aligned controls) into practical configurations, automation, and operational processes. You will partner with business stakeholders, IT operations, and external vendors to deliver reliable services, lead complex initiatives, and drive continuous improvement across the Microsoft stack. Key Responsibilities: IT service Management, project delivery & end user support * Operate within ITIL-aligned practices: incidents, changes, problems, and service requests with clear SLAs and communication. * Plan and lead M365 projects using structured project management (scope, timeline, risk, stakeholder management). * Coordinate cross-functional delivery (security, infrastructure, applications, vendors) to meet business deadlines and quality standards. * Act is primary escalation contact for 2nd & 3rd level end user support issues. Microsoft Intune & mobile device management (MDM/MAM) * Lead the design, implementation, and lifecycle management of Microsoft Intune for enterprise mobile device and application management. * Configure and manage mobile application deployment, updates, and retirement within Microsoft 365. * Implement Conditional Access, security baselines, compliance policies, and data protection controls for mobile devices and managed applications. * Oversee MDM and MAM across supported mobile platforms (e.g. iOS, Android, Windows). * Automate enrolment, compliance remediation, and operational workflows; drive measurable efficiency and reliability improvements. * Ensure all devices accessing Sonata One resources meet defined security and governance standards. Microsoft Entra ID (Azure AD) & identity platform * Architect and implement identity and access management (IAM) solutions using Microsoft Entra ID. * Design and deploy secure authentication including MFA, SSO, and modern auth patterns for cloud and integrated applications. * Integrate third-party SaaS and line-of-business applications while maintaining least-privilege and strong security posture. * Provide expert guidance on identity governance, privileged access, and Entra best practices. * Automate identity-related operations (group management, licensing workflows, lifecycle tasks) where appropriate. * Support SOC 2 control activities through documented processes and regular user access reviews. Identity lifecycle management (ILM) * Own the identity lifecycle: joiner/mover/leaver, role-based access control (RBAC), and federation where applicable. * Design, configure, and automate identity governance workflows to meet internal policy and regulatory expectations. * Implement self-service identity and password management capabilities aligned with security policy. * Drive adoption and maturation of the Microsoft Identity Governance capabilities (e.g. access reviews, entitlement management, lifecycle workflows). * Conduct periodic access certifications with business owners in line with SOC 2 and Sonata One access control policies. Microsoft Purview & data lifecycle management * Lead administration and support of Microsoft Purview for classification, labeling, data governance, and compliance reporting. * Implement and automate retention, deletion, and archival policies across M365 workloads. * Design data protection strategies aligned with GDPR, POPIA, and organisational data handling requirements. * Ensure effective protection through retention labels, DLP, encryption, and integration with backup/archival strategy where required. * Partner with legal, risk, and business teams on data handling, eDiscovery, and audit readiness. Microsoft Sentinel (SIEM) * Implement and operate Microsoft Sentinel for centralised logging, detection, and security analytics. * Configure analytics rules, workbooks, automation rules/playbooks, and integrations for threat detection and incident response. * Tune detections to reduce false positives; improve mean time to detect/respond through automation and operational discipline. * Support security operations with reporting, KPIs, and continuous optimisation of use cases. Microsoft Defender suite (Endpoint, Office 365, Identity & vulnerability management) * Lead configuration and operation of Defender for Endpoint, Defender for Office 365, and Defender for Identity (and related XDR capabilities as adopted). * Architect vulnerability and exposure management: baselines, patching posture, configuration hardening, and endpoint protection standards. * Integrate Defender signals with Sentinel and broader security tooling for cohesive detection and response. * Proactively manage security incidents and alerts; drive improvements to reduce risk and operational friction. * Monitor endpoint and workload health to maintain current patch/vulnerability posture across the estate. SharePoint administration, design & Power Platform * Design, implement, and administer SharePoint Online (sites, hubs, permissions, information architecture) for performance, security, and usability. * Lead development of Power Apps and Power Automate solutions that automate business processes and integrate with M365 and line-of-business systems. * Establish and enforce SharePoint and Power Platform governance (DLP, environment strategy, solution lifecycle, ALM where applicable). * Support document management, collaboration patterns, and migration/onboarding activities as required. Power BI * Architect and deliver Power BI solutions (datasets, reports, dashboards) that support data-driven decision-making. * Integrate data from multiple sources; implement refresh, gateway, and workspace patterns that scale securely. * Enforce Power BI governance: workspace access, sensitivity labels, row-level security, and compliance with data policies. Microsoft Teams * Design and manage Teams environments, policies, and templates for effective collaboration. * Optimise Teams integration with SharePoint, OneDrive, Planner, and Power Platform. * Implement Teams governance and compliance (meeting policies, guest access, retention, eDiscovery alignment). Cybersecurity frameworks & compliance * Apply knowledge of SOC 2, ISO 27001, and NIST (and related control frameworks) to M365 design and operations. * Implement and evidence security controls, risk treatments, and audit-ready documentation. * Ensure incident management, data protection, and access management requirements are met across M365 services. * Facilitate regular access reviews with business partners per Sonata One Access Control and Data Management policies. Automation, scripting & infrastructure as code * Develop automation using PowerShell, Microsoft Graph, Bicep/ARM, and other IaC or API-driven tooling as appropriate. * Build repeatable deployment pipelines and configuration patterns to reduce manual effort and configuration drift. * Deliver low-code/no-code automation on Power Platform where it improves time-to-value for the business. Qualifications & Experience: Required: * 5+ years in IT with 3+ years focused on Microsoft 365 / Azure identity and security (mid-level); 7+ years with substantial ownership of M365 architecture and operations (senior level). * Demonstrable hands-on experience with Entra ID, Intune, Defender, Purview, SharePoint Online, Teams, and Power Platform (Power Apps / Power Automate). * Practical experience implementing Conditional Access, MFA/SSO, compliance policies, and MDM/MAM. * Experience with SIEM/SOC workflows; Microsoft Sentinel strongly preferred. * Strong PowerShell skills and familiarity with Graph API, automation, and IaC concepts (Bicep/Terraform a plus). * Understanding of SOC 2, ISO 27001, or NIST control implementation in cloud/SaaS environments. * Experience supporting access reviews, audit evidence, and identity governance processes. * Relevant Microsoft certifications (e.g. SC-200, SC-300, MS-102, AZ-104, MS-700) or equivalent demonstrated expertise. * Matric plus tertiary qualification in IT, computer science, or related field (or equivalent experience). * Eligibility to work in South Africa; valid driver’s licence if on-site travel is required. Preferred: * Experience with Microsoft Identity Governance (Entitlement Management, Access Reviews, Lifecycle Workflows). * Power BI development and enterprise governance (Premium/Fabric awareness). * POPIA and GDPR data protection programme delivery in Microsoft 365. * ITIL Foundation or practical ITSM tool experience (ServiceNow, Halo, etc.). * Project management certification (PMI, PRINCE2) or proven delivery of multi-workstream programmes. * Experience in professional services, financial services, or regulated industries. Certifications: * Microsoft Certified: Azure Solutions Architect Expert. * Microsoft Certified: Security, Compliance, and Identity Fundamentals. * Microsoft Certified: Microsoft 365 Certified: Enterprise Administrator Expert (or equivalent). * ITIL Certification (latest version). * Certified Information Systems Security Professional (CISSP) or equivalent is a plus.
fairlife, LLC is a Chicago-based nutrition company that creates great-tasting, nutrition-rich and dairy products to nourish consumers. With over $3B in annual retail sales, fairlife’s portfolio of delicious, lactose-free, real dairy products includes: fairlife® ultra-filtered milk; Core Power® High Protein Shakes, a sports nutrition drink to support post-workout recovery; fairlife® nutrition plan™, a nutrition shake to support the journey to better health. A wholly owned subsidiary of The Coca-Cola company, fairlife, LLC has been recognized by both Fast Company and Nielsen for its industry leading innovation. To learn more about fairlife and its complete line of products, please visit fairlife.com [http://www.fairlife.com]. job purpose: The Sr. Infrastructure Engineer will focus on Microsoft & Endpoint and will own the development, governance, standardization, and administration of fairlife's endpoint devices, Microsoft’s endpoint focused solutions, and all software/services focused on endpoint administration. Reporting directly to the Director of IT, this role centralizes foundational Microsoft technologies (Intune, Active Directory/Entra ID, Teams, Exchange Online, etc.) to ensure consistent, secure, and efficient device management and user productivity across all sites. This position supports fairlife's growth by enabling rapid onboarding, focused support/admin roles and reducing risks. This is a high-impact role in a dynamic environment—perfect for someone passionate about Microsoft and their cloud technologies, automation, and building reliable systems in a fast-paced environment. responsibilities: · Design, maintain, and automate workstation/laptop builds and imaging using modern tools (Microsoft Intune, Windows Autopilot, MDT, SCCM). · Manage device enrollment, configuration profiles, compliance policies, app deployment/protection, and patching across Windows, iOS, Android, and Mac devices. · Oversee endpoint security baselines, conditional access, and integration with Microsoft Defender for Endpoint. Design and oversee core M365 tenant configurations: licensing, security/compliance policies, and identity management (Entra ID/Azure AD integration). · Design and oversee Microsoft Teams: policies, channels, guest access, meetings/calling, and app integrations. · Design and oversee Exchange Online: mailbox management, distribution groups, email flow rules, anti-spam/quarantine, and transport rules. · Own core AD/Entra ID governance: user provisioning/deprovisioning automation, group policies, delegated rights models, and synchronization. · Implement and maintain least-privilege access (RBAC) for support teams and end-users. · Develop and maintain PowerShell scripts, Microsoft Graph API workflows, and automation for provisioning, reporting, and remediation for endpoints. · Monitor endpoint health, performance, and compliance; troubleshoot issues and drive proactive improvements. · Partner with the larger Infrastructure Team to provide escalation support, delegated access (e.g., Intune Help Desk roles), and self-service tools. · Partner with Network team on endpoint-network integration (e.g., Wi-Fi profiles, VPN configs). · Document processes, create runbooks, and train teams on new standards. · Ensure endpoint and collaboration configs meet security best practices and regulatory needs (e.g., food safety compliance, data protection). · Participate in audits, vulnerability remediation, and incident response for managed devices/tenants. skills/qualifications required: · Bachelor's degree in Computer Science, Information Technology or related field, or equivalent experience. · 4+ years of hands-on experience administering Microsoft 365, Intune, Entra ID/Azure AD, Teams, SCCM, and Exchange Online in an enterprise environment. · Experience with endpoint management in multi-site or manufacturing settings preferred. · Deep expertise in Microsoft Intune and SCCM (device management, compliance, Autopilot). · Strong knowledge of M365 admin center, PowerShell, Microsoft Graph API, and RBAC/conditional access. · Proficiency in Active Directory/Entra ID, Exchange Online, Teams administration. · Familiarity with endpoint security tools (Defender, BitLocker, etc.). · Experience with automation/scripting and modern deployment strategies. how fairlife nourishes you: At fairlife, we believe in better — and that includes how we support our people. We offer a comprehensive suite of benefits and wellbeing resources designed to support you physically, emotionally, socially, and financially, both in and out of work. · Comprehensive medical, dental, and vision coverage, effective day one! · Supplemental health plans (hospital indemnity, accident, and critical illness insurance) · Paid Time Off to recharge and support work-life balance · Paid parental leave & adoption assistance (up to $10,000) · Parental support & family care benefits, including childcare resources and lactation support · 401(k) to support retirement planning with up to 9% in employer match · Wellness reimbursement (up to $500 for qualified wellbeing expenses) · Employee Assistance Program (EAP) for emotional wellbeing and work-life support · Company-paid life insurance and short-term disability · Employer HSA funding (for HDHP participants) · Tuition reimbursement (up to $10,000) and student loan repayment ($200/month) · Learning & development programs to unlock your full potential · Rewards & recognition, matching gifts, free product, and Business Resource Groups fairlife’s nour!sh program is designed to meet you where you are — supporting your individual wellbeing journey while enabling you to do your best work every day. position location: Chicago, IL reports to: Director, Infrastructure & Services travel requirements: 25% salary range: $115,000 - $135,000 exempt/nonexempt: Exempt #LI-BB1 *Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered. Base pay range: $115,000—$135,000 USD fairlife, LLC is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. All qualified applicants and employees will be given equal opportunity. Selection decisions are based on job-related factors. In addition to its nondiscrimination commitment, the Company will also provide reasonable accommodation of qualified individuals with known disabilities unless doing so would impose an undue hardship on the Company. If you have a disability and would like to request accommodation in order to apply for a position with us, please email careers@fairlife.com [careers@fairlife.com]. For Recruitment Agencies At fairlife, we manage the majority of our hiring internally through our dedicated Talent Acquisition team, which is actively engaged in direct candidate sourcing. Most of our roles are filled through applications submitted via our careers site or through direct outreach by our team. As our recruitment is primarily handled in-house, we work only occasionally with external agencies, and only those on our existing, pre-approved vendor list. At this time, we are not reviewing or expanding that list. Unsolicited resumes or submissions from external agencies not authorized by our Talent Acquisition team will be considered direct candidate applications. As such, fairlife will not assume responsibility for any placement fees associated with these submissions.