Skip to content

Strategy

Read your own job posting: it is an inventory, not a role

Helpdesk, network, security and the ERP, in one listing, at one salary. That is not a job description. It is a record of what one person quietly accumulated, written down for the first time on the day they left.

8 min readComputing America

In short

  • A single posting listing helpdesk, network, security and a line-of-business system is not one role. It is an inventory of what one person had accumulated over years, written down for the first time because they resigned.
  • Sort the duty list by what each item actually demands (presence on site, availability outside business hours, specialist depth used a few times a year, continuity of knowledge) and it stops being one job in every column but the first.
  • The out-of-hours column is the one no single hire can cover, and the reason is structural rather than a question of effort: an availability commitment needs more than one person to be an availability commitment at all.
  • Co-managed is the arrangement where your hire owns presence and relationships and an outside team owns depth, out-of-hours and continuity. The test of whether an offer is co-managed is whether it survives the hire, if it only makes sense while the seat is empty, it is staffing with a different invoice.
  • Write the inventory down before the knowledge leaves rather than after. It is the same document a replacement provider will build in its first two weeks, and it is worth more to you the earlier it exists.

Somewhere in the last month a company of about eighty people posted a job. It asks for someone to run the service desk, administer Microsoft 365 and Entra ID, own the firewall and the site-to-site VPN, manage endpoint protection and patching, hold the backups, act as the security contact for the customer questionnaires that keep arriving, and be the internal expert on the ERP. Five to seven years of experience. One salary, and it is a regional one.

It will not fill. It will sit for ninety days, get re-posted with the word senior added and the salary unchanged, and eventually be filled by somebody who can do about half of it well. That is not a hiring failure and the salary is not the problem either. The problem is upstream: what was posted is not a job.

How the list got that long

Nobody sat down and decided one person should own all of that. Each line arrived on its own, in the week it broke. The Wi-Fi went down at the second site and they fixed it, so the network became theirs. The auditor asked who owned patching and they were the only person in the room who knew, so patching became theirs. A customer sent a security questionnaire and somebody had to answer it. Every one of those decisions was locally correct and cost nothing at the time, because the person absorbing them was competent and did not complain.

What accumulates that way is invisible until it leaves. The organization has no document describing it, because the document was a person. The job posting is the first time in years that anyone has written the estate down, and it was written under time pressure by a manager reconstructing it from memory and from a calendar. That is why the list reads oddly to anyone in the field: it is not a role, it is an inventory, and it is an incomplete one.

Sort it by what each line demands

The list looks like one job because every item is IT. Sort it instead by what each item requires from whoever holds it, and the shape changes immediately. Four columns are enough.

What it demandsExamples from the postingWhat one hire does to it
Presence, being in the building, known by nameThe service desk, new starters, the meeting-room screen, the machine on the shop floor with the serial adapterFits. This is the part a hire is genuinely better at than any outside firm, and it is the part outsourcing does worst.
Availability, answering when the business is not openThe firewall, the VPN, the line-of-business system, anything a restore depends onBreaks. One person is not an availability commitment; they are a person who sleeps, takes leave and eventually resigns.
Depth, specialist judgment used a handful of times a yearIdentity design, network segmentation, backup architecture, answering the security questionnaire truthfullyBreaks, in the expensive direction. A generalist guesses, and the guess is invisible until an auditor or an attacker tests it.
Continuity, knowing why the estate is the way it isWhy that VLAN exists, which vendor holds the circuit, what the last provider changed and did not documentBreaks by construction. It lived in the person who left, and a new hire starts at zero on their first day.
The same duty list, sorted by what it actually asks of a person

Only the first row survives contact with a single hire. That is the whole finding, and it is worth stating plainly because the usual conclusion drawn from a stalled search is that the market is tight or the salary is low. Both may be true. Neither is why three of those four columns are unfillable by one person at any salary.

Why availability is structural and not a matter of effort

The availability row is the one people argue about, usually by pointing at the person who just left and observing that they did answer at eleven at night. They did. That is not the same as the business having an availability commitment, and the difference shows up on exactly the day it matters.

The clearest statement of this is in the incident-response literature rather than the service-desk one. NIST SP 800-61r3 (opens in a new tab) treats response as a set of defined roles with stated responsibilities and stated availability, coordinated against a plan that exists before the incident does. Every version of that guidance assumes the answer to “who is reachable, and by when” is a property of the organization. A single administrator can be heroic; they cannot be a property of the organization. The moment they are on a plane, in a hospital, or three weeks into a new job somewhere else, the commitment was never there; it was a habit, and habits do not survive the event they were being relied on for.

This is also the row that is quietly the most expensive to get wrong, because it only ever fails at the worst moment. Nothing goes wrong at four on a Tuesday afternoon that a competent person cannot handle by Wednesday. The failures that cost real money are the ones discovered at five on a Friday, on a long weekend, or at the exact hour the person holding everything is unreachable and the backup nobody had tested turns out to have been failing silently since March.

What co-managed actually means

The arrangement that fits the four columns is not “hire nobody and outsource it all”, and it is not the hire on their own. It is both, with the split written down: your person owns presence and relationships, an outside team owns availability, depth and continuity. The industry calls this co-managed IT, which is a bland name for the only division of labor the sorted list actually supports.

In practice that means your hire keeps the service desk, the floor, the joiners and leavers, and the standing in the building that lets them tell you what is really going on. They stop being the only person who can restore a server at two in the morning, the only person who has ever configured the firewall, and the only person who knows why the VLAN exists; because those three things are documented, monitored and covered by a team with a rota. They also stop being the person who has to say yes when a customer questionnaire asks whether the environment is monitored.

The version of this that goes wrong is the one where the split is never written down. Two parties both loosely responsible for patching is worse than one party clearly responsible for it, and the failure is silent: everything looks covered until the month it was not. If you take one operational thing from this piece, take that the split has to be a document, per system, with a name against each line.

The test that separates it from staffing

Plenty of firms will offer you something called co-managed while the seat is empty. The question worth asking on the first call is what happens to the arrangement on the day you make the hire. If the answer is that it winds down, you were not being offered co-managed IT. You were being offered a contractor to keep the lights on until you replace them, which is a legitimate product and a different one, and it should be priced and scoped as what it is.

A real co-managed arrangement is more valuable after the hire than before it, because the hire is who it is for. The out-of-hours cover, the specialist depth and the documentation are what make the role fillable at the salary you can actually pay: you are no longer recruiting a mythical person who is simultaneously a network engineer, a security specialist and someone happy to reset passwords. You are recruiting a good generalist with a team behind them, which is a job that exists.

Ask the second question too. When we leave, what do we hold? A firm that cannot answer that in one sentence on the first call has not thought about it, and the cost of leaving a managed arrangement is set on the day you sign it rather than the day you give notice.

What to do this week, even if you hire

The single highest-value action available to you right now has nothing to do with choosing a provider, and it expires. Every week between the resignation and the last day is a week in which the inventory can still be written down by the person who knows it.

  1. 1.Take the posting and mark each line with which of the four columns it belongs to. Half an hour, and it changes what you are recruiting for.
  2. 2.Sit with the person who is leaving and write down what is not on the list: which vendor holds which circuit, what the account with the shared password is for, what breaks every quarter, what they were about to do next and why.
  3. 3.Establish who holds the keys, in whose name. Tenants, domains, licenses and circuits registered to a departing individual or a previous provider are the most common form of lock-in, and it is not a clause; it is an ownership record nobody checked.
  4. 4.Test one restore. Not review the backup dashboard; restore something and open it. This is the single check most likely to return an unwelcome answer, which is why it is worth doing while somebody who knows the system is still employed.
  5. 5.Only then decide the shape: hire, co-manage, or both. The decision is easy once the inventory exists, and impossible to make honestly before.

That list is, deliberately, most of what an incoming provider does in its first two weeks; the estate review, before anything is agreed. If you would rather run it yourself, run it yourself; it is worth more to you than to us and it is worth most while the outgoing person is still there to answer a question.

Where this argument stops

Co-managed is not the right answer everywhere, and the two cases where it is wrong are easy to name. If the honest total across all four columns really is one full-time job (a single site, sixty people, no line-of-business system anyone would call complex) then hire the person and buy nothing else; an outside team layered on top of that is overhead wearing the language of resilience. And if what the estate needs is somebody physically present most days, a remote arrangement will underserve you no matter how good the rota is, and any firm that tells you otherwise on a first call is selling rather than scoping.

Both of those are answerable in forty-five minutes, before anyone quotes anything. What is not answerable in forty-five minutes is whether one person can be four columns at once. That one has already been answered, by the posting.

Sources

  1. 1.SP 800-61r3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management (opens in a new tab), NIST

Next step

Send us the job posting.

Paste the duty list exactly as you posted it. We will sort it into the four columns this piece sets out and say which lines we would expect one hire to hold, and which ones need more than one person behind them to mean anything.

Reply
A person replies, not a sequence: within one business day, from someone who would be on the engagement.