IT, Cloud & Infrastructure

How to Get an IT Manager Job in 2026 and 2027

The short answer

To get hired as an IT manager in 2026 or 2027, stop presenting yourself as the person who fixes things and start presenting yourself as the person who owns headcount, a budget, a vendor list and a risk register. No licence or registration gates the role, so what gates it is evidence of scope: put four numbers in the top third of your resume (people managed, annual budget owned, seats or users supported, number of sites) and be ready to walk a panel through your last contract renewal, how you would take ten percent out of IT spend, and the last time you proved a restore rather than a backup success rate. Most IT managers are promoted internally, so if you are applying externally, target mid-market companies of roughly 150 to 2,000 staff, managed service providers, and single functions inside large enterprises, where the job is advertised and the panel usually includes finance. Expect three to five stages over three to six weeks, often ending in a 90-day plan presentation.

Licence requiredNone. No government licence, registration or board exam gates the IT manager title in the US, UK, Canada or Australia.
Credentials employers actually nameITIL 4 Foundation most often, then PMP or PRINCE2 for project-heavy roles, CISM or CISSP where the role owns security, plus a current Microsoft (Azure, Intune, Microsoft 365) or AWS certification to show you have not drifted away from the estate.
Time to credentialITIL 4 Foundation is a single exam, commonly sat after days to a few weeks of study. PMP requires documented project leadership experience plus 35 hours of formal education before you can sit it. CISM requires several years of verified experience including management domains, so it follows the first manager job rather than opening it. Check each body's current requirements, which change.
Experience before a first manager roleCommonly five to eight years hands-on (service desk, systems or network administration), including some period as a team lead, senior escalation point or project owner.
Most common route inInternal promotion. Externally advertised openings cluster in mid-market companies where IT manager is the top IT job, in managed service providers, and in large enterprises where the title covers one function such as End User Services Manager or Service Desk Manager.
Typical hiring processThree to five stages over three to six weeks: recruiter screen, hiring manager, stakeholder panel, often a presentation or scenario exercise, then references and a background check. Public sector, universities and healthcare run scored panels with fixed questions and take longer.
Who you report toAt mid-market companies IT frequently reports to the CFO or COO rather than a CIO. That one fact changes what the interview is about: spend and contract control under finance, uptime and operational risk under operations, architecture and roadmap under a CIO.
Where to check payUS BLS Occupational Employment and Wage Statistics, SOC code 11-3021 (Computer and Information Systems Managers), filtered to your metro area. It pools IT managers with directors and CIOs, so read it as an upper-skewed envelope, then cross-check pay-transparency postings and published public sector, school district and university salary schedules, which are literal.

How IT manager hiring actually works

Most IT managers are not hired, they are promoted. The person who ran the migration, held the on-call phone and became the one the CFO called directly gets the title when the previous manager leaves. If you are already inside a company, your campaign is twelve to eighteen months of visible ownership, not a resume rewrite. Volunteer for the renewal nobody wants, take the audit evidence pack, run the restore test, present the ticket numbers at the operations meeting. Internal promotion decisions are made on who is already behaving like the manager, and they are usually made before the role is posted.

Externally advertised IT manager roles concentrate in three places, and they are different jobs wearing the same title. In a mid-market company of roughly 150 to 2,000 employees, IT Manager is the top IT job: you own everything from the firewall to the laptop fleet to the Microsoft agreement, you typically have between two and twelve reports, and you report into finance or operations. At a managed service provider, IT Manager usually means running a pod of technicians against client service levels and a utilisation target, and the interview is about margin, escalation and client retention. In a large enterprise it means one slice: End User Services Manager, Infrastructure Manager, Service Desk Manager, Network Operations Manager. Read the posting for seat count, headcount and reporting line before you tailor anything, and if they are missing, ask in the screen.

There is a fourth shape that has become common enough to prepare for: the co-managed role, where the company has outsourced the service desk or infrastructure to a provider and the IT manager manages the contract, the escalations and one or two internal staff rather than a team. If the posting mentions a managed service provider, co-managed IT or a named outsourcer, expect the interview to be weighted towards governance: how you hold a provider to its service levels, how you run a monthly service review with evidence rather than vibes, what you do when the provider's ticket data and your users' experience disagree, and whether you have ever triggered a service credit or exited a provider. Candidates who only describe managing employees lose this version of the job to candidates who can describe managing a supplier.

The stages are predictable. A recruiter or in-house talent partner screens for twenty to thirty minutes and is checking four facts: how many people you have managed, how big a budget you have owned, how many users or seats, and your number. Give those plainly and early. Then the hiring manager, who is frequently not a technologist. Then a stakeholder panel that typically includes finance, sometimes HR, sometimes the security lead, and often a department head whose team you would be serving. At the top of the range there is a presentation or a scenario exercise, usually a 30/60/90 day plan or an assessment of a described estate. Then references and a background check. Three to six weeks is normal, and the gap between panel and offer is usually finance, not doubt about you.

Public sector, local government, school districts, universities and many hospital systems run a different process and it catches private sector candidates out. The application form is the screen, and it is read by HR against the posting rather than by anyone in IT, so address every minimum and desirable qualification explicitly, in the posting's own words, with a line of evidence each. At interview, every candidate is asked the same written questions, read aloud, often with no follow-ups, and each answer is scored against a rubric by two or three panellists. You will not be drawn out. Every answer has to be self-contained: name the situation, the action, the number and the result in about ninety seconds.

Finding these roles takes a different search than a software job. Mid-market IT manager openings are often posted only on the company's own careers page and on one local job board, so build a list of thirty to fifty employers in your commuting area by headcount band and check them directly. Local and regional recruitment agencies place a real share of these roles because mid-market companies without a talent function outsource the shortlist. Managed service providers hire continuously and are the fastest route to a first management title, at the cost of client pressure and utilisation targets. And tell the account managers you already deal with that you are looking, because vendors and resellers hear about open IT manager seats across their whole customer base before the postings go up.

One question to ask in the first conversation, every time: who does this role report to, and what is that person measured on. The answer tells you what the whole process is really about. A CFO hiring an IT manager is buying spend control and predictability. A COO is buying uptime and fewer interruptions to the operation. A CIO is buying delivery of a roadmap they already own. Three different second interviews.

What gates the job, and what does not

Nothing licences this role. There is no board, no registration, no continuing education requirement, no state exam. Anyone telling you a certificate is mandatory to manage IT is selling the certificate. What certificates do is clear a screen and supply vocabulary.

ITIL 4 Foundation is the one that appears most often in postings, and it is worth having for an unglamorous reason: it gives you the shared words for incident, problem, change, request and service level that panels use, and it signals you will not treat a change process as bureaucracy. It is a single exam. PMP or PRINCE2 matters where the role is project-weighted, and PMP in particular requires documented project leadership experience plus formal contact hours before you can sit it, so it is a medium-term plan rather than a weekend. CISM or CISSP matters when the role owns security as well as operations, which in the mid-market it almost always does in practice even when the posting does not say so. Both require verified experience, so they tend to follow the first manager job rather than unlock it.

Keep one current technical certification live even as a manager. Not because anyone needs you to configure conditional access, but because a five-year-old certification next to a resume full of management verbs reads as someone who has lost touch with the estate they are supposed to run. A current Azure, Microsoft 365, Intune or AWS associate-level credential does that job cheaply.

What actually gates the role is evidence of scope. A panel is deciding whether you have ever been accountable when something cost money or stopped working, or whether you have only ever executed. The proof is numbers attached to decisions you made: a contract you signed off, a budget you built and then hit, a person you hired and a person you managed out, a risk you accepted in writing. If you have none of that, get some before you apply. Ask your current manager for the renewal calendar. Ask to own the hardware refresh budget line. Ask to run the next access review. These are not favours; nobody wants to do them.

What belongs on an IT manager resume, and what gets ignored

The most common failure in IT manager resumes is that they read as a senior administrator resume with the word manage pasted over the verbs. The reader cannot tell what you were responsible for, only what you touched.

Lead with scope. Under your name and title, give a one-line scope statement using your real figures: team size, annual budget and whether it is operating, capital or both, user or seat count, number of sites and countries, and the core platforms. A reader is deciding in the first few seconds whether you have operated at their size. Make that decision easy and make it accurate, because every number on that line will be probed.

Then write bullets that start with the business outcome and carry a number you would defend under follow-up questions. The pattern that works: what changed, by how much, over what period, and what you did. Not the technology you used.

What gets ignored or actively counts against you: a skills matrix listing forty technologies, which reads as a doer; strings of certification acronyms after your name; words like spearheaded, synergised and passionate; duties with no scale, such as managed backups and antivirus; and a one-page resume, which at this level hides the scope that is your whole case. Two pages is right. Three is acceptable at fifteen years.

On title honesty: if you ran the team without the title, do not invent one, but do disambiguate. Systems Administrator III (acting IT manager, five reports, 2024 to 2026) is true, searchable, and answers the recruiter's question. Applicant tracking systems and recruiters both filter on title, so burying the fact that you led the team in bullet four will cost you the screen.

Vendors, spend and risk: the three subjects every panel tests

This is the part of the interview that hands-on candidates lose, and it is losable in two minutes. Panels are not testing whether you know what a firewall does. They are testing whether you can be trusted with other people's money and other people's exposure.

Vendors. Expect: walk me through your last renewal. A weak answer names a product and a percentage saved. A strong answer has structure. Here is the category, here is the seat count against true consumption, here was list price against what we paid, here is what I changed in the terms, here is who I brought in, and here is what I was willing to lose. The term changes that impress a panel are unglamorous: removing automatic renewal, co-terminating agreements so renewals land together and you negotiate once with leverage, capping the uplift at renewal, protecting against a mid-term true-up, getting data egress and exit assistance written in, and making sure service credits are not quietly the only remedy. Say plainly that credits are not compensation, they are a discount on the outage you already suffered. Know the purchasing vocabulary: enterprise agreement against cloud solution provider against direct, reseller margin, named user against concurrent, perpetual against subscription, maintenance as a percentage of licence, data processing agreement, subprocessor list. The question behind the question is always whether you will be captured by the incumbent reseller who takes you to lunch.

Be ready for the inventory question too, because nobody answers it badly and recovers. How many software products are in use in your organisation, and how do you know. The credible answer names the method: sign-in logs and enterprise applications in your identity provider, expense and card reports from finance, a discovery tool, and a renewal calendar you maintain by hand. Saying that the last time you did this you found tools nobody in IT had approved, and a product you were paying for twice through two cost centres, is a better answer than claiming a clean inventory.

Spend. You should be able to build an IT budget out loud in three minutes: contracted run rate (what renews whether or not you do anything), hardware refresh (what fraction of the fleet turns over each year and at what unit cost), projects, people including contractors and overtime, and contingency. Know your unit economics, because that is how finance thinks: cost per seat per month for the whole stack, cost per ticket, cost per site. Know why finance cares about capital against operating spend, and that moving a data centre to cloud converts a depreciating asset into a monthly operating cost, which changes how the numbers present even when the total is similar.

Then the cut question, which arrives in almost every mid-market panel: we need ten percent out of IT next year, where does it come from. Weak candidates cut training, spares and the thing they personally dislike. Strong candidates give an ordered list with the risk accepted at each step: reclaim unused licences first because it is free, consolidate overlapping tools, extend the hardware refresh cycle by a year and name the increase in failure rate and support load you are accepting, renegotiate the two largest contracts, defer a named project. Then name what you will not cut and why: backups and restore testing, multi-factor authentication, endpoint protection, and support on anything that stops revenue when it breaks. Saying no to a CFO with a reason attached is the skill being tested.

Risk. Panels want to see that risk is a register with named owners and dates in your world, not a feeling. Be able to list what you tracked and the state it was in when you left: documented recovery time and recovery point objectives per critical system, and whether the business agreed them in writing rather than you guessing; the date of your last tested restore and what failed in it; patch service levels by severity and your actual compliance against them; multi-factor coverage including service accounts and remote access; how many accounts hold the highest privilege and whether that access is standing or requested; how fast a leaver loses access and who triggers it; third-party risk on your top vendors; the insurance questionnaire you signed and whether every answer was true.

The incident scenario is standard: we have ransomware on a file server at 2am, go. They are scoring sequence and judgement, not heroics. Who you wake and in what order. When you isolate rather than power off, and why preserving volatile evidence matters. When legal, the insurer and the executive team get told. A decision log with timestamps from the first minute. Who talks to staff and who does not talk to customers. One detail that catches people out: many cyber policies condition cover on prompt notification and on using the insurer's panel incident response firm, so engaging your own responder first can create an argument about cover. Say you would check the policy's notification requirements rather than asserting a rule, because policies differ.

If you operate in the EU or UK, there are obligations covering operational resilience, incident reporting and the use of AI systems at work that may apply to your sector and your suppliers. Several of these timetables have been amended more than once. Name the obligation in an interview, not the date, and verify the current text before you assert a deadline. Being confidently wrong about a compliance date in front of a panel that includes legal is a specific and avoidable way to lose an offer.

The people part, where hands-on candidates fail

If you take one thing from this guide: when the question is about a person, keep the answer about the person. An engineer asked how they handled a struggling team member will describe the runbook they wrote to fix the underlying problem. That answer scores zero on a panel with an HR representative in the room, because it says you solved the ticket and avoided the human.

Prepare real, specific stories for the standard set. The underperformer: what you observed, what you said in the first conversation, what you documented, whether HR was involved, what the outcome was, and how long it took. The excellent engineer who is corrosive to the team: what behaviour you named, what boundary you set, and what you did when it did not change. The on-call rota: how it was structured, how you compensated it, and what you changed because someone was burning out. The promotion: who you developed and into what. The exit: someone you managed out or made redundant, and how you handled the rest of the team afterwards.

Expect the stakeholder question, because it is the daily reality of the job: a department head is unhappy, goes around you, and emails the CEO. What do you do. The answer that works is boring and adult: you go and see them, you find out what they actually needed and by when, you commit to a date or explain plainly why you cannot, and you tell your own manager before they hear it elsewhere. Panels are checking that you escalate upwards early and do not get defensive sideways.

And prepare the question that separates a lead from a manager: what did you stop doing yourself. Name the specific task you handed over knowing it would be done worse for a while, what that cost in the short term, and how the person is doing now. Candidates who cannot answer this are usually about to be hired as the most expensive senior administrator on the team, and experienced panels know it.

The presentation stage and the 90-day plan

Final stages often include a short presentation, typically thirty to forty-five minutes with questions, on one of two prompts: your first ninety days, or an assessment of an estate they describe to you in advance. It is the highest-leverage hour in the process because most candidates fill it with a technology roadmap for a company they have not seen.

Do the opposite. Make the first two weeks explicitly about looking, and list what you would ask for by name: the asset and licence inventory, the renewal calendar for the next eighteen months, the top ten ticket categories by volume, evidence of the last successful restore, the list of accounts with the highest privilege, the risk register if one exists, the current budget against actuals, and the active contracts. Say you would meet every direct report one to one in week one and at least five business stakeholders outside IT in week two, with the same three questions each time: what works, what wastes your time, and what are you afraid of.

Then commit to one visible win inside the first month, chosen to be low risk and widely felt. New-starter setup that is ready on day one. A password reset path that does not require a phone call. The meeting room that never works. Then a costed plan for days sixty to ninety with three things you would fix, one thing you would stop doing entirely, and an honest statement of what you would need: money, a hire, or a decision from them.

Two things not to do. Do not propose a platform migration or a reorganisation you cannot possibly have justified yet. And do not present a slide of generic best practice; present the questions you would ask about their specific estate and the decisions those answers would drive. Panels remember the candidate who told them something uncomfortable and true about their own environment.

Pay, title inflation and reading the real scope

IT Manager is one of the most elastic titles in the market. The same words cover a two-person team at a 90-person charity and a thirty-person function inside a bank, and the pay gap between them is large. Before you talk about money, work out which job it is.

For a defensible reference point, use the US Bureau of Labor Statistics Occupational Employment and Wage Statistics for SOC code 11-3021, Computer and Information Systems Managers, filtered to your metropolitan area. Read it as an envelope rather than a target, because that code pools working IT managers with IT directors and CIOs and therefore skews above where a first-time manager role sits. Cross-check against live postings in jurisdictions that require a published range, including Colorado, California, New York, Washington and Illinois, and note that the set of states and cities with pay-transparency rules keeps changing, so check what currently applies where you are looking. Published salary schedules for public sector, school district and university roles are literal and often downloadable. In the UK, local government and NHS roles map to published bands. The annual salary guides from large recruitment firms are directional and worth reading for the shape of the market, not as a quotable figure.

What moves the number, in rough order: seat count and headcount, reporting line (a role reporting to the CEO or CFO pays above one reporting to an IT director), industry (financial services, pharmaceutical and energy above average; education, local government and non-profit below), whether you own security and compliance as well as operations, whether you carry a formal on-call obligation, and whether the company has a second site or a second country, which multiplies travel and coordination.

Diagnostic questions that reveal the real job before you negotiate: how many people report to this role and how many are contractors; what is the annual IT spend and who signs off what above which threshold; who approves a hire; how many tickets a month and who is on call; when is the next large renewal; has the estate ever been audited. A role that cannot tell you its own IT spend or who signs off a purchase is not really a manager role yet, whatever the title says. That is worth knowing before you accept, not after.

Making the jump from hands-on to managing

If you are a senior administrator or a team lead and the title has not come, the gap is almost never technical. It is that nobody has yet seen you own an outcome where money or exposure was on the line. There are four things you can start this quarter without anyone's permission.

Build the inventory nobody has. A single spreadsheet of every contract, its renewal date, its cost, its owner and its notice period is usually the most valuable document in a mid-market IT department, and it does not exist. Maintaining it makes you the person consulted on spend, which is the whole job in miniature.

Test a restore and write up the result honestly, including what failed. Then get the business to state what downtime and data loss it can actually tolerate for its three most important systems, in writing. That conversation is the one that turns an administrator into a manager, because it forces you to translate technology into business consequence in front of people who do not care about either until you make them.

Volunteer for the renewal and the access review. Both are tedious, both are avoided, and both produce exactly the evidence an interview panel asks for. Then take the ticket data and present it monthly to someone outside IT, in their language: how long a new starter waits to be productive, which recurring fault costs the sales team the most hours, what it costs per person per month to run their software.

Finally, interview before you are ready. The IT manager interview is a skill with its own vocabulary, and you will be bad at the vendor and budget questions the first two times. Find out which answers fall apart under follow-up while the stakes belong to a role you were not sure about anyway.

Working with AI in this role

What an IT manager has to know about AI in 2026 and 2027

Start with the honest part, because panels can smell the alternative. At the core of this job, AI has changed very little. You still negotiate renewals with a human account manager who has a quota. You still sit on a 3am bridge call. You still have the difficult conversation with the engineer who is not performing. You still argue with finance about the refresh cycle. Anyone telling you that AI has transformed IT management is selling something. What has genuinely changed is the set of problems that now land on the IT manager's desk because of AI, and that set is large, specific, and asked about in interviews.

The first and biggest change: an AI assistant rollout is an IT manager problem, not an innovation project. When a company buys Microsoft 365 Copilot or a comparable assistant, three jobs appear immediately and all three are yours. Licensing: it is a per-user add-on, the cost compounds, and the leading cause of waste is assigning seats broadly and never reclaiming the ones nobody opens, so you need an assignment policy, usage reporting and a reclaim process from day one. Data governance: an assistant that can search everything a user can access will surface every oversharing problem your file estate has accumulated, and it will surface it to the person least equipped to handle it. The salary spreadsheet in a site shared with everyone was always wrong; the assistant is what makes it visible. The remediation is sensitivity labels, site permission cleanup, removing broad sharing links, and restricting what is in search scope before you turn anything on. Adoption measurement: not because adoption is a virtue, but because an unmeasured rollout dies at the next budget review and takes your credibility with it.

The second change is in how AI is priced, and it is the one that most directly affects the vendor conversation you will be tested on. Alongside per-seat add-ons, software vendors increasingly meter AI features by consumption: credits, messages, actions or tokens, bought in packs and topped up. That converts a predictable line item into a variable one, which is exactly what a CFO hates and exactly what you will be asked about. The answer that lands names the controls: a pilot with a measured consumption rate per user before you commit, a contractual cap or an agreed stop on overage rather than silent top-ups, visibility of consumption by team so you can attribute it, and a named business owner who signs for their own usage. Say plainly that you treat a consumption-priced AI feature like cloud spend, not like a licence, because the failure mode is the same.

The third change: shadow AI. Staff paste customer data, contracts and source code into consumer chatbots on personal accounts, and mid-market IT manager interviews now commonly include some version of the question how would you let the sales team use AI without losing control of our customer data. The answer is not a ban, because bans fail and you will be asked why your network and browser telemetry show the traffic anyway. The answer has four parts: a named list of approved tools on enterprise terms with single sign-on and no training on your data; an acceptable use policy that says what classes of information may not go into any tool; technical controls on the rest (conditional access, browser extension governance, data loss prevention rules on the obvious exfiltration paths, blocking consumer tiers while permitting the enterprise tenant); and a request route for a new tool that takes days rather than months. Always include the request route, because that is what stops people going around you.

The fourth change: identity, and specifically machine identity. Automation and agentic tooling run as service principals, API keys and tokens, and these have multiplied faster than anyone's access review process. The IT managers who sound current in 2026 treat non-human identities as a first-class part of access control: an inventory of them, a named human owner for each, scoped permissions rather than broad administrative rights, credential rotation, and inclusion in the quarterly access review. If an agent can create tickets, move files or change records, it is an account with privileges and no manager, and that is the gap auditors have started probing.

The fifth change is in the service desk, and it is real but smaller than the vendor decks claim. AI triage, ticket summarisation and knowledge article suggestion in platforms such as ServiceNow, Jira Service Management, Freshservice and Zendesk do deflect a genuine slice of tier zero work: password and access questions, how-to requests, status questions. What that has done to hiring, judging by what mid-market postings now ask for, is shift tier one roles towards the harder half of the queue rather than eliminate the layer. The operational consequence most managers miss is that deflection quality is a direct function of knowledge base quality, so documentation hygiene has stopped being a nice-to-have and become a measurable dependency with an owner, a review cycle and a staleness report. If you have run this, bring the deflection or self-service resolution rate alongside what happened to satisfaction, because deflection that annoys everyone is not a win.

The sixth change is in the threat model, and it is the one to raise unprompted in a security question. Pretexting has got better and cheaper. Phishing that reads as native English with correct internal detail is now the baseline, and voice cloning has made the helpdesk phone call a real attack path. The controls are procedural rather than technical, and they are what a panel wants to hear: identity proofing before any multi-factor reset or account recovery, with no exception for executives; callback on a separately verified number for any change to payment or bank details, with an emailed request treated as untrusted by default; a secondary verification channel for unusual requests from senior staff. Running a phishing simulation and reporting the click rate is table stakes. Having rewritten the helpdesk reset procedure because a familiar voice is no longer proof of identity is the answer that lands.

One last practical item: cyber insurance renewals and enterprise customer security questionnaires have started asking for an inventory of AI tools in use, what data they touch, and whether contracts prohibit training on your data. Keeping an AI tool register (tool, business owner, data classification, contract and data processing status, approved or not) is a small artefact that answers an interview question, a renewal question and an audit question at once. If you have built one, say so, and say how many tools were on it that nobody in IT had approved.

Governing an AI assistant rollout end to end

Copilot-class deployments fail on permissions and unused licences, not on the technology, and both failures belong to the IT manager. The spend is per user and visible to finance.

Show it: Describe one rollout: how you remediated oversharing and search scope before enabling it, your seat assignment and reclaim policy, and the adoption figure you reported at renewal. Name what the permissions cleanup turned up.

Controlling consumption-priced AI in contracts

AI features metered by credits, messages or tokens turn a fixed licence line into variable spend, and the IT manager is the person finance holds responsible for the variance.

Show it: Explain how you measured consumption per user in a pilot before committing, the cap or overage stop you negotiated, how you attributed usage to teams, and the business owner who signed for it.

Shadow AI control that people actually accept

Panels ask directly how staff can use AI without leaking customer or contract data. A pure ban answer marks you as someone whose policy will be ignored.

Show it: Present four parts together: approved tools on enterprise terms with single sign-on, an acceptable use policy naming prohibited data classes, the technical control you used to block consumer tiers, and a request route with a stated turnaround.

Managing non-human identities

Automation and agents run on service principals and API keys that multiplied faster than access reviews, and this is now a gap auditors and insurers probe.

Show it: Say that your access review covers machine identities, that each has a named human owner and scoped permissions, and give the figure you reduced standing privileged access to.

Reading AI service desk numbers honestly

Deflection is the headline vendors sell, but it only holds if the knowledge base is current, and a deflection gain alongside falling satisfaction is a loss.

Show it: Pair the deflection or self-service rate with satisfaction and reopen rate over the same window, and name the documentation review cycle you put in place to sustain it.

Procedural defences against AI-assisted social engineering

Voice cloning and fluent, well-researched phishing have made helpdesk identity proofing and callback verification on payment changes operational requirements rather than best practice.

Show it: Describe the procedure you rewrote, the exception you refused to grant including for an executive, and your phishing simulation click rate before and after.

Keeping an AI tool register

Cyber insurance renewals and enterprise customer security questionnaires have begun asking what AI tools touch your data and on what contract terms.

Show it: Bring the structure (tool, business owner, data classification, contract and data processing status, approval decision) and the count of unapproved tools you found when you first compiled it.

Judging AI claims in a vendor pitch

Software renewals now arrive with an AI module and a price increase attached, and the IT manager is the only person in the room positioned to ask whether it does anything.

Show it: Describe an AI feature you declined, what evidence you asked for, and what you would have needed to see to say yes. A documented no is stronger evidence of judgement than a list of pilots.

What a screen is looking for

These are the terms that a resume screen, human or automated, is matching against for this role. Use the ones that are true of you, in the words the posting uses.

Mistakes that cost people this job

Answering management questions with technical answers. Asked how you handled a struggling team member, you describe the automation you wrote so the problem could not recur.

When the question is about a person, keep the answer about the person: what you observed, what you said, what you documented, who else was involved, what happened, how long it took. Save the technical fix for a technical question.

Not knowing what things cost. Candidates who ran the estate for six years and cannot state their annual spend, their largest contract or their cost per seat.

Walk in able to state the total annual IT spend you were responsible for, your three largest line items, your cost per seat per month, and your next renewal date. If you were never shown the numbers, say that plainly and describe how you would get them in week one.

Describing a renewal as a percentage saved and nothing else.

Describe the terms you changed. Removing automatic renewal, co-terminating agreements, capping the uplift at renewal, closing mid-term true-up risk, and getting exit and data egress assistance written in are worth more than a one-off discount and show you read the contract.

Quoting backup success rates as evidence of resilience.

Quote your last tested restore: what you restored, how long it took, what failed during the test, and whether the business formally agreed the recovery time and data loss it can tolerate. Backups that have never been restored are an assumption, and panels know it.

A resume that lists forty technologies and never states team size, budget or seat count.

Put scope in the top third: people managed, annual budget owned, seats supported, sites. Cut the technology list to six items. The reader is deciding whether you have operated at their size, and nothing else answers that.

Treating a one-page resume as discipline at this level.

Use two pages. The scope, the budget history, the people record and the audit evidence are the case for hiring you, and compressing them out leaves a senior administrator resume behind.

Applying to a co-managed or outsourced role with a story that is only about managing employees.

Prepare the supplier version: the service levels you held a provider to, what you did when they missed, what your monthly service review produced, and whether you have ever triggered a service credit or exited a provider. Half of these roles are supplier governance jobs.

Proposing a platform migration or a reorganisation in the 90-day presentation.

Spend the first two weeks of the plan looking, and name the artefacts you would ask for. Then one visible quick win, then three costed fixes and one thing you would stop doing. Panels hire the candidate who asked the uncomfortable question about their estate, not the one with a generic roadmap.

Taking the ten percent cut question as a test of loyalty and offering training, spares and documentation first.

Give an ordered list with the risk accepted at each step, starting with reclaiming unused licences because it is free, and finish by naming what you would not cut: backups and restore testing, multi-factor authentication, endpoint protection, and support on anything that stops revenue.

Claiming AI has transformed IT management, or quoting a regulatory deadline you half remember.

Say plainly that the core of the job is unchanged, then be specific about what did change: assistant licensing and permissions cleanup, consumption-priced AI in contracts, shadow AI controls, machine identities, service desk deflection, and voice-era helpdesk verification. Name regulatory obligations without dates, and say the timetable should be checked.

Accepting the title without checking the scope, then discovering you have no hiring authority and no signing threshold.

Ask before you negotiate: how many reports, how many contractors, what is the annual spend, what can you approve without a second signature, who approves a hire, how many tickets a month, who carries on-call. A role that cannot answer these is not yet a manager role.

Questions people ask

Do you need a degree or a licence to become an IT manager?

No licence or registration exists for IT managers in the US, UK, Canada or Australia, and nothing legally gates the title. A bachelor's degree still appears in many postings and matters most in public sector, healthcare and university hiring, where it can be a hard screen written into the job description and enforced by HR. In the private mid-market, an IT manager with eight years of hands-on experience, a team they have led and a budget they have owned usually beats a degree with no scope behind it. If you lack the degree, apply anyway and let the scope statement at the top of your resume do the arguing.

Which certification should an IT manager get first?

An IT manager moving up from hands-on work should take ITIL 4 Foundation first. It is a single exam, it is the certification named most often in postings, and its real value is that it hands you the shared vocabulary panels use for incident, problem, change, request and service level. After that the choice depends on the role: PMP or PRINCE2 if the job is project-weighted, CISM or CISSP if it owns security, and one current Microsoft or AWS credential kept live so a management resume does not read as someone who has lost touch with the estate.

How does an IT manager interview test vendor and contract skills?

An IT manager is almost always asked to walk a panel through their most recent contract renewal, and the answer is scored on structure rather than on the discount. A strong response names the category and the real consumption against the licences paid for, states list price against what was paid, and then describes the terms that changed: automatic renewal removed, agreements co-terminated so renewals land together, the uplift at renewal capped, mid-term true-up risk closed, exit and data egress assistance written in. Panels are checking whether an IT manager will be captured by the incumbent reseller or will negotiate from their own data.

What four numbers should be on an IT manager resume?

An IT manager resume needs people managed, annual budget owned and whether it is operating or capital, seats or users supported, and number of sites or countries, all visible in the top third of page one. These four facts are what a recruiter screens on and what a hiring manager uses to decide quickly whether you have operated at their scale. Every one of them will be probed in interview, so use real figures you can defend with a document.

How does an IT manager answer the question about cutting ten percent of IT spend?

An IT manager answers a budget cut question with an ordered list and the risk accepted at each step, not with a single sacrifice. Start by reclaiming unused and duplicate licences because it costs nothing, then consolidate overlapping tools, then extend the hardware refresh cycle by a year while naming the higher failure rate and support load that creates, then renegotiate the two largest contracts, then defer a specific project. Finish by naming what you will not cut: backups and restore testing, multi-factor authentication, endpoint protection, and support on anything that stops revenue when it breaks.

Has AI reduced the number of IT manager jobs?

There is no credible evidence that AI has reduced demand for IT managers, and the honest position to take in an interview is that the core of the job (people, budget, vendors, risk and uptime) is largely unchanged. What AI has added is work: assistant licensing and the permissions cleanup that must happen before one is switched on, AI features priced by consumption rather than per seat, shadow AI controls, machine and service identities inside access reviews, and helpdesk verification procedures that no longer treat a familiar voice as proof of identity. Where it has bitten is tier one service desk work, where triage and summarisation deflect simple requests and push the harder remainder up into the IT manager's span.

How long does it take to go from hands-on IT to an IT manager role?

Most people reach a first IT manager role after five to eight years of hands-on work, usually including a period as a team lead, senior escalation point or project owner. The delay is rarely technical. What holds candidates back is never having been accountable when money or exposure was on the line, so the fastest route is to volunteer for the unpopular ownership work: the renewal calendar, the licence inventory, the access review, the restore test, and presenting ticket numbers monthly to someone outside IT.

What should an IT manager put in a 30/60/90 day plan presentation?

An IT manager should spend the first two weeks of the plan explicitly on looking, and name the artefacts requested: the asset and licence inventory, the eighteen month renewal calendar, the top ten ticket categories by volume, evidence of the last tested restore, the list of highest-privilege accounts, the risk register, and budget against actuals. Add one to one meetings with every direct report in week one and at least five business stakeholders in week two. Then commit to one low-risk, widely felt quick win inside the first month, and close with three costed fixes, one thing you would stop doing entirely, and what you would need from them to do it.

Where can an IT manager find reliable salary data?

An IT manager should start with the US Bureau of Labor Statistics Occupational Employment and Wage Statistics under SOC code 11-3021, Computer and Information Systems Managers, filtered to their metro area, while remembering that this code pools working IT managers with directors and CIOs and so reads high for a first manager role. Cross-check against live postings in pay-transparency jurisdictions such as Colorado, California, New York, Washington and Illinois, checking which rules currently apply where you are looking, and against published public sector, school district and university salary schedules, which are literal. The spread is driven mainly by seat count, headcount, reporting line, industry, on-call obligation and whether the role owns security as well as operations.

Who interviews an IT manager candidate?

An IT manager candidate is usually screened by a recruiter for twenty to thirty minutes, then interviewed by the hiring manager, who at mid-market companies is often the CFO, COO or an IT director rather than a technologist, then put in front of a stakeholder panel that commonly includes finance, sometimes HR, sometimes the security lead, and often a department head the role would serve. Any IT manager candidate should ask in the first conversation who the role reports to and what that person is measured on, because a CFO is buying spend control, a COO is buying uptime, and a CIO is buying delivery of a roadmap they already own.

Put this on a resume in about a minute

Paste your history once and point it at the IT Manager posting you are looking at. No account, no card.

Build my resume free More roles