Owns the hands-on buildout and operation of corporate identity, endpoint management, employee lifecycle automation, access reviews, SaaS governance, and a scoped government-information enclave. Requires modern identity-provider administration, macOS fleet management, EDR experience, audit-ready controls, and independent execution.
156k – 229k/yr
HybridIT Support
About the role
Responsibilities
Consolidate corporate identity behind a single identity provider, including application onboarding, automated provisioning, deprovisioning, and lifecycle rules.
Stand up endpoint management across the fleet; select and deploy the tool and create device and acceptable-use policies.
Build and instrument joiner, mover, and leaver processes with timing, audit trails, credential revocation, and hardware return.
Establish recurring access reviews that produce audit-ready evidence.
Stand up and document a narrowly scoped enclave with separate identity, managed devices, controlled storage, and a defined boundary.
Create a complete SaaS inventory covering owners, renewal dates, administrators, and data posture.
Separate privileged access from standard access and integrate identity and access evidence into the compliance program.
Prepare the environment for certificate- and smart-card-based authentication.
Write runbooks that allow the program to operate after the engagement ends.
Deliverables
Weeks 1–4
Inventory of devices, applications, and accounts mapped to named employees and reconciled against employment status.
Completion of the identity-provider rollout across remaining applications.
Written joiner, mover, and leaver process with timed and evidenced access revocation.
Weeks 5–12
Endpoint management selected, purchased, and deployed across the fleet.
Device and acceptable-use policy supporting evidence of contractually required software restrictions.
Quarterly access review established in an assessor-acceptable format.
End-to-end automated offboarding, including credential and physical-asset return.
Rationalized SaaS estate inventory.
Months 3–6
Documented separation of privileged and standard access.
Scheduled identity and access evidence for the compliance program.
Scoped enclave stood up and documented with a defined user list and durable boundary.
Readiness for certificate and smart-card authentication.
Operational runbooks.
Requirements
Experience administering a modern identity provider such as Okta, Microsoft Entra ID, or JumpCloud, including application onboarding, SCIM provisioning, and lifecycle rules.
Experience deploying endpoint management from zero across a real fleet using Jamf, Kandji, Hexnode, Intune, or similar.
Experience pairing endpoint management with an EDR tool such as CrowdStrike or Huntress.
Experience building joiner, mover, and leaver processes that produce audit trails.
Fluency in cloud-first, mostly macOS environments with Google Workspace, password managers, AWS console access, and SSO.
Ability to write clear, usable runbooks.
Ability to work independently as the only IT professional, with support from an engineering team.
Must be a US person.
Nice-to-Haves
Experience supporting SOC 2, FedRAMP, or CMMC from the IT side.
Knowledge of certificate and smart-card authentication, PIV, CAC, and government PKI.
Experience implementing device, software, or account restrictions required by government contracts.
Managed service provider experience.
Prior contract-engagement experience delivering comparable IT programs.
Scope
Ownership covers corporate identity and corporate devices, not product engineering or government hosting environments.
Security architecture decisions remain with the engineering lead; this role implements and operates the resulting systems.
Compensation and Benefits
ATS-listed salary range: $156,000–$228,800.
Medical, dental, and vision coverage are fully covered for employees and dependents, including Oxford/United Gold and Platinum PPO plans, Guardian PPO dental, and Beam vision.
Additional benefits include $100,000 in fully paid [benefit details truncated in source].
Lead IT Operations at Instacart, owning asset management, onboarding logistics, procurement, and internal communications. Requires 5+ years IT ops experience, leadership of logistics/onboarding/procurement teams, and proficiency with Jira and ITAM platforms.
155k – 164k/yrHybrid5+ YOEIT Support
Manager, IT Operations
FigmaSan Francisco, CA
Leads San Francisco IT Operations, managing a technical team, escalations, service metrics, systems administration, procurement, and cross-functional IT projects. Requires substantial IT support and team leadership experience plus advanced administration of major SaaS and workplace technology platforms.
153k – 269k/yrHybrid5+ YOEIT Support
Data Center Operations Coordinator
Together AISan Francisco, CA
Coordinate break/fix activities, ticket management, vendor dispatches, and operational reporting across multiple data centers to maintain uptime and fast issue resolution. Requires data center operations experience and hardware knowledge.
150k – 200k/yrOn-siteIT Support
IT Systems Administrator
PerplexitySan Francisco, CA
Manages IT infrastructure including computers, networks, MDM, security, and user accounts for an onsite San Francisco office. Requires 4+ years experience with macOS, GSuite, networking, and cybersecurity; provides technical support and leads projects.
150k – 180k/yrOn-site4+ YOEIT Support
IT Site Specialist
RampSan Francisco, CA
Provides hands-on IT support at Ramp’s San Francisco office while administering core SaaS applications, identity workflows, hardware, licenses, and integrations. Requires at least four years of technical experience spanning enterprise deskside support and SaaS administration.