# IT Operations Manager

**Company:** [Kaizen Labs](https://hotfix.jobs/companies/kaizen-labs)
**Location:** New York, NY, Washington, DC
**Role:** IT Support
**Salary:** $156k – $229k/yr
**Skills:** Okta, microsoft entra id, jumpcloud, SCIM, Jamf, kandji, hexnode, intune, crowdstrike, huntress, Google Workspace, AWS, SSO, piv, cac
**Posted:** 2026-08-10

> Owns the hands-on buildout and operation of corporate identity, endpoint management, employee lifecycle automation, access reviews, SaaS governance, and a scoped government-information enclave. Requires modern identity-provider administration, macOS fleet management, EDR experience, audit-ready controls, and independent execution.

## Job Description

## Responsibilities
- Consolidate corporate identity behind a single identity provider, including application onboarding, automated provisioning, deprovisioning, and lifecycle rules.
- Stand up endpoint management across the fleet; select and deploy the tool and create device and acceptable-use policies.
- Build and instrument joiner, mover, and leaver processes with timing, audit trails, credential revocation, and hardware return.
- Establish recurring access reviews that produce audit-ready evidence.
- Stand up and document a narrowly scoped enclave with separate identity, managed devices, controlled storage, and a defined boundary.
- Create a complete SaaS inventory covering owners, renewal dates, administrators, and data posture.
- Separate privileged access from standard access and integrate identity and access evidence into the compliance program.
- Prepare the environment for certificate- and smart-card-based authentication.
- Write runbooks that allow the program to operate after the engagement ends.

## Deliverables
### Weeks 1–4
- Inventory of devices, applications, and accounts mapped to named employees and reconciled against employment status.
- Completion of the identity-provider rollout across remaining applications.
- Written joiner, mover, and leaver process with timed and evidenced access revocation.

### Weeks 5–12
- Endpoint management selected, purchased, and deployed across the fleet.
- Device and acceptable-use policy supporting evidence of contractually required software restrictions.
- Quarterly access review established in an assessor-acceptable format.
- End-to-end automated offboarding, including credential and physical-asset return.
- Rationalized SaaS estate inventory.

### Months 3–6
- Documented separation of privileged and standard access.
- Scheduled identity and access evidence for the compliance program.
- Scoped enclave stood up and documented with a defined user list and durable boundary.
- Readiness for certificate and smart-card authentication.
- Operational runbooks.

## Requirements
- Experience administering a modern identity provider such as Okta, Microsoft Entra ID, or JumpCloud, including application onboarding, SCIM provisioning, and lifecycle rules.
- Experience deploying endpoint management from zero across a real fleet using Jamf, Kandji, Hexnode, Intune, or similar.
- Experience pairing endpoint management with an EDR tool such as CrowdStrike or Huntress.
- Experience building joiner, mover, and leaver processes that produce audit trails.
- Experience running auditor-accepted access reviews.
- Fluency in cloud-first, mostly macOS environments with Google Workspace, password managers, AWS console access, and SSO.
- Ability to write clear, usable runbooks.
- Ability to work independently as the only IT professional, with support from an engineering team.
- Must be a US person.

## Nice-to-Haves
- Experience supporting SOC 2, FedRAMP, or CMMC from the IT side.
- Knowledge of certificate and smart-card authentication, PIV, CAC, and government PKI.
- Experience implementing device, software, or account restrictions required by government contracts.
- Managed service provider experience.
- Prior contract-engagement experience delivering comparable IT programs.

## Scope
- Ownership covers corporate identity and corporate devices, not product engineering or government hosting environments.
- Security architecture decisions remain with the engineering lead; this role implements and operates the resulting systems.

## Compensation and Benefits
- ATS-listed salary range: $156,000–$228,800.
- Medical, dental, and vision coverage are fully covered for employees and dependents, including Oxford/United Gold and Platinum PPO plans, Guardian PPO dental, and Beam vision.
- Additional benefits include $100,000 in fully paid [benefit details truncated in source].

## Similar roles

- [Manager, IT Operations](https://hotfix.jobs/jobs/6cce2e96-91f9-41c6-9634-80d5e97538a7) - Instacart - San Francisco, CA - $155k – $164k/yr
- [Manager, IT Operations](https://hotfix.jobs/jobs/0b8a56d5-9ff4-47dc-a5dc-6d1c8938eb6e) - Figma - San Francisco, CA - $153k – $269k/yr
- [Data Center Operations Coordinator](https://hotfix.jobs/jobs/94880dbb-6c68-4b94-8898-cc19904b8937) - Together AI - San Francisco, CA - $150k – $200k/yr
- [IT Systems Administrator](https://hotfix.jobs/jobs/1a1a9fd5-2ab7-4886-8428-49615011a2e5) - Perplexity - San Francisco, CA - $150k – $180k/yr
- [IT Site Specialist](https://hotfix.jobs/jobs/bee33ebf-5c73-4e7e-863f-fc229aec182d) - Ramp - San Francisco, CA - $146k – $200k/yr

**Apply:** https://hotfix.jobs/jobs/57f0c29f-00b3-4c35-8db4-0a49e33c0dc9
**Canonical:** https://hotfix.jobs/jobs/57f0c29f-00b3-4c35-8db4-0a49e33c0dc9