IT Systems Administrator
United StatesRemote2+ YOE
Summary
Own day-to-day identity and endpoint operations for a remote-first SaaS company. Administer Okta, Iru MDM, and Slack while automating JML workflows and maintaining security compliance across global time zones.
About the role
Identity & Access Management
- Administer Okta day-to-day: user provisioning, group management, SSO application configuration, and MFA policy enforcement
- Own joiner-mover-leaver (JML) workflows — ensure access is granted on day one, adjusted on role change, and fully revoked on departure
- Maintain and improve Okta lifecycle automation
- Audit access regularly: identify stale accounts, over-provisioned roles, and orphaned app assignments
- Support FIDO2/WebAuthn and YubiKey deployment for privileged access
Endpoint Management & MDM
- Administer Iru (formerly Kandji) MDM for macOS fleet: device enrollment, configuration profiles, compliance baselines, and policy enforcement
- Ensure all managed endpoints meet security baselines — disk encryption, screen lock, patch cadence, and EDR agent deployment
- Support onboarding hardware logistics: device procurement, enrollment, and first-day readiness
- Identify and track unmanaged or out-of-compliance devices; drive remediation
- Maintain MDM configuration as code where possible
SaaS & Collaboration Platform Operations
- Administer Slack workspace: channel governance, app integration reviews, guest access management, and enterprise grid operations
- Manage the corporate SaaS portfolio — own app provisioning, license tracking, and access reviews for tools like Google Workspace, Zoom, Notion
- Review and approve new SaaS integration requests against security and data handling standards
- Maintain an accurate inventory of corporate applications
Automation & Process Improvement
- Identify repetitive IT tasks and eliminate them through automation — scripting, workflow tooling, or Okta lifecycle rules
- Write and maintain runbooks for all core IT operations
- Contribute to IT metrics: onboarding time-to-access, offboarding completion rate, MDM compliance percentage, and access review cadence
- Partner with the Security Engineering team to close gaps surfaced by compliance audits (SOC 2, ISO 27001)
Requirements
- 2–4 years in a corporate IT, IT operations, or identity administration role at a cloud-native or SaaS company
- Hands-on Okta administration experience: SSO, MFA, lifecycle management, and group/policy configuration
- Experience with a modern MDM platform (Kandji/Iru, Jamf, or equivalent) managing a macOS-first fleet
- Working knowledge of JML processes
- Comfortable with scripting or automation (Bash, Python, or similar)
- Async-first communicator: document decisions, write clear runbooks
Nice to Have
- Experience with FIDO2/WebAuthn deployment or hardware security key programs (YubiKey 5 series)
- Familiarity with Slack enterprise grid administration including app governance and Connect channel management
- Exposure to SOC 2 or ISO 27001 evidence collection for identity and endpoint controls
- Experience managing IT operations across APAC and Americas time zones simultaneously
- Familiarity with Google Workspace admin, including directory sync and group-based provisioning
- Prior work in a security-adjacent IT role where identity hygiene and access control were first-class concerns
Skills
OktaSSOMFAIAMKandjiIruMDMJamfmacOSJML workflowsBashPythonSlack Enterprise GridGoogle WorkspaceSOC 2