Lead IT Systems Engineer
Adaugat: 2 zile în urmă
RemoFirst
Lead IT Systems Engineer
Adaugat: 2 zile în urmă
RemoFirst
Acest anunt este cu aplicare externa. Cand dati click pe Aplicare Externa veti fi redirectionat pe un alt site pentru a aplica.
About The RoleWe're a remote-first company of :250 people across 50 countries, and every one of them gets hired, onboarded, and offboarded through systems that need to talk to each other reliably. Today that happens with more human glue than we'd like.You'll own workforce identity and endpoint security end to end: the architecture, the automation, and the day-to-day. The centrepiece is making our HRIS the single source of truth for identity — when someone is hired, changes role, or leaves, the right access should appear or disappear without a ticket, and we should be able to prove it to an auditor.This is a hands-on Lead-level IC role. You'll design the model and also build it.What You'll OwnIdentity lifecycle and HRIS as source of truthDesign and build joiner/mover/leaver automation driven by our HRIS (Workable). This means building the integration — mapping employment events to identity actions via the Workable API, Okta Workflows, and middleware where needed. There is no off-the-shelf connector doing this for usOwn the entitlement model: which groups, roles, and attributes determine access to what, and how role changes propagateHandle the cases that break naive automation — contractors and EOR workers, future-dated changes, internal transfers, rehires, leaves of absence, and country-specific variations in how employment is recordedAccess governanceOwn how access is granted, reviewed, and revoked across our core SaaS estate: Okta, Google Workspace, Slack, Confluence/Jira, Workable, our HRIS, and the long tail of :20 other appsRun access reviews and certification campaigns that hold up under SOC 2 and ISO 27001 audit, ideally on a modern IGA platform rather than in spreadsheetsBuild self-service request-and-approval flows so access requests stop being Slack DMsBring the long tail under management — including the apps with no SCIM support, where you'll need an API, a script, or a documented manual controlEndpoint and network securityOwn our device fleet in Jamf (macOS)]: baseline configuration, patch and OS-update compliance, disk encryption, and fleet visibility, working with our external global tech provider and partner (https://www.tequipy.com/)Tie device posture to access — Okta Device Trust or equivalent — so sensitive apps are reachable only from managed, compliant devicesOwn secure remote access to internal systems (we are considering Tailscale and Cloudflare Zero Trust), and improve on it. Our people are everywhere; VPN-shaped solutions that assume an office don't fit usSecurity operations and auditBe the identity and endpoint interface for SOC 2 and ISO 27001 — evidence, control design, auditor questionsInstrument the above: alerting on suspicious authentication, MFA changes, privilege escalation, and drift in device complianceWrite the runbooks. Make the offboarding path fast and provable, because that's the control auditors and customers ask about firstRequirementsWhat we're looking forMust haveDeep hands-on Okta experience as an administrator and builder — not just console clicks, but Workflows, SCIM, custom attribute mappings, and the debugging that comes with themYou've personally built HRIS-driven joiner/mover/leaver automation, including the parts where the HRIS didn't cooperateYou've run an access-governance program that survived a SOC 2 or ISO 27001 auditPractical endpoint management experience — Jamf or equivalent — and a view on how device posture should gate accessYou explain access decisions in terms of risk and business need, not just tooling, and you can say no to a request without making an enemyNice to haveYou can write code (w/ Claude Code): Python, Go, or TypeScript at the level of building and maintaining integrations and automation. Comfortable with REST APIs, webhooks, and Terraform or similar for config-as-codeExperience with an IGA platform — Okta Identity Governance, ConductorOne, Lumos, or similarZTNA / SASE experience: Tailscale, Tailscale SSH, Netskope, Cloudflare Access, ZscalerYou've done this in a globally distributed, remote-first company, where there's no office network to hide behind and employment models vary by countryFamiliarity with the EOR / global employment space, or with the identity implications of a mixed employee-and-contractor workforceExposure to customer-facing identity (Auth0, OIDC, SAML) — useful for talking to our product engineers, but not what this role is aboutProbably not the right fit if your background is mainly application security or product/customer identity (CIAM), or if you want an architecture role where someone else does the building.BenefitsFully remote roleOpportunity to work on global-scale systems and productsExposure to international teams and modern engineering practicesHigh ownership and autonomy in a fast-growing startup environmentA strong culture grounded in speed, ownership, trust, transparency, customer obsession, and excellenceReal problems, global impact, and the chance to help redefine how the world works Show more Show less
Sfaturi de siguranta
- Nu trimiteti niciodata BANI in avans sau acte de identitate pentru aplicarea la un loc de munca. Nu trimiteti bani in avans pentru promisiuni de angajare sau alte oferte similare.
- Daca aveti impresia ca acest anunt nu este real, va rugam sa il raportati apasand butonul "Raporteaza Job"
This action will pause all job alerts. Are you sure?
Locuri de munca similare
Fii informat
Aboneaza-te la newsletter-ul nostru si primeste cele mai recente oferte de munca si informatii despre cariera direct in inbox-ul tau.
Securitatea datelor dumneavoastra este importanta pentru noi. Citeste Politica de confidentialitate.