Lead IT Systems Engineer

Brak informacji o wynagrodzeniu
SeniorFull-time
#397846·Dodano 9 dni temu·2
Źródło: Remofirst
Aplikuj teraz

Tech Stack / Keywords

SecurityArchitectureAPIJiraNetworkPythonGoTypeScript

Firma i stanowisko

Remofirst is a remote-first company with approximately 250 employees across 50 countries.

Wymagania

  • Deep hands-on Okta experience including administration, Workflows, SCIM, custom attribute mappings, and troubleshooting.
  • Experience building HRIS-driven joiner/mover/leaver automation, including handling non-cooperative HRIS cases.
  • Experience running access-governance programs compliant with SOC 2 or ISO 27001 audits.
  • Practical endpoint management experience with Jamf or equivalent, and understanding of device posture gating access.
  • Capability to explain access decisions based on risk and business need, and confidently deny requests when necessary.

Nice to have:

  • Ability to write code in Python, Go, or TypeScript for building and maintaining integrations and automation, with experience using REST APIs, webhooks, and configuration as code tools like Terraform.
  • Experience with IGA platforms such as Okta Identity Governance, ConductorOne, or Lumos.
  • Knowledge of ZTNA/SASE technologies like Tailscale, Tailscale SSH, Netskope, Cloudflare Access, or Zscaler.
  • Experience working in a globally distributed, remote-first company with varied employment models.
  • Familiarity with EOR/global employment and identity management for mixed employee and contractor workforces.
  • Exposure to customer-facing identity technologies like Auth0, OIDC, and SAML (helpful but not the primary focus).

Obowiązki

  • Design and build joiner/mover/leaver automation driven by the HRIS (Workable), integrating with APIs and middleware.
  • Own the entitlement model, defining which groups, roles, and attributes determine access and how role changes propagate.
  • Handle special cases in automation including contractors, EOR workers, future-dated changes, internal transfers, rehires, leaves of absence, and country-specific employment variations.
  • Manage access granting, review, and revocation across core SaaS applications including Okta, Google Workspace, Slack, Confluence/Jira, and others.
  • Conduct access reviews and certification campaigns compliant with SOC 2 and ISO 27001 audits.
  • Build self-service request and approval flows to replace informal access requests.
  • Manage access for applications without SCIM support via APIs, scripts, or manual controls.
  • Oversee device fleet management in Jamf (macOS), including baseline configurations, patch compliance, disk encryption, and fleet visibility.
  • Implement device posture integration with access controls (e.g., Okta Device Trust) to restrict sensitive apps to managed, compliant devices.
  • Manage secure remote access solutions (considering Tailscale and Cloudflare Zero Trust) suitable for a distributed workforce.
  • Serve as the identity and endpoint interface for SOC 2 and ISO 27001 audits, providing evidence and control design.
  • Implement alerting on suspicious authentication, MFA changes, privilege escalation, and device compliance drift.
  • Write runbooks to ensure a fast and provable offboarding process.

Benefity

  • Fully remote role.
  • Opportunity to work on global-scale systems and products.
  • Exposure to international teams and modern engineering practices.
  • High ownership and autonomy in a fast-growing startup environment.
Elastyczne godziny
RemoFirst

RemoFirst

6 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz