Lead IT Systems Engineer
Brak informacji o wynagrodzeniu
SeniorFull-time
#397846·Dodano 9 dni temu·2
Źródło: RemofirstTech Stack / Keywords
SecurityArchitectureAPIJiraNetworkPythonGoTypeScript
Firma i stanowisko
Remofirst is a remote-first company with approximately 250 employees across 50 countries.
Wymagania
- Deep hands-on Okta experience including administration, Workflows, SCIM, custom attribute mappings, and troubleshooting.
- Experience building HRIS-driven joiner/mover/leaver automation, including handling non-cooperative HRIS cases.
- Experience running access-governance programs compliant with SOC 2 or ISO 27001 audits.
- Practical endpoint management experience with Jamf or equivalent, and understanding of device posture gating access.
- Capability to explain access decisions based on risk and business need, and confidently deny requests when necessary.
Nice to have:
- Ability to write code in Python, Go, or TypeScript for building and maintaining integrations and automation, with experience using REST APIs, webhooks, and configuration as code tools like Terraform.
- Experience with IGA platforms such as Okta Identity Governance, ConductorOne, or Lumos.
- Knowledge of ZTNA/SASE technologies like Tailscale, Tailscale SSH, Netskope, Cloudflare Access, or Zscaler.
- Experience working in a globally distributed, remote-first company with varied employment models.
- Familiarity with EOR/global employment and identity management for mixed employee and contractor workforces.
- Exposure to customer-facing identity technologies like Auth0, OIDC, and SAML (helpful but not the primary focus).
Obowiązki
- Design and build joiner/mover/leaver automation driven by the HRIS (Workable), integrating with APIs and middleware.
- Own the entitlement model, defining which groups, roles, and attributes determine access and how role changes propagate.
- Handle special cases in automation including contractors, EOR workers, future-dated changes, internal transfers, rehires, leaves of absence, and country-specific employment variations.
- Manage access granting, review, and revocation across core SaaS applications including Okta, Google Workspace, Slack, Confluence/Jira, and others.
- Conduct access reviews and certification campaigns compliant with SOC 2 and ISO 27001 audits.
- Build self-service request and approval flows to replace informal access requests.
- Manage access for applications without SCIM support via APIs, scripts, or manual controls.
- Oversee device fleet management in Jamf (macOS), including baseline configurations, patch compliance, disk encryption, and fleet visibility.
- Implement device posture integration with access controls (e.g., Okta Device Trust) to restrict sensitive apps to managed, compliant devices.
- Manage secure remote access solutions (considering Tailscale and Cloudflare Zero Trust) suitable for a distributed workforce.
- Serve as the identity and endpoint interface for SOC 2 and ISO 27001 audits, providing evidence and control design.
- Implement alerting on suspicious authentication, MFA changes, privilege escalation, and device compliance drift.
- Write runbooks to ensure a fast and provable offboarding process.
Benefity
- Fully remote role.
- Opportunity to work on global-scale systems and products.
- Exposure to international teams and modern engineering practices.
- High ownership and autonomy in a fast-growing startup environment.
Elastyczne godziny
RemoFirst
6 aktywnych ofert