Lead IT Systems Engineer
Indexed description
You'll own workforce identity and endpoint security end to end: the architecture, the automation, and the day-to-day. The centrepiece is making our HRIS the single source of truth for identity — when someone is hired, changes role, or leaves, the right access should appear or disappear without a ticket, and we should be able to prove it to an auditor.
This is a hands-on Lead-level IC role. You'll design the model and also build it.
What You'll Own
Identity lifecycle and HRIS as source of truth
- Design and build joiner/mover/leaver automation driven by our HRIS (Workable). This means building the integration — mapping employment events to identity actions via the Workable API, Okta Workflows, and middleware where needed. There is no off-the-shelf connector doing this for us
- Own the entitlement model: which groups, roles, and attributes determine access to what, and how role changes propagate
- Handle the cases that break naive automation — contractors and EOR workers, future-dated changes, internal transfers, rehires, leaves of absence, and country-specific variations in how employment is recorded
- Own how access is granted, reviewed, and revoked across our core SaaS estate: Okta, Google Workspace, Slack, Confluence/Jira, Workable, our HRIS, and the long tail of :20 other apps
- Run access reviews and certification campaigns that hold up under SOC 2 and ISO 27001 audit, ideally on a modern IGA platform rather than in spreadsheets
- Build self-service request-and-approval flows so access requests stop being Slack DMs
- Bring the long tail under management — including the apps with no SCIM support, where you'll need an API, a script, or a documented manual control
- Own our device fleet in Jamf (macOS)]: baseline configuration, patch and OS-update compliance, disk encryption, and fleet visibility, working with our external global tech provider and partner (https://www.tequipy.com/)
- Tie device posture to access — Okta Device Trust or equivalent — so sensitive apps are reachable only from managed, compliant devices
- Own secure remote access to internal systems (we are considering Tailscale and Cloudflare Zero Trust), and improve on it. Our people are everywhere; VPN-shaped solutions that assume an office don't fit us
- Be the identity and endpoint interface for SOC 2 and ISO 27001 — evidence, control design, auditor questions
- Instrument the above: alerting on suspicious authentication, MFA changes, privilege escalation, and drift in device compliance
- Write the runbooks. Make the offboarding path fast and provable, because that's the control auditors and customers ask about first
- Deep hands-on Okta experience as an administrator and builder — not just console clicks, but Workflows, SCIM, custom attribute mappings, and the debugging that comes with them
- You've personally built HRIS-driven joiner/mover/leaver automation, including the parts where the HRIS didn't cooperate
- You've run an access-governance program that survived a SOC 2 or ISO 27001 audit
- Practical endpoint management experience — Jamf or equivalent — and a view on how device posture should gate access
- You explain access decisions in terms of risk and business need, not just tooling, and you can say no to a request without making an enemy
- You can write code (w/ Claude Code): Python, Go, or TypeScript at the level of building and maintaining integrations and automation. Comfortable with REST APIs, webhooks, and Terraform or similar for config-as-code
- Experience with an IGA platform — Okta Identity Governance, ConductorOne, Lumos, or similar
- ZTNA / SASE experience: Tailscale, Tailscale SSH, Netskope, Cloudflare Access, Zscaler
- You've done this in a globally distributed, remote-first company, where there's no office network to hide behind and employment models vary by country
- Familiarity with the EOR / global employment space, or with the identity implications of a mixed employee-and-contractor workforce
- Exposure to customer-facing identity (Auth0, OIDC, SAML) — useful for talking to our product engineers, but not what this role is about
Benefits
- Fully remote role
- Opportunity to work on global-scale systems and products
- Exposure to international teams and modern engineering practices
- High ownership and autonomy in a fast-growing startup environment
- A strong culture grounded in speed, ownership, trust, transparency, customer obsession, and excellence
- Real problems, global impact, and the chance to help redefine how the world works
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search