IT Engineer
Job description
About the role
You will serve as the on-site IT support engineer for our New York office, acting as the primary technical point of contact for employees and resolving hardware, account, and access issues directly in person and through the ticket queue. You will co-own identity and access management alongside the security and engineering teams, ensuring that employee identities are accurate, secure, and aligned with business needs across all systems. In this position, you will administer and evolve our core SaaS stack, taking responsibility for the configuration, health, and adoption of tools that the company relies on every day. You will own the employee identity lifecycle from start to finish, managing onboarding, off-boarding, and access changes with precision and timeliness through platforms like Okta. You will configure and maintain critical integration protocols such as SSO, SAML, OIDC, and SCIM as we bring on new SaaS applications and streamline existing connections. You will automate recurring IT and access-management tasks using scripting in Python and Bash, leveraging orchestration tools to reduce manual effort and improve reliability. You will support security and compliance initiatives by enforcing least-privilege access, MFA policies, and maintaining audit-ready documentation required for frameworks like SOC
2. You will write and maintain clear run-books and architecture documentation so that the systems you build are understandable, maintainable, and usable by the rest of the team. You will identify opportunities to streamline and enhance IT operations at scale, proposing and implementing improvements that support efficiency and growth.
Key facts
What you'll do
- Serve as the on-site IT support engineer for our New York office, resolving hardware, account, and access issues for employees in person and through the ticket queue.
- Administer and evolve our core SaaS stack, including Okta, Google Workspace, Slack, Notion, and other platforms that the business depends on.
- Own the employee identity lifecycle, handling onboarding, off-boarding, and access changes with accuracy and timeliness through Okta.
- Configure and maintain SSO, SAML, OIDC, and SCIM integrations as we integrate new SaaS applications and streamline existing ones.
- Own Mac endpoint management through Rippling MDM, including configuration policies, OS and application patching, and compliance enforcement.
- Automate recurring IT and access-management work using Python, Bash, and tools like Workato or similar platforms.
- Support security and compliance efforts, including least-privilege access, MFA enforcement, and audit-ready documentation for SOC 2 and related frameworks.
- Write and maintain clear run-books and architecture documentation so that the systems you build remain usable and scalable for the rest of the team.
- Identify opportunities to streamline and enhance IT operations at scale, improving processes and enabling the business to operate more efficiently.
- Act as a hands-on problem solver, driving root-cause analysis and implementing fixes that reduce recurring issues.
- Collaborate closely with security, engineering, and operations teams to align IT infrastructure with company goals and compliance requirements.
- Take ownership of end-to-end problem resolution, ensuring that solutions are durable and reduce future ticket volume.
- Evaluate and pilot new SaaS tools and integrations, ensuring they meet security, usability, and operational standards before broad deployment.
- Contribute to incident response and disaster recovery processes, ensuring minimal disruption to the business during critical events.
Requirements
- 5-7 years of experience in IT systems, endpoint, or identity engineering, ideally within a fast-growing company.
- Hands-on administration experience with Okta, including user management, policies, and system configurations.
- Working knowledge of SSO, SAML, OIDC, and SCIM protocols and their implementation in enterprise environments.
- Experience managing SaaS platforms such as Google Workspace, Slack, Notion, Rippling, and communication or productivity tools.
- Experience with Mac endpoint management using Rippling or similar MDM solutions, including policy enforcement and compliance.
- Scripting ability in Python or Bash, with a proven track record of building and deploying automation for IT operations.
- Strong troubleshooting instincts across systems that touch identity, networking, and SaaS integrations, including logs and diagnostics.
- Clear written communication skills, with an emphasis on documenting configurations, processes, and decisions thoroughly.
- Comfort with ambiguity and a preference for owning problems from start to finish, driving solutions without excessive direction.
- Willingness to work in our New York office five days a week and provide in-person support to colleagues while engaging in longer-term strategic projects.
Nice to have
- Experience with iPaaS platforms like Workato, Zapier, or Tines for building and managing integrations.
- Exposure to AWS, GCP, or Azure administration, including basic resource management and security practices.
- Familiarity with SOC 2, ISO 27001, or similar compliance frameworks and the requirements they impose on IT and security controls.
- Experience with infrastructure-as-code tools such as Terraform for managing cloud and infrastructure resources.
- Okta certifications or demonstrated commitment to professional development in identity and access management.
- Experience within high-growth technology businesses, understanding of the unique challenges and priorities they create.
Practical notes
You will work from our New York City office five days a week, providing in-person support and collaborating closely with distributed teams. This is a full-time role with a standard work schedule aligned with business needs. No visa sponsorship is available for this position. The start date is dependent on business needs and the availability of the successful candidate.