Salary
💰 $130,000 - $190,000 per year
Tech Stack
DNSJamfMacOSPythonSwiftTCP/IP
About the role
- Own and administer Mobile Device Management (MDM) platforms (JAMF for macOS and Microsoft Intune for Windows) to automate device deployment, enforce security policies, and manage software distribution.
- Develop and maintain a comprehensive IT Asset Management (ITAM) strategy overseeing the full hardware lifecycle from procurement and deployment to maintenance and secure retirement.
- Implement and refine zero-touch deployment workflows to create a seamless and secure onboarding experience for employees.
- Serve as the primary administrator for the portfolio of SaaS applications, managing licensing, integrations, security configurations, and cost-optimization.
- Develop automated workflows for user provisioning and de-provisioning across the application ecosystem.
- Partner with business departments to evaluate, onboard, and secure new SaaS tools and ensure they meet security standards.
- Manage and enhance the Identity Provider (Okta), including user lifecycle rules, group management, application integrations (SAML/SCIM), and MFA policies.
- Design and enforce role-based access control (RBAC) policies to ensure least-privilege access across corporate systems.
- Act as the subject matter expert on identity, authentication, and authorization, driving security best practices.
- Explore and implement AI-driven tools and methodologies to enhance system monitoring, security, and administrative efficiency.
- Proactively identify potential issues and engineer scalable, resilient solutions for the corporate environment.
Requirements
- 4+ years of experience in an IT Systems Engineer, Infrastructure Engineer, or similar role.
- Deep, hands-on expertise with modern MDM platforms, specifically JAMF Pro and Microsoft Intune.
- Proven experience managing an Identity Provider, with a strong preference for Okta.
- Demonstrable experience administering a wide range of SaaS applications (e.g., Google Workspace, Slack, Atlassian).
- Strong understanding of ITAM principles and hardware lifecycle management.
- Solid knowledge of networking concepts (TCP/IP, DNS, DHCP, VPNs).
- Experience with scripting and automation is highly desirable (e.g., PowerShell, Bash, or Python).
- Experience implementing zero-touch deployment workflows and managing the full hardware lifecycle (procurement, deployment, maintenance, secure retirement).
- Experience developing automated workflows for user provisioning and de-provisioning (lifecycle management).
- Demonstrable experience with RBAC, MFA policies, SAML/SCIM integrations, and identity lifecycle rules.
- Security-first mindset and proactive problem-solving abilities.
- Experience collaborating cross-functionally and driving security best practices across teams.