IT Systems AdministratorActive

The opportunity

You will work directly with our IDM/MDM Lead to own the day-to-day operations of our identity and endpoint stack — Okta, Slack, Iru (MDM), and the integrations that tie them together. This role is equal parts identity management and endpoint operations, with a strong expectation…

What you'll do

  • Administer Okta day-to-day: user provisioning, group management, SSO application configuration, and MFA policy enforcement.

  • Own joiner-mover-leaver (JML) workflows: ensure access is granted on day one, adjusted on role change, and fully revoked on departure with no manual gaps.

  • Maintain and improve Okta lifecycle automation, reducing manual provisioning: toil and closing the window between HR events and access changes.

  • Audit access regularly: identify stale accounts, over-provisioned roles, and orphaned app assignments before they become incidents.

  • Support FIDO2/WebAuthn and YubiKey deployment for privileged access across the organization.

  • Administer Iru (formerly Kandji) MDM for macOS fleet: device enrollment, configuration profiles, compliance baselines, and policy enforcement.

What they're looking for

  • Ensure all managed endpoints meet security baselines: disk encryption, screen lock, patch cadence, and EDR agent deployment.
  • Support onboarding hardware logistics: device procurement, enrollment, and first-day readiness across global time zones.
  • Identify and track unmanaged or out-of-compliance devices; drive remediation: and escalate persistent non-compliance.
  • Maintain MDM configuration as code where possible: changes should be reviewable, versioned, and reversible.