
IT Systems Administrator
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Manage Microsoft Entra ID and Microsoft 365 users, groups, licensing, conditional access, and MFA policies.
• Take ownership of SSO and SAML/OIDC integrations across the federated SaaS landscape and onboard new applications.
• Perform periodic access reviews, conduct least-privilege cleanups, and generate review evidence.
• Assist with domain modifications, directory migrations, and platform consolidation efforts.
• Oversee the Rippling device fleet, including enrollment, configuration, compliance policies, patching, and encryption standards.
• Manage hardware procurement, imaging, shipping, refresh cycles, secure retirement, and asset inventory.
• Keep accurate inventories of devices, software, and SaaS licenses.
• Handle the complete employee onboarding and offboarding process, ensuring same-day provisioning and deprovisioning.
• Act as the escalation point for employee IT requests related to accounts, access, devices, connectivity, and conferencing.
• Administer company-wide SaaS provisioning, deprovisioning, license reconciliation, and vendor/renewal coordination.
• Automate repetitive IT tasks such as scripted provisioning, license reconciliation, access reporting, and compliance evidence collection.
• Utilize Claude Code and Cursor as daily AI tools and develop human- and agent-executable runbooks.
• Support company-wide AI tooling operations, including seat and license management and access provisioning.
• Assist with SOC 2 and NIST 800-171 audits, including evidence collection, auditor responses, remediation tracking, and IT-side controls.
• Manage Vanta and maintain integrations with identity, device, and ticketing systems.
• Track security awareness training, policy acknowledgments, e-signatures, and access review attestations.
• Maintain IT and security policy documentation.
• Administer Keeper and enforce best practices for credential hygiene.
• Support internal network and remote access infrastructure, including the SAML-integrated VPN.
• Develop and maintain runbooks, knowledge base articles, and self-service documentation.
• 3-5 years of practical IT systems administration experience supporting a distributed workforce.
• Proven experience in administering Microsoft Entra ID (Azure AD) and Microsoft 365; this is a strict requirement.
• Hands-on experience with MDM / endpoint management at a company scale, including enrollment, compliance policy, and configuration baselines.
• Familiarity with Rippling, Jamf, Kandji, or a similar endpoint management platform.
• Practical experience in configuring SSO/SAML application integrations and troubleshooting federation issues.
• Experience managing employee onboarding and offboarding, including access provisioning and deprovisioning.
• Scripting skills sufficient to automate tasks using PowerShell, Bash, or Python.
• Experience supporting a security audit or compliance program, including evidence collection, auditor communication, and maintaining control documentation.
• Strong written communication and technical writing abilities; capable of producing clear and usable documentation.
• Genuine interest in utilizing AI tools in operational tasks and a quick aptitude for learning them.
• Service-oriented mindset with sound judgment regarding urgency.
• A degree is appreciated, but experience is the primary focus of evaluation.
• Google Workspace administration experience is preferred.
• Direct experience with Rippling or another HRIS serving as the provisioning source is preferred.
• Familiarity with SOC 2, NIST 800-171, NIST 800-53, CMMC, ISO 27001, Vanta, Drata, or Apptega is preferred.
• Experience with Terraform/OpenTofu or configuration management is preferred.
• Knowledge of GitHub and GitHub Actions, including organization and access administration, is preferred.
• Experience managing a password manager or secrets platform at a company scale is preferred.
• Exposure to Azure, Kubernetes, or a platform engineering environment is preferred.
• Previous experience developing internal automations, integrations, or agents is preferred.
• Background in construction, MEP, manufacturing, or another non-software-native industry is preferred.
• Eligibility to work in the U.S.; E-Verify verification will occur post-hire.
• Comprehensive and competitive health benefits plan.
• Matching 401k contributions.
• 20 days of annual PTO.
• Primarily remote work with occasional annual team onsite events.
accompio
Cumming Group
TopDog Law
Iron Mountain
Get handpicked remote jobs straight to your inbox weekly.