Responsibilities
- Manage daily Okta operations including user lifecycle actions, group configurations, single sign-on setups, and multi-factor authentication policies.
- Lead joiner-mover-leaver processes to ensure timely access provisioning, modification, and deactivation without manual intervention.
- Enhance automated workflows in Okta to minimize manual tasks and align access changes with HR system updates.
- Conduct routine access reviews to detect inactive accounts, excessive permissions, and unassigned application access to prevent security risks.
- Support deployment of FIDO2, WebAuthn, and YubiKey for secure authentication across privileged roles.
- Oversee Iru (formerly Kandji) MDM for macOS devices, including enrollment, configuration, compliance monitoring, and policy enforcement.
- Enforce endpoint security standards such as encryption, screen lock settings, patch management, and EDR agent installation.
- Coordinate global hardware logistics including device acquisition, setup, and timely delivery for new hires across time zones.
- Detect and monitor unmanaged or non-compliant devices, lead remediation efforts, and escalate unresolved cases.
- Implement MDM configurations using code-based practices to enable version control, peer review, and rollback capabilities.
- Administer enterprise Slack environments including channel governance, third-party app integrations, guest access, and multi-workspace coordination.
- Oversee corporate SaaS applications by managing user access, license allocation, and periodic access reviews for platforms like Google Workspace, Zoom, and Notion.
- Evaluate new SaaS tool requests against security and data protection requirements prior to approval and deployment.
- Keep an updated registry of all business applications, including ownership, access levels, and data sensitivity classifications.
- Automate repetitive IT processes using scripting, workflow tools, or identity lifecycle rules to improve efficiency.
- Develop and maintain operational runbooks to ensure consistent support across distributed teams and time zones.
- Track and report key IT performance indicators such as access provisioning speed, offboarding completion rates, device compliance, and review frequency.
- Collaborate with Security Engineering to resolve control deficiencies identified during compliance audits like SOC 2 and ISO 27001.
Benefits
- Fully remote work model with global hiring; optional WeWork or co-working space allowance available worldwide.
- Equity participation through an Employee Stock Option Plan for all team members.
- Annual technology stipend to support personal work equipment and setup preferences.
- Comprehensive health insurance coverage paid in full for employees and 80% for dependents, regardless of location.
- Yearly company-wide off-site event in a rotating international location for team bonding and collaboration.
- Flexible, asynchronous work culture that empowers individuals to manage their own schedules.
- Annual budget for professional growth including courses, certifications, books, and conferences.
Work Arrangement
Remote (Worldwide)
Other
Fully remote position with a preference for candidates located in EST or APAC time zones.