The Opportunity
This role focuses on infrastructure for people and internal systems:
- Identity (SSO, RBAC, lifecycle)
- Endpoints (Mac, Windows, Linux)
- Access (device trust, zero-trust networking)
- Internal platform and automation
This is not a DevOps or SRE role
- You will not primarily own CI/CD pipelines or Kubernetes clusters
- You will not focus on application deployment infrastructure
- This role is about access, identity, endpoints, and secure systems for humans
How You'll Fulfill Your Mission
- Own identity as a first-class system (SSO, RBAC, lifecycle, device trust)
- Build a fully automated onboarding/offboarding pipeline
- Design and operate endpoint infrastructure across Mac, Windows, and Linux
- Eliminate manual IT work through automation, scripting, and tooling
- You should expect to spend the majority of your time building systems and automation—not responding to tickets
- Architect secure network infrastructure across office, lab, and remote environments
- Design and implement modern access patterns (e.g., WireGuard-based networking, zero-trust, device-aware access)
- Own firewall and perimeter security (Palo Alto, Juniper, or equivalent)
- Enable secure, compliant access to cloud environments (AWS GovCloud, GCP Assured Workloads)
- Drive compliance (CMMC, ITAR) through systems—not paperwork
- Partner directly with engineering to remove friction and increase velocity
- You will have high ownership and autonomy to define how these systems are built and operated
Why We Value You
- 8+ yrs of related experience
- 5+ years Proven experience building and owning infrastructure systems
- Deep experience with identity systems (Azure AD / Entra or equivalent; SAML/OAuth/SCIM)
- Strong experience managing heterogeneous endpoint fleets (Mac, Windows, Linux; MDM such as Intune/Jamf/Kandji)
- Hands-on experience with network security and modern connectivity patterns (VPNs, WireGuard, zero-trust networking)
- Strong scripting and automation skills (Python, Bash, or similar)
- Experience integrating systems via APIs and event-driven workflows
- Experience operating in regulated environments (CMMC, ITAR, FedRAMP-like)
What Sets You Apart
- You treat internal infrastructure like a product, not a helpdesk
- You automate everything that happens more than once
- You reduce complexity instead of adding it