IT Operations Manager (Contract)
Kaizen · New York, NY · 2 wk ago
HybridInformation Technology$35/hrFull-time
About the Role
Kaizen builds software for federal and local government. We are roughly ~40 people on a cloud-first, mostly macOS stack, and we sell into customers who impose real requirements on how we run our own corporate systems. IT here is currently distributed across engineers and operators who all have other full-time jobs. This role will build the IT layer properly, leaving behind a system that runs without you.
Responsibilities
- Identity: Consolidate everything behind a single identity provider, focusing on the tail-end applications, manual provisioning, and lifecycle rules. Own the system, including automated provisioning and deprovisioning.
- Endpoints: Stand up a device management program to meet government customer requirements. Select, deploy, and manage tools across the fleet, and write accompanying policies.
- Employee lifecycle: Turn joiner, mover, and leaver processes into instrumented systems with timing, audit trails, and named owners. Ensure tight windows for disabling access upon departure, with evidence of compliance.
- Access reviews: Own recurring reviews of access permissions, producing evidence for auditors and government customers.
- Scoped enclave: Stand up a separate, narrow environment for controlled government information, with its own identity, managed devices, controlled storage, and documented boundaries. Maintain the scope over time.
- SaaS estate: Inventory all SaaS applications, including owners, renewal dates, admins, and data posture. Transition this knowledge from people’s heads into a documented system.
Deliverables
- Weeks 1 to 4:
- Complete inventory of devices, applications, and accounts, mapped to named humans and reconciled against employment status.
- Identity provider rollout finished across remaining applications.
- Written joiner, mover, and leaver process with timed and evidenced revocation steps.
- Weeks 5 to 12:
- Endpoint management selected, purchased, and deployed across the fleet, with policies evidencing contract requirements.
- Quarterly access review established in an auditor-accepted format.
- End-to-end automated offboarding, including credential and physical asset return with written confirmation.
- SaaS estate rationalized: inventory, owners, renewal dates, admin lists, and data posture documented.
- Months 3 to 6:
- Privileged access separated from standard access and documented.
- Identity and access evidence flowing to compliance program on a schedule.
- Scoped enclave stood up, documented, with a defined user list and maintained boundary.
- Readiness for certificate and smart-card-based authentication.
- Runbooks sufficient to sustain the program post-engagement.
Requirements
- Owned a modern identity provider (Okta, Entra, or JumpCloud) as an administrator, including app onboarding, SCIM provisioning, and lifecycle rules.
- Deployed endpoint management (Jamf, Kandji, Hexnode, or Intune) from zero across a real fleet, including handling user pushback.
- Paired endpoint management with an EDR tool (CrowdStrike, Huntress, or similar).
- Built a joiner, mover, and leaver process that produces an audit trail, not just a checklist.
- Run an access review accepted by an auditor, understanding the difference between a spreadsheet and evidence.
- Fluent in a cloud-first, mostly macOS environment (Google Workspace, password manager, AWS console access, SSO everywhere).
- Write runbooks others can follow, ensuring the system outlasts the engagement.
- Comfortable as the sole IT person, collaborating with an engineering team that does not report to you.
- US person.
Nice-to-Have Skills
- Taken a company through SOC 2, FedRAMP, or CMMC on the IT side, knowing which access and device artifacts assessors require.
- Experience with certificate and smart-card authentication (PIV or CAC) and government PKI.
- Handled device, software, or account restrictions flowing down from government contracts.
- Background in a managed service provider, preferring to build in-house over firefighting.
- Completed a similar contract engagement, with insights on what made it succeed or fail.
Scope of Work
You will own corporate identity and corporate devices, not product engineering or government hosting environments. Security architecture decisions sit with our engineering lead; you will implement and operate.
Benefits
- Health & Insurance:
- 100% coverage for medical (Oxford/United Gold and Platinum PPO), dental (Guardian PPO), and vision (Beam) for employees and dependents.
- $100,000 fully paid life insurance.
- FSA and Dependent Care FSA.
- One Medical membership (same-day primary care, 24/7 virtual visits).
- Fertility and family-building support through Carrot.
- 401(k) with 2% company match.
- Family & Time Off:
- 16 weeks fully paid parental leave for birthing parents; 10 weeks for non-birthing parents.
- Unlimited PTO with a two-week minimum.
- Closed for all federal holidays and a company-wide winter break the week of Christmas.
- Company offsites throughout the year.
- Office & Remote Setup:
- Up to $750 one-time home office stipend for NYC-based employees; $500 for remote employees.
- $50/month commuter benefit.
- Expensed lunch while in the office.
- Company-provided laptop of your choice.
- Wellness:
- Fully covered gym membership at Grindhouse (NYC) or $100/month fitness reimbursement for remote employees.
- Stipends:
- $100/month utility stipend.
- $500/year professional development.
- $250/year recreation.
- $300/quarter pet care stipend.