IT Systems Engineer
Austin, Texas, United States·Posted today
cybersecuritysaas
<h3 class="mb-4 text-xl font-extrabold tracking-tight text-gray-900 sm:text-3xl md:text-2xl">About the role</h3> <p class="mt-4">At Thatch, technology is how our teams get their work done, securely and without friction. As our IT Ops/Systems Engineer, you'll own the systems and access infrastructure that keeps the company running: endpoint compliance, identity and access management, and the operational backbone behind our security initiatives. This role goes beyond day-to-day support. You'll be the owner of company-wide compliance, conditional access and privileged access workflows in a Mac-first environment, with the autonomy to build the systems and automation that let us scale securely. If you want real ownership over how a fast-growing technology company manages access and identity, this role is for you.</p> <div class="mt-10"> <h3 class="mb-4 text-xl font-extrabold tracking-tight text-gray-900 sm:text-3xl md:text-2xl">What you'll do</h3> <ul class="ml-4 list-disc"> <li>Own our technology stack including Okta, Iru, Mac, iOS, Android, Rippling MDM/SSO, 1Password, Google Workspace, Microsoft Office, Slack, Zoom, Linear, and Notion</li> <li>Drive endpoint fleet compliance to 100% coverage across MDM, EDR, and DLP, and own remediation when devices fall out of compliance</li> <li>Administer conditional access policies (device trust, managed browser enforcement) and own the exception and escalation process when legitimate access gets blocked</li> <li>Own the Privileged Access Management (PAM) workflow, including replacing manual quarterly access reviews with automated request, approval, and time-bound removal</li> <li>Run trusted device and MFA enrollment, and lead remediation campaigns for weak or breached passwords</li> <li>Own the complete employee lifecycle experience from onboarding through offboarding, managing access control, hardware provisioning, and audit-ready documentation</li> <li>Vet and administer new SaaS tooling for SSO/IdP compliance as part of vendor onboarding, expose and remediate shadow IT</li> <li>Build and maintain a knowledge base that empowers employees to solve common issues independently</li> <li>Identify and build automation for repetitive IT and access-management tasks</li> <li>Partner with the Head of IT and Security to support company-wide initiatives and maintain our security posture</li> </ul> </div> <div class="mt-10"> <h3 class="mb-4 text-xl font-extrabold tracking-tight text-gray-900 sm:text-3xl md:text-2xl">Background we're looking for</h3> <ul class="ml-4 list-disc"> <li>4-6 years of hands-on IT support or systems engineering experience in a corporate environment, ideally including some ownership of identity/access infrastructure</li> <li>Certification in Network+, Security+, JAMF, Bettercloud, Okta, or comparable credentials</li> <li>Deep understanding of SSO, 2FA, passkeys, conditional access, and password management systems</li> <li>Experience administering or implementing a PAM tool, or a clear grasp of the concepts and willingness to build one from scratch</li> <li>Strong knowledge of security principles and best practices with proven ability to implement them at scale</li> <li>Excellent follow-through and organizational skills. You never let tasks fall through the cracks</li> </ul> </div> <div class="mt-10"> <h3 class="mb-4 text-xl font-extrabold tracking-tight text-gray-900 sm:text-3xl md:text-2xl">Experience we’d be particularly excited about</h3> <ul class="ml-4 mt-4 list-disc"> <li>Experience driving a fleet from partial to full MDM/EDR/DLP compliance, and building the exception workflow that kept support ticket volume manageable</li> <li>Self-motivated individuals who can work independently with minimal supervision and take ownership of projects from start to finish</li> <li>Quick learners who can master new technologies with minimal guidance</li> <li>Patient communicators with flexible, inclusive interpersonal skills who genuinely enjoy helping others</li> <li>Problem-solvers who are resilient in learning from mistakes and view technical challenges as opportunities</li> <li>People who thrive in fast-paced environments and can adapt quickly to changing priorities</li> </ul> </div> <div class="mt-10"> <h3 class="mb-4 text-xl font-extrabold text-gray-900 sm:text-3xl md:text-2xl">What to expect</h3> <p class="mt-4">We interview rigorously based on integrity, talent, and drive; the trust we display in our teammates from day 1 is a reflection of the confidence we have in this process. We aim to evaluate the things you’ll be doing every day as best we can, and we move quickly. Here's what to expect:</p> <ul class="ml-8 mt-4 list-disc"> <li>30 minute video meeting to talk through your background and interest in Thatch</li> <li>30 minute video meeting with the hiring manager to dive deeper into your experience and the role</li> <li>30 minute video meeting to meet 4-5 members of the team</li> <li>30 minute video meeting with department leadership to discuss alignment to our company values and career goals</li> <li>20-30 minute video meeting with our founders to discuss your approach to culture and our operating principles</li> </ul> </div><div class="content-pay-transparency"><div class="pay-input"><div class="title">Estimated Compensation Range</div><div class="pay-range"><span>$145,000</span><span class="divider">—</span><span>$158,000 USD</span></div></div></div><div class="content-conclusion"><section class="text-base text-gray-500"> <div class="mt-10 text-base text-gray-500"> </div> </section> <div class="mt-10"> <h3 class="mb-4 text-xl font-extrabold text-gray-900 sm:text-3xl md:text-2xl">About Thatch</h3> <p class="mb-4 text-base text-gray-500">We’re a fully distributed early stage company using technology to change the way America does healthcare. We’re a happy, friendly, high-velocity team. You can read <a class="font-medium text-indigo-600 hover:text-indigo-500" href="https://thatch.ai/company">more on Thatch here</a>.</p> </div></div>