Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Lead IT Systems Engineer

Remofirst
CompanyRemofirst
CategoryUncategorised
LocationRomania
RemoteRemote
EmploymentFull-time
LevelNot stated
SalaryNot stated by the employer
Posted28 Jul 2026
Last verified4 Aug 2026
SourceEmployer ATS (workable)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
About the role We're a remote-first company of ~250 people across 50 countries, and every one of them gets hired, onboarded, and offboarded through systems that need to talk to each other reliably. Today that happens with more human glue than we'd like. You'll own workforce identity and endpoint security end to end: the architecture, the automation, and the day-to-day. The centrepiece is making our HRIS the single source of truth for identity — when someone is hired, changes role, or leaves, the right access should appear or disappear without a ticket, and we should be able to prove it to an auditor. This is a hands-on Lead-level IC role. You'll design the model and also build it. What you'll own Identity lifecycle and HRIS as source of truth Design and build joiner/mover/leaver automation driven by our HRIS (Workable). This means building the integration — mapping employment events to identity actions via the Workable API, Okta Workflows, and middleware where needed. There is no off-the-shelf connector doing this for us. Own the entitlement model: which groups, roles, and attributes determine access to what, and how role changes propagate. Handle the cases that break naive automation — contractors and EOR workers, future-dated changes, internal transfers, rehires, leaves of absence, and country-specific variations in how employment is recorded. Access governance Own how access is granted, reviewed, and revoked across our core SaaS estate: Okta, Google Workspace, Slack, Confluence/Jira, Workable, our HRIS, and the long tail of ~20 other apps. Run access reviews and certification campaigns that hold up under SOC 2 and ISO 27001 audit, ideally on a modern IGA platform rather than in spreadsheets. Build self-service request-and-approval flows so access requests stop being Slack DMs. Bring the long tail under management — including the apps with no SCIM support, where you'll need an API, a script, or a documented manual control. Endpoint and network security Own our device fleet in Jamf (macOS)]: baseline configuration, patch and OS-update compliance, disk encryption, and fleet visibility, working with our external global tech provider and partner ( https://www.tequipy.com/) Tie device posture to access — Okta Device Trust or equivalent — so sensitive apps are reachable only from managed, compliant devices. Own secure remote access to internal systems (we are considering Tailscale and Cloudflare Zero Trust), and improve on it. Our people are everywhere; VPN-shaped solutions that assume an office don't fit us. Security operations and audit Be the identity and endpoint interface for SOC 2 and ISO 27001 — evidence, control design, auditor questions. Instrument the above: alerting on suspicious authentication, MFA changes, privilege escalation, and drift in device compliance. Write the runbooks. Make the offboarding path fast and provable, because that's the control auditors and customers ask about first.