Lead IT Systems Engineer
Remofirst
| Company | Remofirst |
| Category | Uncategorised |
| Location | Portugal |
| Remote | Remote |
| Employment | Full-time |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 5 Aug 2026 |
| Source | Employer ATS (workable) |
Description
About the role We're a remote-first company of ~250 people across 50 countries, and every one of them gets hired, onboarded, and offboarded through systems that need to talk to each other reliably. Today that happens with more human glue than we'd like. You'll own workforce identity and endpoint security end to end: the architecture, the automation, and the day-to-day. The centrepiece is making our HRIS the single source of truth for identity — when someone is hired, changes role, or leaves, the right access should appear or disappear without a ticket, and we should be able to prove it to an auditor. This is a hands-on Lead-level IC role. You'll design the model and also build it. What you'll own Identity lifecycle and HRIS as source of truth Design and build joiner/mover/leaver automation driven by our HRIS (Workable). This means building the integration — mapping employment events to identity actions via the Workable API, Okta Workflows, and middleware where needed. There is no off-the-shelf connector doing this for us. Own the entitlement model: which groups, roles, and attributes determine access to what, and how role changes propagate. Handle the cases that break naive automation — contractors and EOR workers, future-dated changes, internal transfers, rehires, leaves of absence, and country-specific variations in how employment is recorded. Access governance Own how access is granted, reviewed, and revoked across our core SaaS estate: Okta, Google Workspace, Slack, Confluence/Jira, Workable, our HRIS, and the long tail of ~20 other apps. Run access reviews and certification campaigns that hold up under SOC 2 and ISO 27001 audit, ideally on a modern IGA platform rather than in spreadsheets. Build self-service request-and-approval flows so access requests stop being Slack DMs. Bring the long tail under management — including the apps with no SCIM support, where you'll need an API, a script, or a documented manual control. Endpoint and network security Own our device fleet in Jamf (macOS)]: baseline configuration, patch and OS-update compliance, disk encryption, and fleet visibility, working with our external global tech provider and partner ( https://www.tequipy.com/) Tie device posture to access — Okta Device Trust or equivalent — so sensitive apps are reachable only from managed, compliant devices. Own secure remote access to internal systems (we are considering Tailscale and Cloudflare Zero Trust), and improve on it. Our people are everywhere; VPN-shaped solutions that assume an office don't fit us. Security operations and audit Be the identity and endpoint interface for SOC 2 and ISO 27001 — evidence, control design, auditor questions. Instrument the above: alerting on suspicious authentication, MFA changes, privilege escalation, and drift in device compliance. Write the runbooks. Make the offboarding path fast and provable, because that's the control auditors and customers ask about first.