Apply Now

Please mention DailyRemote when applying

About the role

We're a remote-first company of ~250 people across 50 countries, and every one of them gets hired, onboarded, and offboarded through systems that need to talk to each other reliably. Today that happens with more human glue than we'd like.

You'll own workforce identity and endpoint security end to end: the architecture, the automation, and the day-to-day. The centrepiece is making our HRIS the single source of truth for identity — when someone is hired, changes role, or leaves, the right access should appear or disappear without a ticket, and we should be able to prove it to an auditor.

This is a hands-on Lead-level IC role. You'll design the model and also build it.

What you'll own

Identity lifecycle and HRIS as source of truth

  • Design and build joiner/mover/leaver automation driven by our HRIS (Workable). This means building the integration — mapping employment events to identity actions via the Workable API, Okta Workflows, and middleware where needed. There is no off-the-shelf connector doing this for us.
  • Own the entitlement model: which groups, roles, and attributes determine access to what, and how role changes propagate.
  • Handle the cases that break naive automation — contractors and EOR workers, future-dated changes, internal transfers, rehires, leaves of absence, and country-specific variations in how employment is recorded.

Access governance

  • Own how access is granted, reviewed, and revoked across our core SaaS estate: Okta, Google Workspace, Slack, Confluence/Jira, Workable, our HRIS, and the long tail of ~20 other apps.
  • Run access reviews and certification campaigns that hold up under SOC 2 and ISO 27001 audit, ideally on a modern IGA platform rather than in spreadsheets.
  • Build self-service request-and-approval flows so access requests stop being Slack DMs.
  • Bring the long tail under management — including the apps with no SCIM support, where you'll need an API, a script, or a documented manual control.

Endpoint and network security

  • Own our device fleet in Jamf (macOS)]: baseline configuration, patch and OS-update compliance, disk encryption, and fleet visibility, working with our external global tech provider and partner (https://www.tequipy.com/)
  • Tie device posture to access — Okta Device Trust or equivalent — so sensitive apps are reachable only from managed, compliant devices.
  • Own secure remote access to internal systems (we are considering Tailscale and Cloudflare Zero Trust), and improve on it. Our people are everywhere; VPN-shaped solutions that assume an office don't fit us.

Security operations and audit

  • Be the identity and endpoint interface for SOC 2 and ISO 27001 — evidence, control design, auditor questions.
  • Instrument the above: alerting on suspicious authentication, MFA changes, privilege escalation, and drift in device compliance.
  • Write the runbooks. Make the offboarding path fast and provable, because that's the control auditors and customers ask about first.

Requirements

What we're looking for

Must have

  • Deep hands-on Okta experience as an administrator and builder — not just console clicks, but Workflows, SCIM, custom attribute mappings, and the debugging that comes with them.
  • You've personally built HRIS-driven joiner/mover/leaver automation, including the parts where the HRIS didn't cooperate.
  • You've run an access-governance program that survived a SOC 2 or ISO 27001 audit.
  • Practical endpoint management experience — Jamf or equivalent — and a view on how device posture should gate access.
  • You explain access decisions in terms of risk and business need, not just tooling, and you can say no to a request without making an enemy.

Nice to have

  • You can write code (w/ Claude Code): Python, Go, or TypeScript at the level of building and maintaining integrations and automation. Comfortable with REST APIs, webhooks, and Terraform or similar for config-as-code.
  • Experience with an IGA platform — Okta Identity Governance, ConductorOne, Lumos, or similar.
  • ZTNA / SASE experience: Tailscale, Tailscale SSH, Netskope, Cloudflare Access, Zscaler.
  • You've done this in a globally distributed, remote-first company, where there's no office network to hide behind and employment models vary by country.
  • Familiarity with the EOR / global employment space, or with the identity implications of a mixed employee-and-contractor workforce.
  • Exposure to customer-facing identity (Auth0, OIDC, SAML) — useful for talking to our product engineers, but not what this role is about.

Probably not the right fit if your background is mainly application security or product/customer identity (CIAM), or if you want an architecture role where someone else does the building.

Benefits

  • Fully remote role
  • Opportunity to work on global-scale systems and products
  • Exposure to international teams and modern engineering practices
  • High ownership and autonomy in a fast-growing startup environment
  • A strong culture grounded in speed, ownership, trust, transparency, customer obsession, and excellence.
  • Real problems, global impact, and the chance to help redefine how the world works.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Systems Engineer

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified