GENERAL DESCRIPTION:
The Senior IT Systems Analyst owns the internal technology that Stratus itself runs on — users and their access, the computers they work on, the SaaS application estate, and the automation that connects them. Reporting to the Director of Technical Support with a dotted line to the Senior Director, Platform Engineering, this is the senior technical owner of corporate IT at a ~50-person, primarily remote, Series B software company growing quickly.
This is a systems role rather than a queue role. Much of the work is designing the lifecycle, integration, and automation that reduce ticket volume at the source: building an automated onboarding and offboarding process that provisions and revokes users, access, and computers reliably, connecting our systems so data flows between them, replacing recurring manual tasks with automation, and keeping the corporate IT controls our SOC 2 and NIST 800-171 compliance depends on continuously in place.
The load-bearing problems on your plate are: (1) automating the full user lifecycle — onboarding, role changes, and offboarding — across our identity provider, SaaS estate, and HRIS, with clean provisioning, deprovisioning, and access review; (2) owning management, patching, and security of every Windows PC and Mac across a distributed workforce through our MDM, from setup through retirement; (3) maintaining SOC 2 and NIST 800-171 compliance for corporate IT, so controls stay passing and evidence is ready when auditors ask; and (4) automating the recurring manual work — account creation, license reconciliation, certificate and renewal tracking, onboarding setup — so it runs on a reliable schedule.
You will work closely with engineering, security, People Operations, and every business function that depends on a tool you administer. The right candidate is genuinely technical, automates by instinct, documents as they go, and is comfortable being the person who owns internal IT end to end rather than one queue within it.
KEY RESPONSIBILITIES:
- Own user and identity management across the company: user accounts, directory and SSO administration, group and role design, multi-factor enforcement, conditional access, and privileged access management.
- Design, automate, and run onboarding and offboarding end to end — account creation, access provisioning, computer setup and shipping on day one; complete access revocation, device recovery, and data handling on the last day — integrated with our HRIS, with auditable confirmation of every access change.
- Administer and integrate the SaaS application estate, including Microsoft 365 and Teams, Atlassian (Jira and Confluence), and our support and GTM platforms; own SSO configuration, license management, and cost reconciliation across it.
- Own email security and deliverability, including email authentication (SPF, DKIM, DMARC).
- Own management of every Windows PC and Mac across a distributed fleet through our MDM: procurement, zero-touch enrollment and automated provisioning, configuration profiles and compliance policy, OS and application patching, endpoint security coverage, disk encryption (BitLocker and FileVault), remote lock and wipe, asset inventory, and secure retirement.
- Build automation for recurring IT work using workflow platforms (n8n, Power Automate) and scripting (PowerShell, Python, or comparable) — account and license workflows, onboarding and offboarding tasks, device provisioning and compliance checks, renewal and certificate expiry monitoring, and integrations between systems that lack native connectors.
- Maintain SOC 2 and NIST 800-171 compliance for corporate IT: own the IT controls for users, access, and computers, keep them continuously passing in our compliance platform, remediate drift, execute periodic access reviews, and produce the access, asset, and configuration evidence auditors require.
- Own the company password manager and how people share credentials safely: who can see which shared logins, rotating shared passwords when people leave or change roles, and keeping passwords and keys out of chat and email. Production application secrets stay with Platform Engineering.
- Maintain the internal IT knowledge base and runbooks so that common requests are self-service and well documented.
- Serve as the escalation point for complex internal technical issues, partnering with the platform engineering team where corporate IT and production infrastructure meet.
- Evaluate and recommend new internal tooling, including consolidation opportunities, with a clear view of cost, security posture, and administrative burden.
QUALIFICATIONS:
- 6+ years of progressive IT experience, with at least 2+ years as a senior, lead, or sole technical owner of corporate IT or internal systems.
- Deep hands-on administration of Microsoft 365 and Entra ID / Azure AD or comparable, including user management, SSO and SAML/OIDC integration, conditional access, device policy, and privileged access.
- Demonstrated ownership of onboarding and offboarding automation — you have built provisioning and deprovisioning that works, not just followed a checklist.
- Real scripting and automation ability: PowerShell, Python, or comparable, plus workflow automation platforms (n8n, Power Automate, Zapier, or similar). You have replaced manual processes with code.
- Hands-on MDM administration of both Windows PCs and Macs at fleet scale (Intune, Jamf, Kandji, or comparable), including zero-touch enrollment (Windows Autopilot, Apple Business Manager / Automated Device Enrollment), configuration profiles and compliance policy, patch management, and endpoint security tooling.
- Experience administering a multi-tool SaaS estate, including SSO rollout, license optimization, and vendor management.
- Hands-on experience maintaining compliance with SOC 2, NIST 800-171, ISO 27001, or similar frameworks — owning controls day to day, not just preparing for the audit, and knowing what auditors ask for and how to produce it.
- Working knowledge of IT security fundamentals, including TLS and certificate management and email authentication (SPF, DKIM, DMARC).
- Fluency with AI-assisted tooling and a track record of using it to automate operational work — this is a graded expectation at every level at Stratus.
- Excellent documentation and written communication, and the ability to explain technical constraints clearly to non-technical colleagues.
- Self-sufficiency and strong judgment — this role sets its own priorities against stated goals in a company where the IT function is lean and the scope is broad.
NICE TO HAVE:
- Experience at a software company where internal IT interfaces with a production engineering organization, and comfort navigating that boundary.
- Experience with Rippling or a comparable HRIS as the system of record for access provisioning.
- Experience with compliance automation platforms (Vanta, Drata, or comparable).
- Experience administering a company-wide password manager (Keeper, 1Password, or comparable).
- Experience with Windows software distribution and package management (WinGet, Intune app deployment, or comparable).
- Experience supporting engineering workstations, CAD workstations, or other high-specification hardware.
- Experience executing a domain or tenant migration.
- Relevant certifications (Microsoft 365 / Azure administration, CompTIA, security certifications).
- Prior experience in a growth-stage company where the function was being built rather than inherited.
BENEFITS:
- Comprehensive and competitive health benefits plan
- Matching 401k contributions
- Primarily remote work with occasional annual team onsites.
E-VERIFY STATEMENT
Stratus participates in E-Verify. After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only - we never use E-Verify to pre-screen applicants.
E-Verify Notice
Right to Work Notice