Systems Administrator

HUGE INC
New York, NY, United States
3 days ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$70,000.0 - $90,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Bash Shell Software as a Service Dynamic Host Configuration Protocol Domainkeys Identified Mail Domain-Based Message Authentication Reporting and Conformance (DMARC) Domain Name System (DNS) Failover Firmware
+32 more
Identity and Access Management Virtual Private Networks (VPN) Internet Service Provider Python (Programming Language) Network Troubleshooting Microsoft Office Networking Basics Network Administration OpenID Security Assertion Markup Language (SAML) Virtual Local Area Networks Wide Area Networks Smartsheet Scripting Google Cloud Okta Microsoft InTune HR Software Sender Policy Framework (SPF) Adobe Script Language Coda Apple Business Manager Casper Suite Figma Gsuite Route53 Claude Google Gemini Interactive Whiteboards Restful APIs Vulnerability Analysis

Job description

Administer identity, Google Workspace, email security, endpoint management, networking, SaaS applications, and cloud IAM for a distributed organization. Serve as the US escalation point for IT Support, manage onboarding and offboarding, conduct access audits, support acquisitions and platform consolidations, automate recurring tasks with scripts and APIs, coordinate security-provider activities, and maintain infrastructure documentation and runbooks. The role owns the New York office network and infrastructure projects end to end., We are hiring an experienced Systems Administrator to join our globally distributed Systems Administration team as its US-based member. You will report to, and work day to day with, the Associate Director, Systems Administration in the UK, and work alongside our Systems Administrator in Colombia and the IT Support team across the Americas.

You will own the day-to-day health of the systems every employee relies on - identity, email security, device management and office networking - act as the escalation point for the Support team during US hours, and carry infrastructure projects from request to completion. This is a generalist role with real depth in identity and email: you will spend more time in Okta, Google Admin and Mimecast than in cloud consoles. What you will be doing.

  • Administer Okta: SAML, OIDC and SCIM application integrations, group rules driven by our HR system, lifecycle and session policies, Okta Workflows, and the troubleshooting that follows an HRprofile change.
  • Administer Google Workspace at admin-API depth: users, organizational units, shared drives, groups and distribution lists, Gmail routing and spam settings, Drive sharing policy, and scripted changes through GAM or the Directory API.
  • Administer email security in Mimecast: impersonation, spam, URL and attachment policies; permitted-sender hygiene; SPF, DKIM and DMARC for our domains.
  • Manage the endpoint fleet with our MDM platforms - Iru (formerly Kandji) for macOS and Kaseya VSA X for Windows - including Apple Business Manager enrollment, patch and compliance policy, and endpoint privilege management (Delinea).
  • Administer our SASE client (Cato) and office networking on Cisco Meraki: SSIDs, VLANs, uplinks and failover, firmware, and coordination with ISPs and facilities. The New York office is yours in person.
  • Act as IT’s operational contact for our security providers (Sophos MDR, eSentire SOC, Tenable vulnerability scanning): alert follow-up, device hygiene and evidence for client security questionnaires with our Risk and Compliance team.
  • Be the escalation point for the IT Support team in the Americas on identity, Google Workspace, MDM and network issues, and turn recurring escalations into documented procedures Support can run.
  • Take part in integration and consolidation projects across acquired companies: Google Workspace tenant and domain moves, mail-flow cutover, mailbox archive imports, Slack and Box consolidation, and device re-enrollment.
  • Run the quarterly access audits with the team: export users from our systems, reconcile against the HR roster and asset inventory (Asset Panda), route removals for approval and keep the evidence trail.
  • Provision and support our SaaS estate through Okta groups and just-in-time provisioning -Adobe, Figma, Box, Miro, Zoom, Smartsheet, Coda and our AI tools (Claude Enterprise, Gemini) - and keep routing and approval notes current.
  • Manage IT’s slice of cloud: Route 53 DNS, a small number of AWS resources, and Google Cloud project administration and IAM grants.
  • Automate recurring work in Python, Bash or Google Apps Script against vendor APIs, under team-owned service identities, with the code kept in our shared repository.
  • Support onboarding and offboarding from the infrastructure side: account activation, group and app assignment, device shipping and returns, and the offboarding checklist across every system.
  • Maintain the team’s knowledge base: runbooks, procedures and vendor contacts, updated as you go.

Requirements

  • 5 or more years in systems administration or a comparable infrastructure role in a distributed, multi-office company. Role is scoped to grow into a Senior position.
  • Deep, hands-on Okta administration beyond SSO: group rules, SCIM provisioning, attribute mappings from an HR source, Workflows, session and authenticator policy. Equivalent depth in Entra ID or OneLogin considered.
  • Google Workspace administration; comfort with GAM or the Admin SDK is a strong plus. Microsoft 365 administration is useful but secondary here.
  • Working knowledge of email authentication and filtering: SPF, DKIM, DMARC, and a secure email gateway such as Mimecast or Proofpoint.
  • Experience with an Apple MDM (Iru/Kandji, Jamf, Mosyle) and a Windows RMM or MDM (Kaseya, Intune).
  • Networking fundamentals - DNS, DHCP, VLANs, VPN, WAN failover - and comfort in a cloud-managed network dashboard such as Meraki.
  • Scripting to remove repetitive work: Python, Bash or Apps Script against REST APIs.
  • Project-level ownership: Creates tasks, executes them end to end, and drives cross-functional projects - acquisition integrations, access audits, platform consolidations - without hand-holding.
  • Working knowledge of at least one cloud IAM model (AWS or Google Cloud).
  • Strong documentation habits and clear written communication with a manager in another time zone.
  • Calm under escalation, self-directed, and comfortable owning a problem end to end.

Benefits & conditions

Workers shall not be required to pay employers’ or agents’ recruitment fees or other related fees for their employment. If any such fees are found to have been paid by workers, such fees shall be repaid to the worker. The salary range for this position is as listed below. Exactly where a prospective employee will be paid within this range will depend on, among other factors, the actual salary ranges for current and former employees who are either currently filling a similar role or did in the past; the candidate’s depth of experience and qualifications; the level of specialization the role requires; budgetary considerations; the market demand for that role and the local market conditions that exist where the employee will be based. For current Huge employees, tenure will also be a consideration. Wage Disclosure $70,000-$90,000 USD

About the company

Huge is an independent, human-first AI-native design and technology company. We make things that matter by bringing AI, people, design and technology together as one system. With more than 1,000 design and technology experts working in hub cities around the world, including Bogotá, Chicago, Ho Chi Minh City, London, Los Angeles, Medellín, New York, San Francisco, and Washington, DC, we partner with some of the world’s most ambitious brands, including Google, NBCU, PepsiCo, Vail Resorts, Atlantic Health, and Candescent. Learn more at hugeinc.com.

Huge is committed to creating an inclusive employee experience for all. Regardless of race, gender, religion, sexual orientation, age, disability, or if you’re parenting the next generation of innovators, we firmly believe that our work is at its best when everyone feels free to be their most authentic self.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

1:17 min

Eco-friendly factory operations and generative AI image errors

Chris Heilmann Chris Heilmann +1 · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

59 sec

Evaluating intrusive system modifications by enterprise software

Chris Heilmann Chris Heilmann +2 · LIVE

1:06 min

Developer experience and project variety at scale

Alexandra Petri · World Congress 2023

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all