{"schemaVersion":"jobsearcher.job.v1","id":"03e6baf23154902037fa1466","url":"https://jobsearcher.com/jobs/03e6baf23154902037fa1466","canonicalUrl":"https://jobsearcher.com/jobs/03e6baf23154902037fa1466","title":"IT Operations Engineer","description":"AgentSync started in 2018 with one conviction: compliance shouldn't be this hard. It should enable it. We're a venture backed category-defining SaaS company headquartered in Denver. We've raised $161 million from investors including Craft Ventures, Valor Equity Partners, and Marc Benioff.\n\nOur culture runs on four values: customer love, inspire excellence, always be curious, and act like an owner. That means no ego, no politics, and real ownership over your work. If you want to build something that matters for an industry that's ready for change, we'd love to talk.\n\nOverview\n\nAs an IT Operations Engineer, you will own the identity, endpoint, and SaaS infrastructure that every AgentSync employee depends on to do their best work. You will help scale our IT Operations practice in a fast-moving startup environment — replacing manual, ticket-driven work with automation, standing up durable access and device management foundations, and defining the metrics that tell us whether IT is healthy. You’ll take projects from loose problem statements to production, partner closely with Engineering, Security, and the business, and set the standard for what great internal support looks like.\n\nWhat You’ll Do\nOwn and mature our identity provider (Okta) — SSO/SAML/OIDC integrations, SCIM provisioning, lifecycle management, and least-privilege RBAC across our SaaS estate\nBuild the IAM and RBAC foundations that let us grow: consistent access models, automated joiner/mover/leaver workflows, and access reviews that hold up under audit\nDesign and scale our macOS endpoint program in JAMF — zero-touch provisioning, patching, configuration profiles, and compliance baselines — with a clear roadmap toward MDM maturity\nAutomate manual IT workflows with scripting and integrations so that onboarding, offboarding, and access requests are repeatable rather than tribal knowledge\nDefine and report the KPIs that measure IT Operations effectiveness — response and resolution times, provisioning cycle time, patch and MDM compliance, and license utilization — and use them to drive investment decisions\nLead IT projects end to end with loose or evolving requirements: frame the problem, plan the phases, sequence the work, communicate timelines, and deliver\nPrioritize a heavy queue of competing requests and incidents without losing the thread on long-term project work\nPartner with Security and Compliance to support SOC 2 evidence collection, access reviews, and audit readiness\nTroubleshoot escalated issues across identity, networking, endpoints, and SaaS applications — including the ones nobody has documented yet\nSupport employees with genuine customer love, managing frustration with patience while getting to the real fix and preventing the repeat\nAdminister and improve our ticketing and collaboration platforms so requests are routed, tracked, and measured rather than lost in DMs\nRegularly bridge the gap between IT and Engineering, Security, and business teams as a champion of cross-team collaboration\nProvision and manage employee hardware\nParticipate in helping to build and maintain a culture of IT and engineering best practices\nWhat You’ll Bring\nSignificant hands-on experience in IT Operations or IT Engineering, ideally at a startup or other high-growth, fast-changing environment\nDeep experience administering an identity provider and access permissions at scale (Okta strongly preferred), including SAML, SSO, OIDC, and automated provisioning\nStrong macOS fleet management experience with an MDM (Jamf preferred), and a clear point of view on what a mature MDM solution looks like and how to get there\nWorking knowledge of AWS, including cloud identity and access management\nSolid Linux fundamentals and networking knowledge — comfortable reasoning through the OSI model when troubleshooting\nScripting and automation experience (Python, Bash) paired with an automation-first mindset\nFamiliarity with security and compliance frameworks (SOC 2) and how IT controls support them\nExperience administering ticketing and collaboration platforms and improving the workflows that run on them\nA track record of leading projects without being handed direction, and of executing from scratch in ambiguous situations\nExperience mentoring, leading, or otherwise growing the people around you\nThe desire to work on a collaborative, learning oriented team\nStrong verbal and written communication skills, with the ability to explain identity, access, and endpoint concepts to non-technical audiences\nA scrappy, roll-up-your-sleeves mentality — you thrive with ambiguity and ownership\n\nLocation\nOur ideal candidate will live within 25 miles of our office in Denver. Other states we're able to consider candidates in CA, CO, CT, GA, IL, IN, KS, MA, MD, MI, MN, MO, NC, NY, OR, TN, TX, UT, and WA. We are not hiring or able to consider candidates in New York metro, Seattle metro, or Bay Area.\n\nTotal Compensation\n\nThe following represents AgentSync’s reasonable estimate of the range of possible compensation for this role.\n\n $100K-$115K base salary\n\n Annual company bonus program\n\n⚖️ Equity in the form of stock options\n\nHealth Benefits\n\n Medical - Multiple Cigna plans to choose from, with up to 80% employer paid premiums for you and your dependents\n\n Dental - Multiple Cigna plans with up to 80% employer paid premiums for you and your dependents\n\n️ Vision - 80% paid premium plan for you and your dependents\n\n Employee Assistance Plan, Life & AD&D Insurance\n\nFinancial Benefits\n\n 401(k) retirement savings plan\n\n HSA employer contributions\n\nOther Benefits\n\n Flexible PTO\n\n 12 paid holidays per year\n\n 12 weeks parental leave w/generous return to work stipend\n\nCandidates: AgentSync Recruiting & Talent teams will only communicate with you using @agentsync.io email addresses. When you receive communication from AgentSync, check the email address domain to ensure you're connected with our team (and not a scammer!).\n\nWe are not able to consider candidates who require a work visa now or in the future.\n\nE-Verify: AgentSync participates in the federal E-Verify program. As required, we will verify the identity and employment eligibility of all newly hired employees through E-Verify.","company":"Agentsync","rawCompany":"agentsync","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-19T12:53:12.205Z","occupations":[{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"11-3021.00","title":"Computer and Information Systems Managers","slug":"computer-and-information-systems-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"IT Operations Engineer","description":"AgentSync started in 2018 with one conviction: compliance shouldn't be this hard. It should enable it. We're a venture backed category-defining SaaS company headquartered in Denver. We've raised $161 million from investors including Craft Ventures, Valor Equity Partners, and Marc Benioff.\n\nOur culture runs on four values: customer love, inspire excellence, always be curious, and act like an owner. That means no ego, no politics, and real ownership over your work. If you want to build something that matters for an industry that's ready for change, we'd love to talk.\n\nOverview\n\nAs an IT Operations Engineer, you will own the identity, endpoint, and SaaS infrastructure that every AgentSync employee depends on to do their best work. You will help scale our IT Operations practice in a fast-moving startup environment — replacing manual, ticket-driven work with automation, standing up durable access and device management foundations, and defining the metrics that tell us whether IT is healthy. You’ll take projects from loose problem statements to production, partner closely with Engineering, Security, and the business, and set the standard for what great internal support looks like.\n\nWhat You’ll Do\nOwn and mature our identity provider (Okta) — SSO/SAML/OIDC integrations, SCIM provisioning, lifecycle management, and least-privilege RBAC across our SaaS estate\nBuild the IAM and RBAC foundations that let us grow: consistent access models, automated joiner/mover/leaver workflows, and access reviews that hold up under audit\nDesign and scale our macOS endpoint program in JAMF — zero-touch provisioning, patching, configuration profiles, and compliance baselines — with a clear roadmap toward MDM maturity\nAutomate manual IT workflows with scripting and integrations so that onboarding, offboarding, and access requests are repeatable rather than tribal knowledge\nDefine and report the KPIs that measure IT Operations effectiveness — response and resolution times, provisioning cycle time, patch and MDM compliance, and license utilization — and use them to drive investment decisions\nLead IT projects end to end with loose or evolving requirements: frame the problem, plan the phases, sequence the work, communicate timelines, and deliver\nPrioritize a heavy queue of competing requests and incidents without losing the thread on long-term project work\nPartner with Security and Compliance to support SOC 2 evidence collection, access reviews, and audit readiness\nTroubleshoot escalated issues across identity, networking, endpoints, and SaaS applications — including the ones nobody has documented yet\nSupport employees with genuine customer love, managing frustration with patience while getting to the real fix and preventing the repeat\nAdminister and improve our ticketing and collaboration platforms so requests are routed, tracked, and measured rather than lost in DMs\nRegularly bridge the gap between IT and Engineering, Security, and business teams as a champion of cross-team collaboration\nProvision and manage employee hardware\nParticipate in helping to build and maintain a culture of IT and engineering best practices\nWhat You’ll Bring\nSignificant hands-on experience in IT Operations or IT Engineering, ideally at a startup or other high-growth, fast-changing environment\nDeep experience administering an identity provider and access permissions at scale (Okta strongly preferred), including SAML, SSO, OIDC, and automated provisioning\nStrong macOS fleet management experience with an MDM (Jamf preferred), and a clear point of view on what a mature MDM solution looks like and how to get there\nWorking knowledge of AWS, including cloud identity and access management\nSolid Linux fundamentals and networking knowledge — comfortable reasoning through the OSI model when troubleshooting\nScripting and automation experience (Python, Bash) paired with an automation-first mindset\nFamiliarity with security and compliance frameworks (SOC 2) and how IT controls support them\nExperience administering ticketing and collaboration platforms and improving the workflows that run on them\nA track record of leading projects without being handed direction, and of executing from scratch in ambiguous situations\nExperience mentoring, leading, or otherwise growing the people around you\nThe desire to work on a collaborative, learning oriented team\nStrong verbal and written communication skills, with the ability to explain identity, access, and endpoint concepts to non-technical audiences\nA scrappy, roll-up-your-sleeves mentality — you thrive with ambiguity and ownership\n\nLocation\nOur ideal candidate will live within 25 miles of our office in Denver. Other states we're able to consider candidates in CA, CO, CT, GA, IL, IN, KS, MA, MD, MI, MN, MO, NC, NY, OR, TN, TX, UT, and WA. We are not hiring or able to consider candidates in New York metro, Seattle metro, or Bay Area.\n\nTotal Compensation\n\nThe following represents AgentSync’s reasonable estimate of the range of possible compensation for this role.\n\n $100K-$115K base salary\n\n Annual company bonus program\n\n⚖️ Equity in the form of stock options\n\nHealth Benefits\n\n Medical - Multiple Cigna plans to choose from, with up to 80% employer paid premiums for you and your dependents\n\n Dental - Multiple Cigna plans with up to 80% employer paid premiums for you and your dependents\n\n️ Vision - 80% paid premium plan for you and your dependents\n\n Employee Assistance Plan, Life & AD&D Insurance\n\nFinancial Benefits\n\n 401(k) retirement savings plan\n\n HSA employer contributions\n\nOther Benefits\n\n Flexible PTO\n\n 12 paid holidays per year\n\n 12 weeks parental leave w/generous return to work stipend\n\nCandidates: AgentSync Recruiting & Talent teams will only communicate with you using @agentsync.io email addresses. When you receive communication from AgentSync, check the email address domain to ensure you're connected with our team (and not a scammer!).\n\nWe are not able to consider candidates who require a work visa now or in the future.\n\nE-Verify: AgentSync participates in the federal E-Verify program. As required, we will verify the identity and employment eligibility of all newly hired employees through E-Verify.","datePosted":"2026-08-19T12:53:12.205Z","dateModified":"2026-08-19T12:53:12.205Z","hiringOrganization":{"@type":"Organization","name":"Agentsync","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"03e6baf23154902037fa1466"},"url":"https://jobsearcher.com/jobs/03e6baf23154902037fa1466"}}