Summary
What you’ll impact
Our organization seeks an experienced IT Manager to own end-to-end information technology and security for a fast-growing, multi-site startup. The sole IT team member will manage day-to-day support, infrastructure, AI tool governance, compliance with defense standards, and develop strategic security roadmaps while advising leadership on IT strategy.
Responsibilities
What you'll do
- Own day-to-day IT support across all offices: hardware, software, accounts, and access. No ask is too small, and you'll build systems so the small asks stay small.
- Run employee onboarding and offboarding end to end: provisioning, deprovisioning, access reviews, and equipment lifecycle.
- Manage laptop fleets and mobile device management (MDM), including configuration baselines, patching, and endpoint security.
- Administer identity and access: SSO via Rippling, Google Workspace, MFA, SCIM provisioning, and role-based access across our SaaS stack.
- Own office IT infrastructure across four sites: networking, Wi-Fi (including RADIUS-authenticated networks), conference rooms and AV, printers, and physical access systems where applicable.
- Manage IT vendors, licensing, and renewals, and keep spend sensible.
- Help shape and administer the company's AI usage policies: which tools are approved, how they're provisioned, and how sensitive data stays out of them.
- Own AI tool spend and seat management, monitoring usage and controlling costs so budget goes where it delivers value.
- Ensure employees are genuinely supported and productive with AI tools while steering usage toward the right tool for the job (not every task needs a frontier model).
- Serve as the company's first line of defense: monitor for and respond to security events, phishing attempts, and incidents, and run the playbooks you'll write.
- Own compliance with CMMC and other defense-related IT standards (e.g., NIST SP 800-171), including gap assessments, remediation plans, evidence collection, and audit readiness.
- Establish and maintain policies and controls for handling sensitive and controlled information, and train employees on them.
- Get in front of strategic security: build the roadmap for where our security program needs to be as the company scales, and drive it, rather than waiting for requirements to arrive.
- Partner with leadership, legal, and engineering on customer and government security requirements, questionnaires, and audits.
- Advise leadership on IT strategy, budget, and build-vs-buy decisions as headcount and office footprint grow.
- Design systems and processes that scale: self-service where it makes sense, automation where it pays off, documentation everywhere.
- Lay the groundwork for a future IT team, and eventually help build it.
Requirements
What you’ll bring
- 6+ years of progressive IT experience, including experience as the sole or founding IT owner at a startup.
- Hands-on depth with MDM platforms (e.g., Jamf, Kandji, Intune) across macOS and Windows fleets.
- Strong experience administering SSO and identity providers and designing sane access models; we run SSO through Rippling on top of Google Workspace, and experience with either (or comparable platforms like Okta or Entra) translates well.
- Experience with automated user lifecycle management, including SCIM provisioning and deprovisioning across SaaS applications.
- Experience deploying and managing RADIUS servers for network authentication (e.g., certificate-based Wi-Fi auth tied to MDM and identity).
- Working knowledge of CMMC, NIST SP 800-171, or comparable defense and government IT compliance frameworks, ideally having taken a company through an assessment or audit.
- Solid grounding in security operations: endpoint protection, email security, incident response, and security awareness.
- Comfort with office networking (firewalls, VLANs, Wi-Fi) across multiple physical sites.
- A service mindset paired with strategic judgment: you take pride in fast, friendly support and in knowing which problems to solve permanently.
- Clear written communication; you document what you build and can explain security tradeoffs to non-technical audiences.
- Willingness to travel roughly 25% of the time between our offices.
- Due to the nature of our work and applicable regulations, this position requires U.S. person status (U.S. citizen or lawful permanent resident).