SonicJobs Logo
Left arrow iconBack to search

IT Operations Manager (Contract)

Kaizen Labs
Posted 2 days ago, valid for 20 days
Location

New York, NY, US

Salary

$75 - $110 per hour

Contract type

Full Time

Paid Time Off
Life Insurance
Flexible Spending Account

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Kaizen is seeking a candidate with experience in managing modern identity providers and endpoint management tools to enhance government technology services.
  • The role requires hands-on work in deploying tools, managing devices, and establishing employee lifecycle processes, with a focus on compliance and security.
  • Candidates should have a strong background in cloud-first environments, ideally with experience in Okta, Jamf, or similar tools, and must be comfortable working independently.
  • The position offers a competitive salary, which can vary based on experience, and requires a minimum of 5 years in a related field.
  • Kaizen provides comprehensive benefits, including 100% health coverage, unlimited PTO, and various stipends for home office setup and professional development.

Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services.

Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service.

Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year.

Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back.

The Role

Kaizen builds software for federal and local government. We are roughly 80 people on a cloud-first, mostly macOS stack, and we sell into customers who impose real requirements on how we run our own corporate systems.

IT here is currently distributed across engineers and operators who all have other full-time jobs. It works, in the sense that people can log in. Selling into government means holding a higher bar on identity, devices and access than a side-of-desk model can sustain, so we are building the layer properly. This engagement does that and leaves behind something that runs without you.

Hands-on build work: deploying tools, writing policy, and cleaning up account sprawl rather than advising on it.

What You'd Own

Identity. We are partway through consolidating everything behind a single identity provider and the tail is where the value is: the applications nobody wanted to touch, the provisioning that still happens by hand, and the lifecycle rules that turn it into a system. You would finish it and then own it, including automated provisioning and deprovisioning.

Endpoints. Device management is a program you would stand up rather than one you would inherit. Our government customers set requirements on the devices used for their work, and this role owns meeting those requirements and evidencing them. You would select the tool, deploy it across the fleet, and write the policy that goes with it. This is the largest single deliverable in the engagement.

Employee lifecycle. Joiner, mover, leaver. Today both are documented processes rather than instrumented ones. You would turn them into a system with timing, an audit trail, and named owners, including credential and hardware return. One design constraint: some of our contracts specify tight windows for disabling access when someone departs, so the leaver path has to be built against a clock and produce evidence that it met it.

Access reviews. A recurring review of who has access to what, on a cadence, producing evidence rather than a screenshot. Our auditors and our government customers both ask for this, and you would own the cadence and the trail.

A scoped enclave. Some of our government work involves controlled information with handling requirements that do not apply to the rest of the business. You would stand up a separate, deliberately narrow environment for it, with its own identity, managed devices, controlled storage and a documented boundary, then write the runbook that keeps the scope from drifting. Keeping that boundary narrow over time is harder than building it.

The SaaS estate. Inventory, owners, renewal dates, who has admin, and what data sits where. Right now that knowledge is in people's heads.

Deliverables

What we expect to have in hand at each stage.

Weeks 1 to 4

  • A complete inventory of devices, applications, and accounts, each mapped to a named human and reconciled against current employment status

  • The identity provider rollout finished across the remaining applications, with the queued work closed out

  • A written joiner, mover and leaver process with the revocation step timed and evidenced

Weeks 5 to 12

  • Endpoint management selected, purchased and deployed across the fleet, with a device and acceptable-use policy that lets us evidence the software restrictions our contracts carry

  • A quarterly access review established, in a format an assessor will accept

  • Offboarding automated end to end, including credential and physical asset return with written confirmation

  • SaaS estate rationalized: inventory, owner, renewal date, admin list, and data posture for each

Months 3 to 6

  • Privileged access separated from standard access and documented

  • Identity and access evidence flowing to our compliance program on a schedule

  • The scoped enclave stood up and documented, with a defined user list and a boundary that holds

  • Readiness for certificate and smart-card based authentication, which some of our government work will require

  • Runbooks good enough that the program survives the end of this engagement

What You'll Bring

  • You have owned a modern identity provider, Okta, Entra or JumpCloud, as the administrator rather than a user. App onboarding, SCIM provisioning, lifecycle rules, and the unglamorous work of chasing down the last twelve applications

  • You have deployed endpoint management from zero across a real fleet. Jamf, Kandji, Hexnode or Intune. You know what breaks when you do this to people who have never had a managed device, and you have a plan for that conversation

  • You have paired endpoint management with an EDR tool and can speak to both halves. CrowdStrike, Huntress or similar

  • You have built a joiner, mover and leaver process that produced an audit trail, not a checklist someone remembers to open

  • You have run an access review that an auditor accepted. You know the difference between a spreadsheet and evidence

  • You are fluent in a cloud-first, mostly macOS environment: Google Workspace, a password manager, AWS console access, SSO everywhere

  • You write runbooks other people can follow. This engagement is judged partly on what still works after it ends

  • You are comfortable as the only IT person, with an engineering team who will help you but does not report to you

  • US person

Strong Candidates May Also

  • Have taken a company through SOC 2, FedRAMP or CMMC on the IT side and know exactly which access and device artifacts the assessor asks for. This is the single most valuable thing on this list and it moves our rate

  • Know certificate and smart-card authentication, PIV or CAC, and government PKI

  • Have handled device, software or account restrictions that flowed down from a government contract

  • Have come out of a managed service provider and want to build in-house instead of firefighting across twenty clients

  • Have done exactly this as a contract engagement before and can describe what made it work or fail

Scope of Work

Product engineering and our government hosting environments stay with employees. You would own corporate identity and corporate devices, not the production or federal environments. Security architecture decisions sit with our engineering lead; you would implement and operate.

Don't Apply If...

  • Your background is ticket triage and password resets. This engagement designs and builds systems, and there is no queue to work

  • You need an established stack and a documented environment to step into. Neither exists yet, and building them is the job

  • Your experience is Windows and on-premise Active Directory. It does not transfer cleanly to where we are

  • You want a retainer to advise. We need someone who buys the tool and deploys it

  • You would rather grow a team than do the work yourself. There is no team, and there will not be one during this engagement

What Kaizen Offers

Health & Insurance

  • 100% coverage across the board: medical through Oxford/United (Gold and Platinum PPO plans), dental through Guardian PPO, and vision through Beam — all fully covered for employees, with 100% coverage for dependents.

  • $100,000 in fully paid life insurance. FSA and Dependent Care FSA.

  • One Medical membership, on us — same-day primary care, 24/7 virtual visits, and offices all over the city.

  • Fertility and family-building support through Carrot.

  • 401(k) through Guideline, with a 2% company match.

Family & Time Off

  • 16 weeks of fully paid parental leave for birthing parents. 10 weeks fully paid for non-birthing parents.

  • Unlimited PTO, with a two-week minimum (we mean it when we say take time off!)

  • Closed for all federal holidays.

  • Company-wide winter break the week of Christmas.

  • Company offsites throughout the year.

Office & Remote Setup

  • Up to $750 one-time home office or desk setup stipend for NYC-based employees. $500 for remote employees.

  • $50/month commuter benefit (company contribution).

  • Expensed lunch while in the office.

  • Company-provided laptop of your choice.

Wellness

  • Fully covered gym membership at Grindhouse — right across the street from our office at 47 W 17th St (and in Williamsburg). A $225/month value, on us. For remote employees, $100/month dedicated to gym or physical fitness reimbursement.

Stipends

  • $100/month utility stipend.

  • $500/year professional development.

  • $250/year recreation.

  • $300/quarter pet care stipend.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.