Source-listed Job

IT Systems Engineer

About the role

Job Remote Source description available
Thatch Source published Oct 8, 2026 Source retrieved Oct 8, 2026
Source: Thatch Health (greenhouse) · A retrieval date records when our system last obtained the source record. It does not guarantee the vacancy is still open or that every detail has been independently checked.
Description from the source The source description is formatted below for discovery. The provider owns the original wording and may change its requirements or close applications.
Work modeRemote / location-flexible

Overview

About the role

Full job description

About the role At Thatch, technology is how our teams get their work done, securely and without friction. As our IT Ops/Systems Engineer, you'll own the systems and access infrastructure that keeps the company running: endpoint compliance, identity and access management, and the operational backbone behind our security initiatives. This role goes beyond day-to-day support. You'll be the owner of company-wide compliance, conditional access and privileged access workflows in a Mac-first environment, with the autonomy to build the systems and automation that let us scale securely. If you want real ownership over how a fast-growing technology company manages access and identity, this role is for you. What you'll do Own our technology stack including Okta, Iru, Mac, iOS, Android, Rippling MDM/SSO, 1Password, Google Workspace, Microsoft Office, Slack, Zoom, Linear, and Notion Drive endpoint fleet compliance to 100% coverage across MDM, EDR, and DLP, and own remediation when devices fall out of compliance Administer conditional access policies (device trust, managed browser enforcement) and own the exception and escalation process when legitimate access gets blocked Own the Privileged Access Management (PAM) workflow, including replacing manual quarterly access reviews with automated request, approval, and time-bound removal Run trusted device and MFA enrollment, and lead remediation campaigns for weak or breached passwords Own the complete employee lifecycle experience from onboarding through offboarding, managing access control, hardware provisioning, and audit-ready documentation Vet and administer new SaaS tooling for SSO/IdP compliance as part of vendor onboarding, expose and remediate shadow IT Build and maintain a knowledge base that empowers employees to solve common issues independently Identify and build automation for repetitive IT and access-management tasks Partner with the Head of IT and Security to support company-wide initiatives and maintain our security posture Background we're looking for 4-6 years of hands-on IT support or systems engineering experience in a corporate environment, ideally including some ownership of identity/access infrastructure Certification in Network+, Security+, JAMF, Bettercloud, Okta, or comparable credentials Deep understanding of SSO, 2FA, passkeys, conditional access, and password management systems Experience administering or implementing a PAM tool, or a clear grasp of the concepts and willingness to build one from scratch Strong knowledge of security principles and best practices with proven ability to implement them at scale Excellent follow-through and organizational skills. You never let tasks fall through the cracks Experience we’d be particularly excited about Experience driving a fleet from partial to full MDM/EDR/DLP compliance, and building the exception workflow that kept support ticket volume manageable Self-motivated individuals who can work independently with minimal supervision and take ownership of projects from start to finish Quick learners who can master new technologies with minimal guidance Patient communicators with flexible, inclusive interpersonal skills who genuinely enjoy helping others Problem-solvers who are resilient in learning from mistakes and view technical challenges as opportunities People who thrive in fast-paced environments and can adapt quickly to changing priorities What to expect We interview rigorously based on integrity, talent, and drive; the trust we display in our teammates from day 1 is a reflection of the confidence we have in this process. We aim to evaluate the things you’ll be doing every day as best we can, and we move quickly. Here's what to expect: 30 minute video meeting to talk through your background and interest in Thatch 30 minute video meeting with the hiring manager to dive deeper into your experience and the role 30 minute video meeting to meet 4-5 members of the team 30 minute video meeting with department leadership to discuss alignment to our company values and career goals 20-30 minute video meeting with our founders to discuss your approach to culture and our operating principles Estimated Compensation Range $145,000 — $158,000 USD   About Thatch We’re a fully distributed early stage company using technology to change the way America does healthcare. We’re a happy, friendly, high-velocity team. You can read  more on Thatch here .

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.
Original authoritative source

JobOpportunity.info helps you discover and organize source listings. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from Thatch Health (greenhouse) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books