Stratus Logo

Stratus

IT Systems Administrator

Posted 2 Hours Ago
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
Own Stratus’s internal IT environment, including Microsoft Entra ID, Microsoft 365, identity access, SaaS applications, endpoint management, hardware assets, onboarding and offboarding, employee support, and compliance controls. Automate provisioning, license reconciliation, access reviews, and audit evidence collection using scripting and AI tools. Administer security, VPN, password management, documentation, and SOC 2/NIST-related processes while supporting a distributed workforce.
The summary above was generated by AI

Stratus, deriving from the Latin term meaning 'layer', offers an advanced set of MEPspecific solutions that seamlessly layer across a contractor's entire workflow from design to fabrication to installation. Our team of seasoned industry experts, skilled technology leaders, innovators, and entrepreneurs understands that fabrication does not occur in isolation, and increasingly, it may not happen within your own fabrication shop. Through close relationships with our customers — who include some of the most innovative and largest MEP contractors — we have developed a suite of Stratus tools to digitize, automate, and optimize piping, plumbing, sheet metal, and electrical contracting. Stratus provides the software layer an MEP contractor needs to optimize profits with true "Data-Driven Contracting."

General Description 

The IT Systems Administrator will own the internal technology estate at Stratus and report to the Senior Director, Platform Engineering. The headline outcome of this role is a company where every new hire is fully productive on day one and fully deprovisioned the day they leave — with the identity, endpoint, and SaaS systems behind that managed as repeatable process rather than tribal knowledge. You will run our Microsoft Entra ID and Microsoft 365 environment, our Rippling-managed device fleet, and the SaaS applications the company depends on, and you will steadily convert the manual work in each of those into automation. This role sits on the Platform Engineering team rather than in a standalone IT function, which means you will have platform engineers to learn from, real tooling to work with, and an expectation that you automate your way out of recurring toil instead of absorbing it. You should be pragmatic and service-oriented, comfortable being the person the whole company relies on for access and equipment, and genuinely interested in using AI tooling to do that job better than it has been done before. 

Key Responsibilities 

Identity and Access 

  • Administer the Microsoft Entra ID workforce tenant and Microsoft 365 environment — users, groups, licensing, conditional access, and MFA policy. 
  • Own SSO and SAML/OIDC application integrations across our federated SaaS estate (GitHub Enterprise Cloud, Salesforce, MongoDB Atlas, HubSpot, Keeper, OpenVPN, Autodesk, and roughly a dozen more), including onboarding new applications to SSO as the company adopts them. 
  • Run periodic user access reviews and least-privilege cleanup, and produce the evidence that those reviews happened. 
  • Support identity and directory initiatives as the environment evolves — domain changes, directory migrations, and platform consolidation. 

Endpoint and Asset Management 

  • Manage the device fleet through Rippling — enrollment, configuration and compliance policy, patching, and encryption baselines across the company’s laptops and mobile devices. 
  • Own hardware asset inventory and lifecycle: procurement, imaging, shipping to remote employees, refresh, and secure retirement. 
  • Maintain an accurate, current inventory of devices, software, and SaaS licenses — and keep it accurate without a quarterly fire drill. 

Onboarding, Offboarding, and Support 

  • Own the end-to-end onboarding and offboarding process. Rippling is our system of record for people, devices, and assets — drive that toward same-day provisioning and same-day deprovisioning with no manual steps. 
  • Serve as the escalation point for employee IT requests — accounts, access, devices, connectivity, conferencing, and the everyday problems that block people from working. 
  • Administer SaaS applications company-wide: provisioning, deprovisioning, license reconciliation, and vendor/renewal coordination. 

Automation and AI-Assisted Operations 

  • Automate recurring IT work rather than repeating it — scripted provisioning, license reconciliation, access reporting, and compliance evidence collection. 
  • Use AI tooling (we use Claude Code and Cursor) as a daily part of the job, and write internal runbooks in a form that both a human and an agent can execute. 
  • Contribute to company-wide AI tooling operations: seat and license management, access provisioning, and helping the rest of the company adopt the tools effectively. 

Security and Compliance 

  • Support our SOC 2 and NIST 800-171 audits end to end — gather and produce evidence, respond to auditor requests, track remediation items to closure, and own the IT-side controls outright: access control, account lifecycle, asset inventory, MFA enforcement, and device compliance. 
  • Administer Vanta, our compliance platform, and keep its integrations wired into identity, device, and ticketing systems so evidence collection runs continuously in the background instead of becoming a quarterly scramble ahead of each audit window. 
  • Own the employee-facing compliance obligations that audits actually fail on — security awareness training completion, policy acknowledgement and e-signature tracking, and access review attestations — and make them a tracked part of onboarding rather than a fire drill. 
  • Help maintain IT and security policy documentation so what we have written down matches what we actually do. 
  • Administer our password and secrets management platform (Keeper) and enforce good credential hygiene across the company. 
  • Support internal network and remote access infrastructure, including our SAML-integrated VPN. 

Documentation 

  • Create and maintain clear runbooks, internal knowledge base articles, and self-service documentation. Documentation is a deliverable here, not an afterthought — if only you know how something works, the job is not finished. 

Qualifications 

  • 3-5 years of hands-on IT systems administration experience supporting a distributed workforce. A degree is welcome but experience is what we are evaluating. 
  • Demonstrated production experience administering Microsoft Entra ID (Azure AD) and Microsoft 365 — this is our environment and it is a hard requirement. 
  • Hands-on experience with MDM / endpoint management at company scale — enrollment, compliance policy, and configuration baselines. We run Rippling; equivalent experience in Jamf, Kandji, or a comparable platform transfers. 
  • Practical experience configuring SSO/SAML application integrations and troubleshooting federation failures. 
  • Experience owning employee onboarding and offboarding, including access provisioning and deprovisioning. 
  • Scripting ability sufficient to automate real work — PowerShell, Bash, or Python. We are not looking for a software engineer, but we are looking for someone who reaches for a script before a checklist. 
  • Experience supporting a security audit or compliance program — collecting evidence, responding to auditor requests, and keeping control documentation current. You do not need to be a compliance specialist, but audit season should not be new to you. 
  • Strong written communication and technical writing skills; demonstrated ability to produce documentation other people actually use. 
  • Genuine enthusiasm for using AI tooling in operations work, and the aptitude to pick it up quickly. Prior experience is a plus, not a requirement — we will teach you how we use it. 
  • Service orientation and sound judgment about urgency. You will be the person the company depends on when something blocks their work. 

Preferred Qualifications 

  • Google Workspace administration experience. 
  • Direct experience administering Rippling, or another HRIS used as the provisioning source of truth (Workday, BambooHR, or similar). 
  • Direct experience with SOC 2 or NIST 800-171 (or adjacent frameworks — NIST 800-53, CMMC, ISO 27001), and with compliance automation platforms such as Vanta, Drata, or Apptega. 
  • Experience with infrastructure as code (Terraform/OpenTofu) or configuration management for internal-facing systems. 
  • Familiarity with GitHub and GitHub Actions, including organization and access administration. 
  • Experience administering a password manager or secrets platform at company scale. 
  • Exposure to Azure, Kubernetes, or a platform engineering environment. 
  • Prior experience building internal automations, integrations, or agents. 
  • Background in construction, MEP, manufacturing, or another non-software-native industry. 

Benefits

  • Comprehensive and competitive health benefits plan
  • Matching 401k contributions
  • 20 days annual PTO
  • Primarily remote work with occasional annual team onsites.


E-VERIFY STATEMENT 
Stratus participates in E-Verify. After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only - we never use E-Verify to pre-screen applicants. 
E-Verify Notice 
Right to Work Notice 


Similar Jobs

4 Days Ago
Remote
US
95K-110K Annually
Mid level
95K-110K Annually
Mid level
Automotive
Administer and support the Enrich fleet maintenance platform across configuration, user access, data quality, interfaces, troubleshooting, testing, releases, documentation, and training. Provide Tier 1 and Tier 2 support for related fleet systems, investigate issues across application and data layers, monitor integrations, reconcile records, and coordinate with business, IT, and vendor teams. Support process improvements, reporting, audit readiness, and critical incidents or deployments outside standard hours when necessary.
Top Skills: Amerit HubDomoEnrichExcelJIRAPeoplesoftPower BIServicenowSQLSsrsTrimble Tmt/Tmw Fleet MaintenanceZendesk
11 Days Ago
Remote
USA
Mid level
Mid level
Information Technology • Professional Services • Security • Defense
Owns the lifecycle, security, and administration of company devices, Mac MDM, user accounts, endpoint controls, networks, servers, backups, logging, and vulnerability remediation. Supports field deployments and customer-site infrastructure, maintains IT policies and documentation, coordinates shared services with parent-company IT, evaluates new tools, and communicates project risks and tradeoffs to leadership.
Top Skills: Apple MdmCentralized LoggingDisk EncryptionEndpoint Protection/EdrFirewallsGoogle WorkspaceIamJAMFKandjimacOSMfaMicrosoft IntuneMosylePatch ManagementSIEMSwitchesVpn
19 Days Ago
Remote
US
Senior level
Senior level
Digital Media • Edtech
Administer Epic’s corporate identity, access, endpoints, applications, devices, and employee IT support. Manage onboarding and offboarding, access reviews, authentication and device standards, MDM provisioning, asset inventories, procedures, and audit evidence. Support SOC 2 or similar compliance activities, security reviews, and incident response while partnering with infrastructure and people operations. This is a fully remote, US-based role supporting a global engineering team.
Top Skills: BashCertalignCoppaDrataEndpoint ManagementFerpaGdprGoogle WorkspaceIdentity And Access Management (Iam)Iso 27001JAMFKandjiLumosmacOSMicrosoft IntuneMobile Device Management (Mdm)Multi-Factor Authentication (Mfa)PowershellPythonSailpointSAMLScimSingle Sign-On (Sso)Soc 2Vanta

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account