MTS - IT Engineer
Summary
Onsite IT Engineer in San Francisco builds and secures identity, device, and network infrastructure for a fast-growing construction-tech startup, ensuring compliance and supporting a distributed workforce.
About Ironsite
The Role
What You'll Build
- Identity & Access Management. Automated onboarding and offboarding, SSO, and least-privilege access across our SaaS stack and multi-cloud environments, so the right people get the right access on day one, and lose it cleanly when they leave.
- Device & Endpoint Management. MDM and EDR across the laptop fleet, plus asset management and provisioning workflows for the hardware deployed across jobsites. The fleet is going to grow fast; the tooling has to grow with it.
- Security & Compliance. The controls behind SOC 2 and ISO 27001, partnership with the team on InfoSec, and the evidence and monitoring that make audits routine rather than fire drills. Enterprise customers ask about this in every deal so your work directly enables our sales motion.
- IT Support & Enablement. The support workflows and self-serve tooling that keep a distributed, multi-state team unblocked and productive, whether they're at HQ, remote, or in the field on a jobsite.
- Networking & Corporate Infrastructure. Corporate networking, VPN, and the core IT systems the company runs on will be managed as code wherever possible, so future you (and future hires) don't inherit a mess.
Technical Challenges You'll Solve
- Securing and supporting a workforce that spans HQ, remote employees, and field crews across the country. IT for a distributed company is one problem. IT for a company where a meaningful chunk of the team is on active construction jobsites is a different problem. You'll build systems and workflows that work for both without compromising either.
- Standing up and maintaining SOC 2 and ISO 27001 without slowing the company down. Compliance can either become a drag on the org or the foundation that lets us move faster. Your job is to make sure it's the second and help us by building controls that pass audits without becoming day-to-day bottlenecks.
- Keeping access least-privilege as the org changes weekly. We're growing fast, adding SaaS tools regularly, and rearchitecting how teams work as we scale. Identity and access management has to keep up without becoming a manual project every week. You'll build the automation that makes this a solved problem, not a running fire.
- Building asset management for a growing fleet of field-deployed hardware. Ironsite deploys hundreds of devices across jobsites in multiple states, with more coming every month. The tooling to track, provision, secure, and retire that hardware doesn't exist yet so you'll build it.
- Automating IT so it scales sub-linearly with headcount. As Ironsite grows from 35 people to 200, the IT footprint can't grow linearly with the team. You'll build the automation, self-serve tooling, and infrastructure-as-code patterns that make that possible.
What We're Looking For
- Strong background in IT engineering, systems administration, or corporate IT in production environments, typically 4+ years, with hands-on experience across the full stack of what a modern IT team owns.
- Deep experience with authentication and authorization: multi-cloud IAM, SSO (Google Workspace and similar), LDAP, and the identity patterns modern SaaS orgs run on.
- Hands-on experience with modern device management: MDM, EDR, and the endpoint security patterns for a distributed workforce.
- Comfort with Infrastructure as Code (Terraform or similar) and strong scripting skills (Python, Bash)
- Real experience designing and administering ZTNA/VPN deployments, plus corporate network administration.
- Hands-on experience implementing and maintaining security and compliance frameworks (SOC 2, ISO 27001, or similar).
- Judgment about when to build vs. when to buy, as you know when a SaaS tool is the right answer and when it's a tax you'll regret paying later.
- A background in Computer Science, Software Engineering, Mathematics, Physics, or a related technical field, or the equivalent hands-on experience.
Preferred Qualifications
- Cloud network architecture (VPCs, peering, segmentation).
- Relevant certifications (Security+, CISSP, Okta, Jamf, or similar).
- Experience scaling IT at a fast-growing startup through rapid headcount and multi-site growth, as you've been through this before and know what breaks first.
- Experience supporting hardware or device fleets, or IT for field operations.
- Experience leading or supporting SOC 2 or ISO 27001 audits end-to-end.
- Experience with construction, manufacturing, or similar operational industries where your users aren't always behind a desk.
Location, Compensation, & Perks
- San Francisco Bay Area (on-site)
- Base salary: $150-200k per year, commensurate with experience
- Meaningful early-stage equity.
- Full benefits including health, dental, vision, and 401(k) with 6% match
- Daily catered breakfast and lunch
- Office in San Francisco, next to Oracle Park and the Caltrain
