IT Systems Administrator
SupabaseAbout Supabase
Supabase is an open source Firebase alternative. We give developers a Postgres database, authentication, instant APIs, edge functions, and real-time subscriptions — all in one platform. We are building the infrastructure layer for the next generation of applications.
Corporate IT at Supabase reports into the Security organization. Identity and endpoint hygiene are treated as security controls, not administrative overhead. You will work with a small, senior team with direct access to engineering leadership and a mandate to automate everything.
About the Role
You will work directly with our IDM/MDM Lead to own the day-to-day operations of our identity and endpoint stack — Okta, Slack, Iru (MDM), and the integrations that tie them together. This role is equal parts identity management and endpoint operations, with a strong expectation that you automate what you repeat and document what you automate.
This role provides follow-the-sun IT and identity coverage alongside our IDM/MDM Lead on the West Coast. Fully remote, with a strong preference for candidates based in EST or APAC.
What You’ll Own
Identity & Access Management
Administer Okta day-to-day: user provisioning, group management, SSO application configuration, and MFA policy enforcement.
Own joiner-mover-leaver (JML) workflows — ensure access is granted on day one, adjusted on role change, and fully revoked on departure with no manual gaps.
Maintain and improve Okta lifecycle automation, reducing manual provisioning toil and closing the window between HR events and access changes.
Audit access regularly: identify stale accounts, over-provisioned roles, and orphaned app assignments before they become incidents.
Support FIDO2/WebAuthn and YubiKey deployment for privileged access across the organization.
Endpoint Management & MDM
Administer Iru (formerly Kandji) MDM for macOS fleet: device enrollment, configuration profiles, compliance baselines, and policy enforcement.
Ensure all managed endpoints meet security baselines — disk encryption, screen lock, patch cadence, and EDR agent deployment.
Support onboarding hardware logistics: device procurement, enrollment, and first-day readiness across global time zones.