IT Operations Manager (Contract)

Posted Yesterday
Be an Early Applicant
2 Locations
Hybrid
75-110 Hourly
Senior level
Social Impact • Software
Modern, people-first software for America’s public services.
The Role
Contract IT Operations Manager to design and implement identity, endpoint, and access lifecycle systems for a cloud-first macOS-centric startup selling to government. Deliver device management, automated joiner/mover/leaver workflows, access reviews, SaaS inventory, a scoped enclave, and compliance evidence; produce runbooks so the program runs after the engagement ends.
Summary Generated by Built In

Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services.

Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service.

Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year.

Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back.

The Role

Kaizen builds software for federal and local government. We are roughly ~40 people on a cloud-first, mostly macOS stack, and we sell into customers who impose real requirements on how we run our own corporate systems.

IT here is currently distributed across engineers and operators who all have other full-time jobs. It works, in the sense that people can log in. Selling into government means holding a higher bar on identity, devices and access than a side-of-desk model can sustain, so we are building the layer properly. This engagement does that and leaves behind something that runs without you.

Hands-on build work: deploying tools, writing policy, and cleaning up account sprawl rather than advising on it.

What You'd Own

Identity. We are partway through consolidating everything behind a single identity provider and the tail is where the value is: the applications nobody wanted to touch, the provisioning that still happens by hand, and the lifecycle rules that turn it into a system. You would finish it and then own it, including automated provisioning and deprovisioning.

Endpoints. Device management is a program you would stand up rather than one you would inherit. Our government customers set requirements on the devices used for their work, and this role owns meeting those requirements and evidencing them. You would select the tool, deploy it across the fleet, and write the policy that goes with it. This is the largest single deliverable in the engagement.

Employee lifecycle. Joiner, mover, leaver. Today both are documented processes rather than instrumented ones. You would turn them into a system with timing, an audit trail, and named owners, including credential and hardware return. One design constraint: some of our contracts specify tight windows for disabling access when someone departs, so the leaver path has to be built against a clock and produce evidence that it met it.

Access reviews. A recurring review of who has access to what, on a cadence, producing evidence rather than a screenshot. Our auditors and our government customers both ask for this, and you would own the cadence and the trail.

A scoped enclave. Some of our government work involves controlled information with handling requirements that do not apply to the rest of the business. You would stand up a separate, deliberately narrow environment for it, with its own identity, managed devices, controlled storage and a documented boundary, then write the runbook that keeps the scope from drifting. Keeping that boundary narrow over time is harder than building it.

The SaaS estate. Inventory, owners, renewal dates, who has admin, and what data sits where. Right now that knowledge is in people's heads.

Deliverables

What we expect to have in hand at each stage.

Weeks 1 to 4

  • A complete inventory of devices, applications, and accounts, each mapped to a named human and reconciled against current employment status

  • The identity provider rollout finished across the remaining applications, with the queued work closed out

  • A written joiner, mover and leaver process with the revocation step timed and evidenced

Weeks 5 to 12

  • Endpoint management selected, purchased and deployed across the fleet, with a device and acceptable-use policy that lets us evidence the software restrictions our contracts carry

  • A quarterly access review established, in a format an assessor will accept

  • Offboarding automated end to end, including credential and physical asset return with written confirmation

  • SaaS estate rationalized: inventory, owner, renewal date, admin list, and data posture for each

Months 3 to 6

  • Privileged access separated from standard access and documented

  • Identity and access evidence flowing to our compliance program on a schedule

  • The scoped enclave stood up and documented, with a defined user list and a boundary that holds

  • Readiness for certificate and smart-card based authentication, which some of our government work will require

  • Runbooks good enough that the program survives the end of this engagement

What You'll Bring
  • You have owned a modern identity provider, Okta, Entra or JumpCloud, as the administrator rather than a user. App onboarding, SCIM provisioning, lifecycle rules, and the unglamorous work of chasing down the last twelve applications

  • You have deployed endpoint management from zero across a real fleet. Jamf, Kandji, Hexnode or Intune. You know what breaks when you do this to people who have never had a managed device, and you have a plan for that conversation

  • You have paired endpoint management with an EDR tool and can speak to both halves. CrowdStrike, Huntress or similar

  • You have built a joiner, mover and leaver process that produced an audit trail, not a checklist someone remembers to open

  • You have run an access review that an auditor accepted. You know the difference between a spreadsheet and evidence

  • You are fluent in a cloud-first, mostly macOS environment: Google Workspace, a password manager, AWS console access, SSO everywhere

  • You write runbooks other people can follow. This engagement is judged partly on what still works after it ends

  • You are comfortable as the only IT person, with an engineering team who will help you but does not report to you

  • US person

Strong Candidates May Also
  • Have taken a company through SOC 2, FedRAMP or CMMC on the IT side and know exactly which access and device artifacts the assessor asks for. This is the single most valuable thing on this list and it moves our rate

  • Know certificate and smart-card authentication, PIV or CAC, and government PKI

  • Have handled device, software or account restrictions that flowed down from a government contract

  • Have come out of a managed service provider and want to build in-house instead of firefighting across twenty clients

  • Have done exactly this as a contract engagement before and can describe what made it work or fail

Scope of Work

Product engineering and our government hosting environments stay with employees. You would own corporate identity and corporate devices, not the production or federal environments. Security architecture decisions sit with our engineering lead; you would implement and operate.

Don't Apply If...
  • Your background is ticket triage and password resets. This engagement designs and builds systems, and there is no queue to work

  • You need an established stack and a documented environment to step into. Neither exists yet, and building them is the job

  • Your experience is Windows and on-premise Active Directory. It does not transfer cleanly to where we are

  • You want a retainer to advise. We need someone who buys the tool and deploys it

  • You would rather grow a team than do the work yourself. There is no team, and there will not be one during this engagement

What Kaizen Offers

Health & Insurance

  • 100% coverage across the board: medical through Oxford/United (Gold and Platinum PPO plans), dental through Guardian PPO, and vision through Beam — all fully covered for employees, with 100% coverage for dependents.

  • $100,000 in fully paid life insurance. FSA and Dependent Care FSA.

  • One Medical membership, on us — same-day primary care, 24/7 virtual visits, and offices all over the city.

  • Fertility and family-building support through Carrot.

  • 401(k) through Guideline, with a 2% company match.

Family & Time Off

  • 16 weeks of fully paid parental leave for birthing parents. 10 weeks fully paid for non-birthing parents.

  • Unlimited PTO, with a two-week minimum (we mean it when we say take time off!)

  • Closed for all federal holidays.

  • Company-wide winter break the week of Christmas.

  • Company offsites throughout the year.

Office & Remote Setup

  • Up to $750 one-time home office or desk setup stipend for NYC-based employees. $500 for remote employees.

  • $50/month commuter benefit (company contribution).

  • Expensed lunch while in the office.

  • Company-provided laptop of your choice.

Wellness

  • Fully covered gym membership at Grindhouse — right across the street from our office at 47 W 17th St (and in Williamsburg). A $225/month value, on us. For remote employees, $100/month dedicated to gym or physical fitness reimbursement.

Stipends

  • $100/month utility stipend.

  • $500/year professional development.

  • $250/year recreation.

  • $300/quarter pet care stipend.

Skills Required

  • Administered a modern identity provider (Okta, Entra, or JumpCloud) including app onboarding, SCIM provisioning, and lifecycle rules
  • Selected, deployed, and managed endpoint management across a fleet (Jamf, Kandji, Hexnode, or Intune)
  • Paired endpoint management with an EDR solution (e.g., CrowdStrike, Huntress) and operated both
  • Designed and implemented joiner, mover, and leaver processes producing an audit trail
  • Conducted access reviews accepted by auditors and produced evidence rather than spreadsheets
  • Fluent operating in a cloud-first, mostly macOS environment (Google Workspace, AWS Console, SSO, password manager)
  • Authored runbooks and documentation that enable ongoing operation after engagement end
  • Experience as the sole or primary IT person supporting an engineering organization
  • US person (must be eligible to work as a US person)
  • Experience taking a company through SOC 2, FedRAMP, or CMMC on the IT side
  • Knowledge of certificate and smart-card authentication, PIV/CAC, and government PKI
  • Experience handling device, software, or account restrictions flowing from government contracts
  • Background at a managed service provider or prior contract engagements doing this work

Kaizen Labs Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kaizen Labs and has not been reviewed or approved by Kaizen Labs.

  • Healthcare Strength Comprehensive medical, dental, and vision coverage is emphasized, with strong employer contributions and options like FSAs and employer‑paid life insurance. These offerings can meaningfully enhance total rewards beyond base pay.
  • Parental & Family Support Fully paid parental leave is provided for both birthing and non‑birthing parents, signaling meaningful support for growing families. A stated return‑to‑work approach further underscores family‑oriented benefits.
  • Fair & Transparent Compensation Role postings include explicit salary ranges and pay bands, improving clarity on cash compensation. Visible ranges help candidates understand where they might slot within the band during offer discussions.

Kaizen Labs Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, New York
40 Employees
Year Founded: 2022

What We Do

Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services. Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service. Our platform already reaches 40 million residents across 50+ agencies in 17 states. Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn’t be a luxury in government. It’s how you earn trust back.

Why Work With Us

At Kaizen, you’ll find more than just a job - you’ll find ownership, autonomy, and purpose. We're building tools that truly help communities, with a culture rooted in trust, psychological safety, and cross-functional collaboration. It's meaningful work, with smart, supportive people by your side.

Gallery

Gallery

Similar Jobs

PwC Logo PwC

Data Scientist

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
6 Locations
370000 Employees
63K-140K Annually

PwC Logo PwC

Salesforce Consulting Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
64 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

ServiceNow Deployment- Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
62 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

Marketing Channel Strategy Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
63 Locations
370000 Employees
151K-187K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account