The Role
Build and operate the company’s global IT function, including Google Workspace, identity and access management, endpoint management, hardware lifecycle, SaaS governance, IT support, automation, vendor management, and technical SOC 2/GDPR compliance. Ensure secure onboarding and offboarding, manage devices and access across countries, run audits and security awareness programs, and establish scalable IT processes as the organization grows.
Summary Generated by Built In
Hey there! KodeKloud is a young, fully remote, bootstrapped startup growing fast. Trusted by over 1 million users worldwide, we're an EdTech SaaS company dedicated to transforming the way businesses upskill their teams in DevOps, Cloud Computing, and IT by offering hands-on, practical learning experience.
As trailblazers in the remote-first workforce, we seamlessly blend work from cozy cafes, sunny beaches, mountain retreats, and vibrant cities or from our company-sponsored home office setups. Our team spans the globe, and we're all about creating a fun, no-ego environment where everyone can learn, grow, and make an impact.
For this role, we're looking for someone who can build an IT function from nothing and run it properly. We're 110+ people across 22 countries with no offices - which means everything a traditional IT team would own (identity, devices, access, tooling, security controls) is currently spread across different teams. You'd be the first person to take all of it, decide how it should work, and make it work.
This is a "build + run" role in the truest sense. Some of it is hands-on and immediate - someone's laptop has died in Moldova, a new joiner starts in Singapore on Monday. Some of it is systemic - choosing and deploying MDM, owning our SOC 2 technical controls, building a device lifecycle that works across borders. You'll need to be good at both, and comfortable deciding what to fix first.
Note: This is a hands-on individual contributor role to start with, and it's our first IT hire. You won't be inheriting a function - you'll be designing one, with the opportunity to build and lead a team as we scale.
Job requirements
Must-have:
Nice-to-have
Job responsibilities
What You'll Own & Lead:
Benefits
As trailblazers in the remote-first workforce, we seamlessly blend work from cozy cafes, sunny beaches, mountain retreats, and vibrant cities or from our company-sponsored home office setups. Our team spans the globe, and we're all about creating a fun, no-ego environment where everyone can learn, grow, and make an impact.
For this role, we're looking for someone who can build an IT function from nothing and run it properly. We're 110+ people across 22 countries with no offices - which means everything a traditional IT team would own (identity, devices, access, tooling, security controls) is currently spread across different teams. You'd be the first person to take all of it, decide how it should work, and make it work.
This is a "build + run" role in the truest sense. Some of it is hands-on and immediate - someone's laptop has died in Moldova, a new joiner starts in Singapore on Monday. Some of it is systemic - choosing and deploying MDM, owning our SOC 2 technical controls, building a device lifecycle that works across borders. You'll need to be good at both, and comfortable deciding what to fix first.
Note: This is a hands-on individual contributor role to start with, and it's our first IT hire. You won't be inheriting a function - you'll be designing one, with the opportunity to build and lead a team as we scale.
Job requirements
Must-have:
- 5-8 years in IT operations or IT and security, including a distributed or remote-first environment
- Deep Google Workspace administration - real depth, not familiarity with the admin console
- Hands-on MDM ownership across macOS and Windows
- Identity and access management: SSO, MFA, provisioning, access reviews
- Experienced in vendor negotiation and renewal management
Nice-to-have
- Has carried SOC 2 (or ISO 27001) controls through an audit as an implementer, not a policy author
- Working GDPR knowledge in a technical context
- Multi-country asset lifecycle management
- Scripting and automation for provisioning and reporting
- Experience administering JumpCloud and using Drata or equivalent compliance platforms
Job responsibilities
What You'll Own & Lead:
- Google Workspace & Identity Own Workspace end to end - org structure, security settings, licences, groups, mail routing, and retention. Enforce SSO and MFA across every business tool, and make sure our domain can't be spoofed in mail sent to our customers.
- Access Management & Privileged Access Governance Own joiner, mover and leaver access across all systems. Run quarterly access reviews on a least-privilege basis, control third-party app access, and put real governance around privileged access - an approval path for account and mailbox access, audit log monitoring, and a record of who used elevated access and why.
- Device & Endpoint Management Select, deploy and run MDM across every company-owned device - encryption, screen lock, patching, endpoint protection, remote lock and wipe. Build a workable approach for personally-owned devices where full management isn't available to us.
- Hardware Asset Lifecycle & Global Logistics Build and own a single asset register - every device, who holds it, what it costs, which entity owns it, when it's due for refresh. Set standard specs, run regional procurement (buy, lease, or device-as-a-service, whichever actually wins), and own returns, buyback, resale and secure disposal with proof of data destruction.
- Enterprise Tooling & SaaS Governance Bring tool administration out of individual inboxes and into managed ownership. Maintain a central register of every business tool with its owner, cost, renewal date, data classification and DPA status. Reclaim licences at exit, kill duplicate tools, and surface shadow IT - including AI tools, and what data is going into them.
- Security & Compliance Execution (SOC 2 & GDPR) Own the technical side of compliance: implement the controls, run them, and evidence them. Access reviews, onboarding and offboarding trails, change records, compliance automation tooling, incident response (including rehearsing it), and the vendor and subprocessor register. Coordinate penetration tests and track remediation. Be our named owner for customer security questionnaires and enterprise security reviews.
- Security Awareness & Enablement Run security awareness and phishing training that people actually complete, and build an internal knowledge base so the same question doesn't get answered twice. Explain risk to non-technical teammates without hand-waving or lecturing.
- IT Support & Day-1 Readiness Run a real support channel with published response times that works across our time zones. Make sure every new KodeKlouder has their accounts live and their laptop in hand before day one, and that leavers are fully offboarded the same day, with an evidence trail.
- Automation, Vendors & IT Budget Automate the repetitive work - provisioning, deprovisioning, reporting. Manage IT vendors and renewals in partnership with Finance, with a clear view of what we're spending and why.
Benefits
- Fully Remote: Work from anywhere - yes, your couch in pajamas is totally fine.
- Big Impact: We're a small team, so your contributions will directly shape our future.
- Lots of Learning: We're growing, and so will you - there's plenty of room to expand your skills and take on new challenges.
- People & Culture: Expect to be surrounded by a bunch of super passionate and pretty awesome people, and a culture of trust and transparency.
Skills Required
- 5-8 years of experience in IT operations or IT and security, including experience in a distributed or remote-first environment
- Deep Google Workspace administration experience
- Hands-on MDM ownership across macOS and Windows
- Identity and access management experience, including SSO, MFA, provisioning, and access reviews
- Vendor negotiation and renewal management experience
- Experience implementing SOC 2 or ISO 27001 controls through an audit
- Working knowledge of GDPR in a technical context
- Multi-country asset lifecycle management experience
- Scripting and automation experience for provisioning and reporting
- Experience administering JumpCloud and using Drata or an equivalent compliance platform
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
KodeKloud is an online learning platform dedicated to practical, hands-on DevOps education. Founded by industry experts, it combines video lectures with interactive labs and real-world scenarios so learners can apply skills immediately. The platform serves beginners and experienced professionals with career-focused courses, just-in-time help, community support, and hands-on challenges designed to solve technical problems and accelerate advancement in evolving IT environments.






