Stratus, deriving from the Latin term meaning 'layer', offers an advanced set of MEPspecific solutions that seamlessly layer across a contractor's entire workflow from design to fabrication to installation. Our team of seasoned industry experts, skilled technology leaders, innovators, and entrepreneurs understands that fabrication does not occur in isolation, and increasingly, it may not happen within your own fabrication shop. Through close relationships with our customers — who include some of the most innovative and largest MEP contractors — we have developed a suite of Stratus tools to digitize, automate, and optimize piping, plumbing, sheet metal, and electrical contracting. Stratus provides the software layer an MEP contractor needs to optimize profits with true "Data-Driven Contracting."
General Description
The IT Systems Administrator will own the internal technology estate at Stratus and report to the Senior Director, Platform Engineering. The headline outcome of this role is a company where every new hire is fully productive on day one and fully deprovisioned the day they leave — with the identity, endpoint, and SaaS systems behind that managed as repeatable process rather than tribal knowledge. You will run our Microsoft Entra ID and Microsoft 365 environment, our Rippling-managed device fleet, and the SaaS applications the company depends on, and you will steadily convert the manual work in each of those into automation. This role sits on the Platform Engineering team rather than in a standalone IT function, which means you will have platform engineers to learn from, real tooling to work with, and an expectation that you automate your way out of recurring toil instead of absorbing it. You should be pragmatic and service-oriented, comfortable being the person the whole company relies on for access and equipment, and genuinely interested in using AI tooling to do that job better than it has been done before.
Key Responsibilities
Identity and Access
- Administer the Microsoft Entra ID workforce tenant and Microsoft 365 environment — users, groups, licensing, conditional access, and MFA policy.
- Own SSO and SAML/OIDC application integrations across our federated SaaS estate (GitHub Enterprise Cloud, Salesforce, MongoDB Atlas, HubSpot, Keeper, OpenVPN, Autodesk, and roughly a dozen more), including onboarding new applications to SSO as the company adopts them.
- Run periodic user access reviews and least-privilege cleanup, and produce the evidence that those reviews happened.
- Support identity and directory initiatives as the environment evolves — domain changes, directory migrations, and platform consolidation.
Endpoint and Asset Management
- Manage the device fleet through Rippling — enrollment, configuration and compliance policy, patching, and encryption baselines across the company’s laptops and mobile devices.
- Own hardware asset inventory and lifecycle: procurement, imaging, shipping to remote employees, refresh, and secure retirement.
- Maintain an accurate, current inventory of devices, software, and SaaS licenses — and keep it accurate without a quarterly fire drill.
Onboarding, Offboarding, and Support
- Own the end-to-end onboarding and offboarding process. Rippling is our system of record for people, devices, and assets — drive that toward same-day provisioning and same-day deprovisioning with no manual steps.
- Serve as the escalation point for employee IT requests — accounts, access, devices, connectivity, conferencing, and the everyday problems that block people from working.
- Administer SaaS applications company-wide: provisioning, deprovisioning, license reconciliation, and vendor/renewal coordination.
Automation and AI-Assisted Operations
- Automate recurring IT work rather than repeating it — scripted provisioning, license reconciliation, access reporting, and compliance evidence collection.
- Use AI tooling (we use Claude Code and Cursor) as a daily part of the job, and write internal runbooks in a form that both a human and an agent can execute.
- Contribute to company-wide AI tooling operations: seat and license management, access provisioning, and helping the rest of the company adopt the tools effectively.
Security and Compliance
- Support our SOC 2 and NIST 800-171 audits end to end — gather and produce evidence, respond to auditor requests, track remediation items to closure, and own the IT-side controls outright: access control, account lifecycle, asset inventory, MFA enforcement, and device compliance.
- Administer Vanta, our compliance platform, and keep its integrations wired into identity, device, and ticketing systems so evidence collection runs continuously in the background instead of becoming a quarterly scramble ahead of each audit window.
- Own the employee-facing compliance obligations that audits actually fail on — security awareness training completion, policy acknowledgement and e-signature tracking, and access review attestations — and make them a tracked part of onboarding rather than a fire drill.
- Help maintain IT and security policy documentation so what we have written down matches what we actually do.
- Administer our password and secrets management platform (Keeper) and enforce good credential hygiene across the company.
- Support internal network and remote access infrastructure, including our SAML-integrated VPN.
Documentation
- Create and maintain clear runbooks, internal knowledge base articles, and self-service documentation. Documentation is a deliverable here, not an afterthought — if only you know how something works, the job is not finished.
Qualifications
- 3-5 years of hands-on IT systems administration experience supporting a distributed workforce. A degree is welcome but experience is what we are evaluating.
- Demonstrated production experience administering Microsoft Entra ID (Azure AD) and Microsoft 365 — this is our environment and it is a hard requirement.
- Hands-on experience with MDM / endpoint management at company scale — enrollment, compliance policy, and configuration baselines. We run Rippling; equivalent experience in Jamf, Kandji, or a comparable platform transfers.
- Practical experience configuring SSO/SAML application integrations and troubleshooting federation failures.
- Experience owning employee onboarding and offboarding, including access provisioning and deprovisioning.
- Scripting ability sufficient to automate real work — PowerShell, Bash, or Python. We are not looking for a software engineer, but we are looking for someone who reaches for a script before a checklist.
- Experience supporting a security audit or compliance program — collecting evidence, responding to auditor requests, and keeping control documentation current. You do not need to be a compliance specialist, but audit season should not be new to you.
- Strong written communication and technical writing skills; demonstrated ability to produce documentation other people actually use.
- Genuine enthusiasm for using AI tooling in operations work, and the aptitude to pick it up quickly. Prior experience is a plus, not a requirement — we will teach you how we use it.
- Service orientation and sound judgment about urgency. You will be the person the company depends on when something blocks their work.
Preferred Qualifications
- Google Workspace administration experience.
- Direct experience administering Rippling, or another HRIS used as the provisioning source of truth (Workday, BambooHR, or similar).
- Direct experience with SOC 2 or NIST 800-171 (or adjacent frameworks — NIST 800-53, CMMC, ISO 27001), and with compliance automation platforms such as Vanta, Drata, or Apptega.
- Experience with infrastructure as code (Terraform/OpenTofu) or configuration management for internal-facing systems.
- Familiarity with GitHub and GitHub Actions, including organization and access administration.
- Experience administering a password manager or secrets platform at company scale.
- Exposure to Azure, Kubernetes, or a platform engineering environment.
- Prior experience building internal automations, integrations, or agents.
- Background in construction, MEP, manufacturing, or another non-software-native industry.
Benefits
- Comprehensive and competitive health benefits plan
- Matching 401k contributions
- 20 days annual PTO
- Primarily remote work with occasional annual team onsites.
E-VERIFY STATEMENT
Stratus participates in E-Verify. After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only - we never use E-Verify to pre-screen applicants.
E-Verify Notice
Right to Work Notice
Skills Required
- 3-5 years of hands-on IT systems administration experience supporting a distributed workforce
- Production experience administering Microsoft Entra ID and Microsoft 365
- Hands-on experience with MDM or endpoint management at company scale
- Experience configuring SSO and SAML application integrations and troubleshooting federation failures
- Experience owning employee onboarding and offboarding, including access provisioning and deprovisioning
- Scripting ability with PowerShell, Bash, or Python
- Experience supporting a security audit or compliance program
- Strong written communication and technical writing skills
- Enthusiasm for using AI tooling in operations work
- Service orientation and sound judgment about urgency
- Google Workspace administration experience
- Experience administering Rippling or another HRIS used as a provisioning source of truth
- Experience with SOC 2, NIST 800-171, NIST 800-53, CMMC, ISO 27001, or adjacent frameworks
- Experience with compliance automation platforms such as Vanta, Drata, or Apptega
- Experience with infrastructure as code such as Terraform or OpenTofu
- Familiarity with GitHub and GitHub Actions organization and access administration
- Experience administering a password manager or secrets platform at company scale
- Exposure to Azure, Kubernetes, or a platform engineering environment
- Experience building internal automations, integrations, or agents
- Background in construction, MEP, manufacturing, or another non-software-native industry
What We Do
The Leading Tool for MEP Fabrication Workflows. Stratus is a cloud-based software platform that revolutionizes MEP fabrication and construction management by seamlessly integrating CAD software like Revit and AutoCAD with manufacturing tools to reduce errors and boost efficiency. By leveraging digital models for precision fabrication and enabling real-time collaboration, Stratus enhances communication among teams and ensures accurate project tracking. This platform empowers specialty contractors to streamline their workflows from BIM to installation, optimizing planning, resource allocation, and project execution. Stratus... - Optimizes Project Management and Decision Making with a modern, cloud-based platform that connects your VDC, Shop and Field teams - Eliminates Paper and PDF Workflows in the shop and in the field with direct access to the model - Reduces Waste with smart cut lists, material management and smart labels - Automates Fabrication with direct output to various cutting equipment - Eliminates Manual Conversion Steps with direct integration from CAD software like Revit and AutoCAD to manufacturing tools, automating the fabrication process and reducing errors -Leverages Historical Data to forecast future project timelines and productivity, enabling better planning and resource allocation -Assigns custom tracking statuses to work packages, offering unparalleled visibility into project progress and logistics









