IT Engineer II

Tunnl
Hybrid

About The Position

The IT Engineer II owns the systems, tools, and infrastructure that keep the organization running. This is a hands-on role spanning SaaS administration, application integrations, network operations, and security — with direct exposure to audit and compliance work. You'll have real ownership and high visibility on a lean, high-trust team.

Requirements

  • 4-6 years in an IT engineering or systems administration role in a fast-moving environment.
  • Google Workspace administration — user management, Drive policies, security settings.
  • Rippling or comparable HRIS/MDM platform experience, including device management and integrations.
  • Network administration with Cisco Meraki (switches and/or APs); Sophos XGS or equivalent next-gen firewall.
  • Endpoint security experience — SentinelOne, CrowdStrike, or similar EDR platforms.
  • Working knowledge of SCIM, SSO (SAML/OIDC), and identity lifecycle management.
  • Familiarity with SOC 2 or comparable compliance frameworks and evidence collection.
  • Ability to document systems clearly — network diagrams, runbooks, integration specs.
  • Scripting or automation experience (Python, Bash, and PowerShell) for workflow tasks

Nice To Haves

  • Relevant certifications: Google Workspace Admin, CompTIA Security+, Meraki ECMS, CCNA, CCNP, or equivalent.
  • SIEM or log aggregation experience (Splunk, Datadog, or similar).

Responsibilities

  • Own provisioning, deprovisioning, licensing, and access control across Tunnl's SaaS portfolio — Google Workspace, Slack, Zoom, Notion, and others.
  • Enforce least-privilege and RBAC standards; manage vendor relationships and escalations.
  • Monitor application health, usage, and license efficiency.
  • Build and maintain integrations between SaaS platforms and Rippling, including SCIM provisioning, SSO, and workflow automation.
  • Identify and deploy configuration profiles and MDM policies to enforce IT and Security policy
  • Identify and automate manual processes; document all integration architecture and data flows.
  • Troubleshoot sync errors, auth failures, and integration breaks across connected systems.
  • Monitor, configure, and maintain Cisco Meraki switching/wireless and Sophos XGS firewall infrastructure.
  • Manage VLANs, firewall rules, access policies, and traffic segmentation; coordinate ISP circuit management and upgrades.
  • Maintain current network topology documentation; follow change management procedures for all modifications.
  • Triage and remediate security alerts from SentinelOne; perform vulnerability assessments across endpoints, apps, and network.
  • Maintain Rippling MDM policies for endpoint compliance, configuration profiles, and patching.
  • Contribute to security policy development and stay current on emerging threats relevant to Tunnl's environment.
  • Function as “End of Tier” support for IT issues.
  • Partner with Security and external auditors to support SOC 2 Type II — evidence collection, control documentation, and access reviews.
  • Maintain audit-ready records across access logs, change logs, and configuration baselines; respond to auditor requests directly.

Benefits

  • Comprehensive benefits with excellent medical, vision, and dental coverage.
  • Health Savings Account (HSA) and Flexible Spending Account (FSA) options.
  • Employer-paid life insurance & short-term & long-term disability, with other voluntary additional coverage available (accident, critical illness, hospital indemnity).
  • Flexible paid vacation plus 80 hours of paid sick leave.
  • 10 paid company holidays per year.
  • 401(k) plan with 100% match up to 3%, plus 50% match up to 5% (subject to IRS limits).
  • Cell phone reimbursement stipend.
  • Monthly parking or commuter stipend for VA-based employees.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service