IT Systems Engineer

GallatinWashington, DC

About The Position

We’re looking for an IT Systems Engineer to help build and scale the systems Gallatin employees rely on every day. As the second dedicated IT hire, you will work across endpoint engineering, identity and access management, SaaS administration, security and compliance, office infrastructure, automation, and employee support. You will own systems end to end and help define how IT operates as Gallatin grows. This is a broad systems role with a strong endpoint focus. You should be able to operate across macOS, Windows, mobile, identity, and cloud applications, with hands-on experience in Jamf Pro, Microsoft Intune, Google Workspace, and Okta. Experience managing Windows devices and access controls in Microsoft 365 GCC High is especially important. The level is flexible. We care more about technical judgment, ownership, and the ability to build reliable systems than a specific title or number of years.

Requirements

  • Experience as an IT Systems Engineer, Endpoint Engineer, Systems Administrator, or in a similarly broad technical role.
  • Strong hands-on Okta administration, including SSO, MFA, application integrations, lifecycle management, and access policies.
  • Strong hands-on management of macOS, Windows, and mobile devices using Jamf Pro, Microsoft Intune, and Google Workspace.
  • Experience operating Microsoft 365 and Intune in GCC High or another regulated Microsoft cloud environment.
  • Ability to independently design, implement, operate, and improve production IT systems.
  • Strong troubleshooting skills across operating systems, networks, identity platforms, and cloud applications.
  • Automation skills using Bash, PowerShell, Python, APIs, or workflow platforms.
  • Understanding of identity lifecycle management, device trust, least privilege, conditional access, and role-based access.
  • Strong communication, documentation, and judgment in fast-moving environments.
  • Comfort operating in a small team where ownership is broad and outcomes matter more than organizational boundaries.

Nice To Haves

  • Endpoint privilege management and application control.
  • Enterprise browser management, secure web gateways, or SaaS security posture management.
  • macOS Platform SSO or Windows Hello for Business.
  • PKI, device certificates, and certificate lifecycle management.
  • Configuration-as-code or infrastructure-as-code for corporate IT systems.

Responsibilities

  • Build and Own Endpoint Management: Own the lifecycle of Gallatin’s macOS, Windows, and mobile environments, from enrollment through deprovisioning. Build and maintain Jamf Pro policies, profiles, packages, scripts, smart groups, compliance controls, and Self Service workflows. Implement and operate Windows device management through Microsoft Intune in GCC High. Design Google Workspace mobile application management controls for employee-owned devices. Automate provisioning, application deployment, patching, security baselines, inventory, and compliance reporting.
  • Scale Identity and Enterprise Systems: Own identity lifecycle workflows across Okta, Google Workspace, Microsoft 365 GCC High, Slack, and other business-critical platforms. Automate onboarding, role changes, access reviews, and offboarding using APIs, scripts, and workflow tools. Design access controls around least privilege, device trust, role-based access, and data sensitivity. Administer and integrate Gallatin’s core productivity, collaboration, engineering, and business applications. Establish guardrails for enterprise AI tools and AI-enabled SaaS applications, including authentication, provisioning, data handling, retention, integrations, and audit logging. Partner with Security and Engineering to protect sensitive company and government data while enabling employees to use approved AI tools productively. Replace brittle manual processes with systems that are repeatable, observable, and difficult to misuse.
  • Strengthen and Operate the Environment: Translate CMMC, NIST 800-171, and other requirements into technical controls that work in practice. Build reliable device compliance, access enforcement, evidence collection, and audit-readiness workflows. Troubleshoot complex issues across endpoints, identity, SaaS applications, networking, authentication, and operating systems. Provide direct employee support while eliminating recurring failure modes through engineering and automation. Create clear documentation, runbooks, standards, and employee-facing guidance. Take ownership of unfamiliar problems and drive them through resolution.

Benefits

  • generous equity grant
  • full healthcare coverage
  • 401k
  • unlimited PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service