IT Systems Engineer

Gyde•New York, NY

About The Position

Gyde is reimagining the insurance brokerage industry by building the first AI-native insurance brokerage platform. This platform aims to automate operations, power intelligent voice and chat experiences, and predict the right coverage and products for individuals and businesses. The company acquires traditional brokerages and transforms them into data-driven organizations using its platform. The role of the IT Systems Engineer is crucial in integrating these acquired agencies into the Gyde platform, ensuring their IT infrastructure is functional from day one. This involves managing accounts, laptops, and access, and engineering automated systems for these processes. The engineer will be part of the Infrastructure team, reporting to the Head of Infrastructure, and will focus on automating integration runbooks into repeatable systems. The role involves significant operational work, including managing device fleets, handling MFA and SSO resets, and managing account lifecycles across various platforms like Entra/Okta and Google Workspace/M365. The ideal candidate will have experience in end-user IT in a fast-paced, multi-tenant environment, be proficient in scripting and configuration-as-code, and remain calm under pressure during integration cutovers.

Requirements

  • 4–6 years in end-user IT, IT operations, systems engineering, or an MSP environment.
  • Hands-on scripting and automation (PowerShell, Python, or similar) and comfort managing configuration as code. This is a core requirement for this role, not a bonus.
  • Hands-on administration of an IdP (Entra ID or Okta) plus Google Workspace and/or Microsoft 365.
  • MDM experience including policy and compliance management (Hexnode a plus; Intune, Jamf, or Kandji acceptable).
  • Comfortable imaging/provisioning laptops and managing the device lifecycle end to end.
  • Solid working grasp of MFA, SSO/conditional access, VPN, and AVD or a comparable remote-desktop setup.
  • Automation & Configuration-as-Code: You script and version-control your work (PowerShell, Python, Graph API, or similar), and you'd rather define infrastructure and policy as code than manage it by hand. You see a recurring task and instinctively reach for a way to make it disappear.
  • Identity & Access Management: Confident across an IdP (Entra/Okta), Google Workspace/M365, MFA, SSO, and conditional access, with clean JML hygiene. You reason about least privilege and entitlements, and you don't need to be told when an offboarding has to happen same-day.
  • Endpoint & MDM Operations: You've owned a device fleet, not just touched one — imaging, enrollment, lifecycle, inventory reconciliation, and policy/compliance troubleshooting in an MDM (Hexnode or comparable), ideally managed as code.
  • End-User Support & Troubleshooting: You diagnose and resolve laptop, SaaS, connectivity, and access issues quickly and explain them plainly to non-technical users — and you treat a recurring issue as a signal to fix or automate something upstream, not a task to close.
  • Communication & Stakeholder Management: Calm, clear, and credible with non-technical agency users and leadership, especially under cutover pressure. You can explain what's happening and what's next without jargon.
  • Operational Rigor & Security Mindset: You follow and improve runbooks, document recurring quirks, and handle HIPAA-aware verification and device-loss scenarios without being prompted. You build process and tooling, not just habit.

Nice To Haves

  • Config-as-code / IaC tooling for identity or endpoints (e.g., Terraform, Okta Workflows, Entra Lifecycle Workflows, or Intune-as-code).
  • Experience supporting a HIPAA or otherwise regulated environment.
  • Multi-tenant, MSP, or M&A / agency-integration IT experience.
  • Hexnode and Azure Virtual Desktop (AVD) specifically.

Responsibilities

  • Engineer the agency-integration experience, don't just run it. Own onboarding, cutover, hypercare, and day-to-day support for acquired agencies as the primary IT point of contact — and continuously convert that work into scripted, repeatable systems so each integration is faster and more hands-off than the last.
  • Manage endpoints and devices as code. Image, enroll, ship, and lifecycle-manage laptops (provisioning through RMA and offboarding retrieval); operate the MDM (Hexnode) day to day, and codify policies, baselines, and compliance remediation instead of clicking through consoles.
  • Automate the identity and access lifecycle. Provision, modify, and deprovision accounts across Entra/Okta, Google Workspace/M365, and core SaaS; run JML workflows with same-day deprovisioning as a non-negotiable, and drive toward automated, HRIS-triggered lifecycle so it happens reliably without manual steps.
  • Turn integration runbooks into repeatable tooling. Take the Infra Engineer's runbooks, schedule and run cutover waves with agency leadership, capture friction, and feed fixes back as automation and version-controlled process; own status comms during rollouts and incidents.
  • Build security hygiene into the system. Enforce endpoint baselines, disk encryption, MFA enrollment, and screen-lock policies through managed, auditable configuration; support phishing reporting and basic user security education; flag anomalies (impossible travel, unmanaged devices, shadow IT) to Security/Infra; keep HIPAA-aware habits by default.

Benefits

  • Top of the market compensation
  • Flexible (Unlimited) Paid Time Off
  • Medical, Dental, and Vision benefits for you and your family
  • Retirement Plan (e.g., 401K)
  • Parental Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service