Unknown Company
<h2><strong>About Supabase</strong></h2><p style="min-height:1.5em">Supabase is an open source Firebase alternative. We give developers a Postgres database, authentication, instant APIs, edge functions, and real-time subscriptions — all in one platform. We are building the infrastructure layer for the next generation of applications.</p><p style="min-height:1.5em">Corporate IT at Supabase reports into the Security organization. Identity and endpoint hygiene are treated as security controls, not administrative overhead. You will work with a small, senior team with direct access to engineering leadership and a mandate to automate everything.</p><p style="min-height:1.5em"></p><h2><strong>About the Role</strong></h2><p style="min-height:1.5em">You will work directly with our IDM/MDM Lead to own the day-to-day operations of our identity and endpoint stack — Okta, Slack, Iru (MDM), and the integrations that tie them together. This role is equal parts identity management and endpoint operations, with a strong expectation that you automate what you repeat and document what you automate.</p><p style="min-height:1.5em">This role provides follow-the-sun IT and identity coverage alongside our IDM/MDM Lead on the West Coast. Fully remote, with a <strong>strong preference for candidates based in EST or APAC.</strong></p><p style="min-height:1.5em"></p><h2><strong>What You’ll Own</strong></h2><p style="min-height:1.5em"></p><h3><strong>Identity & Access Management</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Administer Okta day-to-day: user provisioning, group management, SSO application configuration, and MFA policy enforcement.</p></li><li><p style="min-height:1.5em">Own joiner-mover-leaver (JML) workflows — ensure access is granted on day one, adjusted on role change, and fully revoked on departure with no manual gaps.</p></li><li><p style="min-height:1.5em">Maintain and improve Okta lifecycle automation, reducing manual provisioning toil and closing the window between HR events and access changes.</p></li><li><p style="min-height:1.5em">Audit access regularly: identify stale accounts, over-provisioned roles, and orphaned app assignments before they become incidents.</p></li><li><p style="min-height:1.5em">Support FIDO2/WebAuthn and YubiKey deployment for privileged access across the organization.</p></li></ul><h3><strong>Endpoint Management & MDM</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Administer Iru (formerly Kandji) MDM for macOS fleet: device enrollment, configuration profiles, compliance baselines, and policy enforcement.</p></li><li><p style="min-height:1.5em">Ensure all managed endpoints meet security baselines — disk encryption, screen lock, patch cadence, and EDR agent deployment.</p></li><li><p style="min-height:1.5em">Support onboarding hardware logistics: device procurement, enrollment, and first-day readiness across global time zones.</p></li><li><p style="min-height:1.5em">Identify and track unmanaged or out-of-compliance devices; drive remediation and escalate persistent non-compliance.</p></li><li><p style="min-height:1.5em">Maintain MDM configuration as code where possible — changes should be reviewable, versioned, and reversible.</p></li></ul><h3><strong>SaaS & Collaboration Platform Operations</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Administer Slack workspace: channel governance, app integration reviews, guest access management, and enterprise grid operations.</p></li><li><p style="min-height:1.5em">Manage the corporate SaaS portfolio — own app provisioning, license tracking, and access reviews for tools like Google Workspace, Zoom, Notion, and others.</p></li><li><p style="min-height:1.5em">Review and approve new SaaS integration requests against security and data handling standards before deployment.</p></li><li><p style="min-height:1.5em">Maintain an accurate inventory of corporate applications, their owners, access scope, and data classification.</p></li></ul><h3><strong>Automation & Process Improvement</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Identify repetitive IT tasks and eliminate them through automation — scripting, workflow tooling, or Okta lifecycle rules.</p></li><li><p style="min-height:1.5em">Write and maintain runbooks for all core IT operations so coverage is consistent across time zones and not dependent on any single person.</p></li><li><p style="min-height:1.5em">Contribute to IT metrics: onboarding time-to-access, offboarding completion rate, MDM compliance percentage, and access review cadence.</p></li><li><p style="min-height:1.5em">Partner with the Security Engineering team to close gaps surfaced by compliance audits (SOC 2, ISO 27001) that touch identity and endpoint controls.</p></li></ul><h3><strong>You Might Be a Good Fit If You Have</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em">2–4 years in a corporate IT, IT operations, or identity administration role at a cloud-native or SaaS company.</p></li><li><p style="min-height:1.5em">Hands-on Okta administration experience: SSO, MFA, lifecycle management, and group/policy configuration.</p></li><li><p style="min-height:1.5em">Experience with a modern MDM platform (Kandji/Iru, Jamf, or equivalent) managing a macOS-first fleet.</p></li><li><p style="min-height:1.5em">Working knowledge of JML processes — you understand why a 24-hour offboarding window is a security risk, not just an IT inconvenience.</p></li><li><p style="min-height:1.5em">Comfortable with scripting or automation (Bash, Python, or similar) to reduce manual toil.</p></li><li><p style="min-height:1.5em">Async-first communicator: you document decisions, write clear runbooks, and don’t let tasks die in DMs.</p></li></ul><h3><strong>Nice to Have</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Experience with FIDO2/WebAuthn deployment or hardware security key programs (YubiKey 5 series).</p></li><li><p style="min-height:1.5em">Familiarity with Slack enterprise grid administration including app governance and Connect channel management.</p></li><li><p style="min-height:1.5em">Exposure to SOC 2 or ISO 27001 evidence collection for identity and endpoint controls.</p></li><li><p style="min-height:1.5em">Experience managing IT operations across APAC and Americas time zones simultaneously.</p></li><li><p style="min-height:1.5em">Familiarity with Google Workspace admin, including directory sync and group-based provisioning.</p></li><li><p style="min-height:1.5em">Prior work in a security-adjacent IT role where identity hygiene and access control were first-class concerns.</p></li></ul><h3><strong>What We’re Not Looking For</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em">A ticket-taker who waits for requests. We expect you to proactively find and close gaps — stale accounts, unmanaged devices, ungoverned app integrations.</p></li><li><p style="min-height:1.5em">Someone who treats IT and security as separate disciplines. Every identity and endpoint decision here is a security decision.</p></li><li><p style="min-height:1.5em">A process follower who can’t write automation. If you’re doing the same task manually for the third time, that’s a bug.</p></li></ul><h3><strong>What We Offer</strong></h3><ul style="min-height:1.5em"><li><p style="min-height:1.5em"><strong>Fully Remote</strong></p><p style="min-height:1.5em">We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.</p></li><li><p style="min-height:1.5em"><strong>ESOP</strong></p><p style="min-height:1.5em">Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.</p></li><li><p style="min-height:1.5em"><strong>Tech Allowance</strong></p><p style="min-height:1.5em">Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.</p></li><li><p style="min-height:1.5em"><strong>Health Benefits</strong></p><p style="min-height:1.5em">Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.</p></li><li><p style="min-height:1.5em"><strong>Annual Off-Sites</strong></p><p style="min-height:1.5em">Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.</p></li><li><p style="min-height:1.5em"><strong>Flexible Work</strong></p><p style="min-height:1.5em">We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.</p></li><li><p style="min-height:1.5em"><strong>Professional Development</strong></p><p style="min-height:1.5em">Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.</p><p style="min-height:1.5em"></p></li></ul><h3><strong>About the Team</strong></h3><p style="min-height:1.5em">Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">280+ team members</p></li><li><p style="min-height:1.5em">55+ countries</p></li><li><p style="min-height:1.5em">20+ languages spoken</p></li><li><p style="min-height:1.5em">$500M raised</p></li><li><p style="min-height:1.5em">500,000+ community members</p></li></ul><p style="min-height:1.5em">We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.</p><p style="min-height:1.5em"></p><h3><strong>Hiring Process</strong></h3><p style="min-height:1.5em">We keep things simple, async-friendly, and respectful of your time:</p><ol style="min-height:1.5em"><li><p style="min-height:1.5em">Apply – Our team will review your application.</p></li><li><p style="min-height:1.5em">Intro Call – A short video chat to get to know each other.</p></li><li><p style="min-height:1.5em">Interviews – Up to four calls with:</p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Team Leads</p></li><li><p style="min-height:1.5em">Future teammates</p></li><li><p style="min-height:1.5em">Someone cross-functional from product, growth, or engineering (depending on the role)</p></li><li><p style="min-height:1.5em">Someone from our leadership/founding team</p></li></ul></li><li><p style="min-height:1.5em">Decision – We may follow up with a final question or go straight to offer.</p></li></ol><p style="min-height:1.5em">All communication is remote and we aim to move fast.</p>