IT Ops Engineer

F2Onsite

Dublin (CA)

On-site

USD 115,000 - 135,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity compensation
Flexible Time Off
Medical, dental, and vision coverage
Disability and life insurance

Job summary

F2OnSite is seeking a senior IT professional to own endpoint engineering across Windows, macOS, and Linux, with hands-on security, identity, and workplace technology leadership. You will manage Intune enrollment, Entra ID, Kandji/Jamf/Mosyle, and support executive events from a technical perspective.

The role requires deep experience with Okta, Google Workspace, AWS, Jira/Confluence, and strong scripting abilities in PowerShell, Bash, and Python. Onsite presence in Dublin, CA is required.

Qualifications

  • 7+ years of IT systems engineering and enterprise IT support experience.
  • Hands-on depth across macOS and Windows environments.
  • MDM platform experience (Kandji/Jamf/Mosyle).
  • Okta administration with SSO, SCIM, MFA, and lifecycle automation.
  • Proficiency with Google Workspace, Microsoft 365, Jira, and Confluence.

Responsibilities

  • Own endpoint health, security, and lifecycle for Windows, macOS, and Linux.
  • Administer Okta identity, SSO, SCIM provisioning and lifecycle automation.
  • Lead SOC 2 related activities, evidence gathering and control testing.
  • Provide senior level escalation for complex endpoint issues.
  • Configure and support AV for live events and hybrid meetings.
  • Automate IT processes using PowerShell, Bash, and Python.
  • Coordinate with cross functional teams; maintain documentation and runbooks.
  • Oversee ITSM ticketing, SLAs, and change management.

Skills

macOS
Windows
Intune
Entra ID
Okta
PowerShell
Bash
Python
Jira
Confluence
AV/Live events
SOC 2
MDM automations
Customer-facing
Scripting

Tools

Kandji
Jamf
Mosyle
Google Workspace
Microsoft 365
Jira
Confluence
AWS
PagerDuty
OBS
vMix
Wirecast
ATEM Mini

Job description

Job Description

Job Description:
About the Role We're looking for an experienced, highly hands-on IT professional who can operate across enterprise endpoint engineering, identity and security, partner-facing technical support, AV/media production, and physical IT infrastructure. This is not a traditional service desk position or a role focused on a single operating system. You'll take meaningful ownership of both our Windows and macOS environments while helping run the systems, security controls, workplace technology, and operational processes that keep the company moving. You'll also serve as a senior technical resource when complex internal or partner-facing issues arise. The right person is equally comfortable troubleshooting an Intune compliance issue, configuring Okta lifecycle automation, helping a partner isolate a technical problem, supporting an executive live event, or improving an operational process with PowerShell, Bash, or Python. This position is based in our Dublin, California office and requires a significant onsite presence. What You’ll Own Endpoint & Workplace Engineering — Windows, macOS and Linux You'll be responsible for the health, security, usability, and lifecycle of our employee endpoint environment across both major desktop platforms. Take end-to-end ownership of the Windows fleet, including Intune and Entra ID enrollment, Autopilot provisioning, configuration and compliance policies, Windows Update rings, BitLocker, and Defender for Endpoint. Manage the macOS fleet from enrollment through retirement using Kandji, including zero-touch Automated Device Enrollment, Blueprints, Platform SSO, FileVault key escrow, Gatekeeper and XProtect posture, and major macOS upgrade cycles. Create a consistent experience across Windows and macOS by maintaining a common security baseline, patch SLA, application catalog, onboarding process, and overall employee experience. Support the company’s smaller Linux endpoint footprint used by engineering, including baseline hardening, disk encryption, and patching. Package, validate, and deploy applications across both primary endpoint environments while maintaining an effective self‑service software catalog. Operate as the senior‑most endpoint escalation point and resolve technical issues that cannot be closed by the service desk. Manage the complete IT asset lifecycle, beginning with procurement and continuing through deployment, BYOD enrollment, offboarding wipes, and certified data destruction. Automate endpoint administration through PowerShell, Bash, Python, MDM APIs, and identity APIs. The goal is to remove unnecessary manual work rather than simply write instructions for repeating it. Deliver hands‑on, white‑glove technical support to employees and executive staff across platforms. Security Operations, Compliance & Physical Security You’ll help connect identity, endpoint, network, compliance, and physical access into a cohesive security program. Administer Okta identity and access management, including SSO, SCIM provisioning, phishing‑resistant MFA, application assignments, automated lifecycle processes, and access‑review evidence. Deploy and administer enterprise platforms including Google Workspace, Microsoft 365, AWS, Jira, and Confluence. Own the technical onboarding and offboarding process from start to finish, covering user accounts, group memberships, assigned devices, badge access, and same‑day access revocation when someone leaves. Apply least‑privilege practices across enterprise systems, conduct periodic access reviews, and eliminate unnecessary standing privilege. Investigate endpoint and identity alerts involving phishing, malware, suspected account compromise, and similar events, escalating to Information Security according to the incident response plan. Own IT’s responsibilities within SOC 2, including evidence gathering, control testing, ticket and change records, and audit walkthroughs involving endpoint, identity, and physical security controls. Maintain current security‑control documentation, policies, and procedures mapped to SOC 2 requirements, including accurate ownership information. Maintain corporate network security controls including VPN and ZTNA access, 802.1X, DNS filtering, firewall rules, and segmentation of guest and IoT environments. Operate physical building‑security technologies including electronic locks, access‑control systems, badge administration, visitor tracking, video surveillance, and camera‑retention practices aligned with company policy. Keep physical and logical access changes synchronized so that provisioning and revocation occur from the same trigger and on the same day. Ensure consumer and partner information is handled only through approved systems and immediately elevate any suspected data exposure. Forward‑Deployed Partner Technical Support A portion of this position is externally facing. You’ll work alongside Partner Success, Support, and Implementation as the technical resource for questions and issues raised by bank and credit union partners. Triage, reproduce, investigate, and resolve inbound technical questions from partners as an embedded technical resource. Translate partner‑reported symptoms into reproducible technical findings that Engineering can act on, including relevant logs, environment details, and a clear reproduction path. Participate directly in partner calls and communicate root cause, remediation steps, and expected timelines in terms that non‑technical stakeholders can understand and act on. Retain ownership of an issue through confirmed resolution instead of simply transferring it to another team. Turn repeat issues into internal troubleshooting runbooks and partner‑facing FAQ material, while advocating for technical fixes that reduce future ticket volume. Handle partner and consumer information exclusively within approved systems and in accordance with GLBA and FCRA obligations. This position does not make or automate lending, credit, or eligibility decisions. AV & Media Production You’ll also own and improve the workplace technology that supports meetings, media, and company communications. Design and configure AV environments including conference rooms, digital signage, and live‑event production setups. Support and optimize Zoom, Microsoft Teams, and Webex for reliable hybrid meetings. Operate and maintain professional cameras, lighting equipment, and audio systems. Manage video post‑production workflows using tools such as Adobe Premiere and DaVinci Resolve. Support podcast production using platforms such as Audition, Audacity, and Pro Tools. Administer cloud‑based media storage and establish AV standards that produce consistent quality. Introduce AI‑enabled improvements where appropriate, including automated media processing and real‑time captioning. Live Event Operations When an important meeting or production is happening, you’ll help make sure the technology disappears into the background. Provide live IT and AV support for company meetings, webinars, executive presentations, and hybrid events. Diagnose and resolve technical or AV issues in real time during critical operations and productions. Maintain high‑quality streaming and broadcasting for executive and company‑wide events. IT Service Management Strong technology matters, but so does the operating discipline behind it. Manage IT ticketing and service desk operations with an emphasis on prompt, accountable issue resolution. Define, maintain, and enforce SLAs for support and infrastructure services. Measure and report IT performance, including resolution times, system availability, and user satisfaction. Apply ITIL practices across incident, problem, and change management. Participate in the technical support on‑call rotation, including after‑hours coverage for security incidents, outages, live productions, and other critical events. Facilities & Physical IT Infrastructure Some parts of this role require getting out from behind the keyboard. Maintain environmental monitoring for network closets and server rooms, including temperature, humidity, and power conditions. Coordinate with facilities vendors on IT‑related infrastructure such as HVAC, electrical power, and structured cabling. Maintain UPS equipment, backup power systems, and other critical infrastructure. Manage physical IT infrastructure such as network distribution, server racks, and cable management. Documentation, Automation & Technical Leadership You’ll be expected to leave systems and processes better than you found them. Build and maintain system diagrams, SOPs, runbooks, knowledge‑base articles, and other IT documentation. Develop and present Lunch & Learn sessions covering technology tools, security practices, and emerging technologies. Automate repetitive operational work and document those automations well enough that others can confidently operate them. Establish technical standards for the IT function. Mentor junior IT team members in endpoint management, identity, and security practices. Project Management & Cross‑Functional Coordination You’ll own projects as well as systems. Lead IT initiatives involving new system implementations, infrastructure improvements, and technology deployments. Create project plans covering timelines, dependencies, staffing or resource requirements, and risk‑mitigation strategies. Monitor project execution using tools such as Jira and Asana and provide regular status reporting. Maintain project artifacts including requirements, technical designs, test plans, and deployment documentation. Coordinate user acceptance testing and end‑user training for newly deployed systems. Manage timelines and deliverables for projects involving outside vendors. Required Experience & Qualifications This is a senior, broad‑scope role. We’re looking for someone who has substantial hands‑on experience across the technologies they’ll be responsible for. 7+ years of experience across IT systems engineering, enterprise IT support, cloud administration, AV system design, or a combination of these areas. Genuine hands‑on depth across both macOS and Windows enterprise environments. At least three years managing a macOS fleet at scale using an MDM platform such as Kandji, Jamf, or Mosyle. At least three years managing a Windows fleet with Intune and Entra ID. Deep expertise in one operating system paired with only basic familiarity in the other will not be sufficient for this position. Hands‑on Okta administration experience encompassing SSO, SCIM provisioning, MFA policies, and lifecycle automation—not simply experience using Okta as an employee. Proficiency with enterprise platforms including Google Workspace, Microsoft 365, Jira, Confluence, AWS, Kandji, Intune, and PagerDuty. Experience administering networks and applying security best practices involving VPNs, firewalls, and endpoint protection. Experience managing physical security systems such as building access controls and video surveillance. Participation in at least one complete SOC 2 audit cycle as either a control owner or evidence provider. Demonstrated success in a customer‑ or partner‑facing technical position such as support engineering, solutions engineering, implementation, or forward‑deployed engineering. Ability to confidently conduct technical conversations with partner or customer stakeholders. Working proficiency with PowerShell, Bash, and Python for scripting and automation. Hands‑on video production, camera‑operation, and editing experience using tools such as Adobe Premiere, Final Cut Pro, or DaVinci Resolve. Podcast‑production experience, including multi‑track editing and publishing. Familiarity with video conferencing and live‑streaming technologies including OBS, vMix, Wirecast, and ATEM Mini. Experience establishing technical standards and mentoring less‑senior IT professionals. Strong analytical and problem‑solving ability, including the judgment required to operate independently and exercise appropriate discretion. Excellent communication skills and the ability to collaborate effectively across departments. Preferred Background The following experience is helpful but not required: Experience in fintech, lending, financial services, or another regulated environment involving FCRA, GLBA, SOC 2, or comparable compliance obligations. Experience managing a smaller Linux endpoint environment. Familiarity with Zero Trust Network Access and device‑posture‑driven conditional access. Certifications such as Okta Certified Administrator, Microsoft 365 Certified Endpoint Administrator Associate, Apple Certified Support Professional, CompTIA Security+, or ITIL Foundation. A bachelor's degree in a relevant discipline or a compelling equivalent built through self‑directed learning and professional experience. How Success Will Be Evaluated This role has tangible operational outcomes. Performance will be measured in areas including: Endpoint compliance: The percentage of Windows and macOS endpoints that meet established security baselines and patch SLAs. IT responsiveness: Resolution time by severity compared with published service‑level commitments. SOC 2 preparedness: IT‑owned controls have current evidence available when requested, with zero audit findings resulting from those controls. Partner issue resolution: Time between receipt of an inbound technical inquiry and confirmed resolution, along with a measurable reduction in repeat partner inquiries. Live‑event reliability: Executive presentations and company‑wide events are delivered without AV or IT interruptions. Onboarding and offboarding accuracy: New employees have the access they require on day one, while departing employees have both logical and physical access fully revoked on their departure date. Location, Travel & On‑Call Expectations Location: This position is onsite at our Dublin, California office a minimum of three days per week, although four to five onsite days are strongly preferred. The onsite requirement is meaningful: conference‑room AV, physical security systems, network closets, and portions of the physical infrastructure cannot be managed remotely. Travel: Approximately 5% travel, primarily for conferences. This position does not require travel to partner locations. On‑call: Participation in the technical support rotation is required. This includes after‑hours availability when necessary for outages, security incidents, live events, and executive presentations. Background check: A background check is required, consistent with standard practices in regulated financial services. Compensation The annual base salary for this position is between $115,000.00 and $135,00000, depending upon experience. Additional Benefits In addition to base compensation, we provide: Equity compensation package. Flexible Time Off (FTO), allowing employees to take the time they need to rest and recharge. Medical, dental, and vision coverage with 100% of the employee premium paid. Disability and life insurance. Opportunities for continued learning and career advancement with a top Bay Area technology company.

Company Description

F2OnSite is the fastest growing IT field services company in the United States, with hundreds of employee technicians in over 40 states. F2 OnSite performs service on computers, printers, point of sale systems, servers and other hardware technologies - including installations, migrations, deployments and break/fix. Learn more at F2onsite.com. WHAT WE DO: Our focus is Hardware: Desktops, Laptops, Servers, Printers, POS systems, and LCDs. We have hundreds of team members across the US who work Onsite at customer locations - providing hardware break/fix services, migrate data, install computers, move printers, install/fix servers and POS systems. We close thousands of service calls each week, and do whatever it takes to get our customers up and running again. We specialize in all types of technology, projects, desktop support and more.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Desktop Support Technician - Part Time
Desktop Support Technician - Part Time

F2Onsite • Town of Texas (WI)

On-site
USD 18,000 - 28,000
Level 2 Desktop Support Technician
Level 2 Desktop Support Technician

F2Onsite • Virginia (IL)

On-site
USD 42,000 - 60,000
Senior IT Ops Engineer - Endpoints, Security & AV (Onsite)
Senior IT Ops Engineer - Endpoints, Security & AV (Onsite)

F2Onsite • Dublin (CA)

On-site
USD 115,000 - 135,000
Equity compensation
Flexible Time Off
Medical, dental, and vision coverage
+1
Systems Engineer I
Systems Engineer I

T2 Tech Group • Costa Mesa (CA)

On-site
USD 90,000 - 120,000
Remote Technical Support Engineer II
Remote Technical Support Engineer II

FusionTek • Northern (KY)

Hybrid
USD 41,000 - 48,000
Competitive salary
Quarterly bonus up to 4%
Medical, Dental, Vision
+5
IT Engineer
IT Engineer

Panthalassa • Portland (OR)

On-site
USD 120,000 - 160,000
Flexible paid time off
100% health insurance
Equity in the company
+1
Technical Support Engineer II - Hybrid (DC)
Technical Support Engineer II - Hybrid (DC)

FusionTek • Washington

Hybrid
USD 41,000 - 48,000
Competitive salary
Quarterly bonus eligibility
Must reside in DC metro area
+6
Technical Support Engineer II - Hybrid (Tampa) FusionTek · $62k – $73k Middle 7h ago
Technical Support Engineer II - Hybrid (Tampa) FusionTek · $62k – $73k Middle 7h ago

Remote Genie • Tampa (FL), Northern (KY)

Hybrid
USD 41,000 - 48,000
Medical, Dental, and Vision
401(k) with 4% company matching
Generous PTO and holidays
+4
Systems Engineer I
Systems Engineer I

T2 Group • Redondo Beach (CA)

On-site
USD 70,000 - 95,000
Remote Technical Support Engineer II FusionTek · $62k – $73k Middle 7h ago
Remote Technical Support Engineer II FusionTek · $62k – $73k Middle 7h ago

Remote Genie • Northern (KY)

Hybrid
USD 41,000 - 48,000
Competitive salary
Quarterly bonus eligibility
Medical, Dental, Vision
+5