{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/lifecycle-automation"},"x-facet":{"type":"skill","slug":"lifecycle-automation","display":"Lifecycle Automation","count":2},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_1e275c7d-4a3"},"title":"Staff Systems Engineer, Identity","description":"<p>As a Staff Systems Engineer, Identity, you will serve as the primary technical owner of CoreWeave&#39;s enterprise identity ecosystem, with a focus on Okta and Opal. You will design, build, and operate identity lifecycle systems that are secure, automated, and scalable.</p>\n<p>This is a highly visible, high-impact role where identity sits at the center of security. You will define how access is granted, changed, and removed across the organization, enabling business velocity while enforcing least privilege and strong governance.</p>\n<p>Key responsibilities include:</p>\n<p><strong>Design and scale enterprise identity architecture that minimizes access sprawl and enforces least privilege</strong></p>\n<p><strong>Own and improve Joiner, Mover, and Leaver (JML) lifecycle processes across all critical systems</strong></p>\n<p><strong>Build and operate identity governance and administration (IGA) capabilities including birthright access models, role-based access control (RBAC), approval workflows and policy enforcement, access reviews and certification processes</strong></p>\n<p><strong>Administer and enhance Okta capabilities (SSO, MFA, adaptive policies, lifecycle management, SCIM, integrations)</strong></p>\n<p><strong>Build and scale access request workflows in Opal and integrated systems</strong></p>\n<p><strong>Integrate new applications into the identity ecosystem (SAML, OIDC, SCIM, role mapping)</strong></p>\n<p><strong>Develop automation and infrastructure-as-code to improve reliability and reduce manual effort</strong></p>\n<p><strong>Partner with Security to strengthen identity as a core control plane (Zero Trust, authentication, authorization)</strong></p>\n<p><strong>Align identity systems with PeopleOps and organizational changes</strong></p>\n<p><strong>Monitor and improve identity system health, observability, and performance</strong></p>\n<p><strong>Troubleshoot complex authentication, provisioning, and authorization issues</strong></p>\n<p><strong>Maintain documentation, runbooks, and architectural standards</strong></p>\n<p><strong>Serve as an escalation point for identity-related incidents</strong></p>\n<p><strong>Drive continuous improvement in identity architecture, governance, and user experience</strong></p>\n<p>Requirements include:</p>\n<p><strong>7–10+ years of experience in IT systems engineering, identity engineering, or systems architecture</strong></p>\n<p><strong>Deep hands-on experience with Okta in a complex enterprise environment</strong></p>\n<p><strong>Strong expertise in identity and access concepts (SSO, MFA, SAML, OAuth, OIDC, SCIM, RBAC, Zero Trust)</strong></p>\n<p><strong>Proven experience designing lifecycle automation (JML) and access governance frameworks</strong></p>\n<p><strong>Experience with IGA or access request platforms such as Opal</strong></p>\n<p><strong>Strong automation and infrastructure-as-code experience (Terraform, APIs, Python/PowerShell/Golang)</strong></p>\n<p><strong>Ability to integrate enterprise applications into centralized identity platforms</strong></p>\n<p><strong>Strong troubleshooting skills across identity, federation, and provisioning systems</strong></p>\n<p><strong>Excellent communication skills with the ability to influence cross-functional stakeholders</strong></p>\n<p>Preferred qualifications include familiarity with Active Directory, Entra ID, HRIS systems, and SaaS ecosystems, experience building identity observability and reporting, and relevant certifications (Okta, cloud, or security).</p>\n<p>Why CoreWeave?</p>\n<p>At CoreWeave, we work hard, have fun, and move fast! We&#39;re in an exciting stage of hyper-growth that you will not want to miss out on. We&#39;re not afraid of a little chaos, and we&#39;re constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:</p>\n<p><strong>Be Curious at Your Core</strong></p>\n<p><strong>Act Like an Owner</strong></p>\n<p><strong>Empower Employees</strong></p>\n<p><strong>Deliver Best-in-Class Client Experiences</strong></p>\n<p><strong>Achieve More Together</strong></p>\n<p>Why This Role Matters</p>\n<p>Identity is one of the most critical control planes in a modern enterprise. In this role, you will define how secure access is managed across CoreWeave, ensuring identity remains a foundational pillar of security, compliance, and scale.</p>\n<p>The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).</p>\n<p>What We Offer</p>\n<p>The range we&#39;ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.</p>\n<p>In addition to a competitive salary, we offer a variety of benefits to support your needs, including medical, dental, and vision insurance, company-paid life insurance, voluntary supplemental life insurance, short and long-term disability insurance, flexible spending account, health savings account, tuition reimbursement, ability to participate in employee stock purchase program (ESPP), mental wellness benefits through Spring Health, family-forming support provided by Carrot, paid parental leave, flexible, full-service childcare support with Kinside, 401(k) with a generous employer match, flexible PTO, catered lunch each day in our office and data center locations, a casual work environment, and a work culture focused on innovative disruption.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_1e275c7d-4a3","directApply":true,"hiringOrganization":{"@type":"Organization","name":"CoreWeave","sameAs":"https://www.coreweave.com","logo":"https://logos.yubhub.co/coreweave.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coreweave/jobs/4668575006","x-work-arrangement":"hybrid","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"Base salary range: $188,000 to $275,000","x-skills-required":["Okta","Opal","identity lifecycle systems","security","automation","infrastructure-as-code","Terraform","APIs","Python","PowerShell","Golang","identity and access concepts","SSO","MFA","SAML","OAuth","OIDC","SCIM","RBAC","Zero Trust","lifecycle automation","access governance frameworks","IGA","access request platforms","SaaS ecosystems","Active Directory","Entra ID","HRIS systems"],"x-skills-preferred":["identity observability and reporting","relevant certifications","cloud"],"datePosted":"2026-04-18T15:48:46.456Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Livingston, NJ / New York, NY / Sunnyvale, CA /Dallas, TX"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Okta, Opal, identity lifecycle systems, security, automation, infrastructure-as-code, Terraform, APIs, Python, PowerShell, Golang, identity and access concepts, SSO, MFA, SAML, OAuth, OIDC, SCIM, RBAC, Zero Trust, lifecycle automation, access governance frameworks, IGA, access request platforms, SaaS ecosystems, Active Directory, Entra ID, HRIS systems, identity observability and reporting, relevant certifications, cloud","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":188000,"maxValue":275000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_1e9bd843-ca4"},"title":"Global Head of IT","description":"<p>About the Role</p>\n<p>KoBold&#39;s IT function supports a globally distributed team of ~280 geoscientists, data scientists, and engineers working across North America, Zambia, the DRC, and field exploration sites around the world. As we scale, our IT needs are evolving rapidly,from reactive, break/fix helpdesk support toward proactive, automated IT operations that work seamlessly across geographies, including remote field sites with limited connectivity.</p>\n<p>In this role, you will own the full operational scope of Global IT. That means endpoint management, software procurement and renewals, identity and access administration, license optimization, vendor management, employee onboarding and offboarding, hardware lifecycle management, and IT training. You’ll lead a team of IT support staff, set technical direction, manage the annual software budget, and be the person who makes sure nothing falls through the cracks,renewals don’t expire, new hires have everything they need on day one, and the fleet is healthy and compliant.</p>\n<p>Responsibilities</p>\n<p>Endpoint Management &amp; Fleet Operations</p>\n<ul>\n<li>Own the Global IT roadmap, setting technical direction for endpoint management, fleet automation, and IT operations across all KoBold offices and field sites in 10+ countries</li>\n<li>Design and implement zero-touch provisioning and automated reimaging workflows for macOS (Jamf) and Windows (Intune) endpoints</li>\n<li>Build endpoint monitoring, alerting, and fleet health dashboards to shift IT from reactive to proactive support</li>\n<li>Drive device lifecycle management including EoL/EoS tracking, hardware refresh planning, and inventory management across Jamf, Intune, CrowdStrike, and related tooling</li>\n<li>Create self-service application deployment and access workflows to reduce helpdesk volume and empower employees</li>\n<li>Apply DevOps principles to IT operations: configuration-as-code (e.g. managing Intune policies via Terraform), infrastructure automation, version-controlled policies, and repeatable processes</li>\n<li>Own internet reliability and network performance at all global remote KoBold sites</li>\n</ul>\n<p>Software Procurement, Licensing &amp; Vendor Management</p>\n<ul>\n<li>Manage the full software procurement lifecycle: new purchases, renewals, expansions, and cancellations, ensuring user access is never disrupted by lapsed licenses or last-minute renewals</li>\n<li>Own and drive execution of the annual software budget, including process improvements year-over-year and proactive renewal pipeline visibility for legal and finance</li>\n<li>Optimize license utilization across the SaaS portfolio,track usage, right-size seat counts, consolidate redundant tools, and negotiate pricing with vendors</li>\n<li>Coordinate with legal on contract review, working within the existing procurement process to move quickly on low-risk purchases while ensuring appropriate review for larger spend</li>\n<li>Onboard new SaaS applications with proper Okta integration (SSO, SCIM) before launch, and manage decommissioning of deprecated tools</li>\n</ul>\n<p>Identity, Access &amp; Employee Lifecycle</p>\n<ul>\n<li>Own Okta administration including SSO integrations, SCIM provisioning, group management, access request workflows, and lifecycle automation</li>\n<li>Manage Google Workspace administration, including license management, security settings, and break-glass super-admin governance</li>\n<li>Build automation for minimal-touch employee onboarding and offboarding,ensuring new hires are fully provisioned on day one and departing employees are cleanly deprovisioned</li>\n<li>Support AI tooling rollout (Claude Desktop, Claude Code, and related tools) across the endpoint fleet, including deployment, configuration, and employee training</li>\n</ul>\n<p>Team Leadership &amp; Training</p>\n<ul>\n<li>Supervise and mentor IT support staff, providing technical coaching, priority-setting, performance management, and career development</li>\n<li>Develop and maintain IT training programs for new hires and ongoing employee enablement, including documentation, video walkthroughs, and live onboarding sessions</li>\n<li>Provide helpdesk backup on high-volume days, modeling the standard of responsiveness and quality you expect from the team</li>\n</ul>\n<p>Cross-Functional Collaboration</p>\n<ul>\n<li>Learn about mineral exploration by working closely with exploration teams, including time in the field in remote operations</li>\n<li>Collaborate with infrastructure engineering and security teams on cross-cutting initiatives including observability, access controls, endpoint security posture, and incident response</li>\n<li>Partner across the company to contribute to specification, vendor selection, and change management on new software requests</li>\n<li>Partner with finance on budget tracking, invoice approvals, and AFE submissions for software spend</li>\n<li>Work with legal to streamline the contract review pipeline, maintain lead times on renewals, and advocate for tiered review processes that match risk to effort</li>\n<li>Coordinate digitization efforts across the globe, ensuring consistent standards and tooling for converting physical records to digital archives at field and office sites</li>\n</ul>\n<p>Qualifications</p>\n<ul>\n<li>5+ years of experience in IT engineering, IT management, or a similar role combining hands-on technical depth with operational ownership</li>\n<li>Strong experience with MDM platforms, particularly Jamf (macOS) and Microsoft Intune (Windows), including policy configuration, automated enrollment, compliance enforcement</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_1e9bd843-ca4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"KoBold","sameAs":"https://www.kobold.com/","logo":"https://logos.yubhub.co/kobold.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/koboldmetals/jobs/4683079005","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["endpoint management","software procurement","identity and access administration","license optimization","vendor management","employee onboarding and offboarding","hardware lifecycle management","IT training","MDM platforms","Jamf","Microsoft Intune","policy configuration","automated enrollment","compliance enforcement","Okta administration","SSO integrations","SCIM provisioning","group management","access request workflows","lifecycle automation","Google Workspace administration","license management","security settings","break-glass super-admin governance","DevOps principles","configuration-as-code","infrastructure automation","version-controlled policies","repeatable processes"],"x-skills-preferred":[],"datePosted":"2026-04-17T12:41:36.369Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote - US"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"IT","industry":"Technology","skills":"endpoint management, software procurement, identity and access administration, license optimization, vendor management, employee onboarding and offboarding, hardware lifecycle management, IT training, MDM platforms, Jamf, Microsoft Intune, policy configuration, automated enrollment, compliance enforcement, Okta administration, SSO integrations, SCIM provisioning, group management, access request workflows, lifecycle automation, Google Workspace administration, license management, security settings, break-glass super-admin governance, DevOps principles, configuration-as-code, infrastructure automation, version-controlled policies, repeatable processes"}]}