Back to jobs
New

Systems Administrator

United States

Location: This role would be hybrid as needed within the United States.

The role.

We are hiring an experienced Systems Administrator to join our globally distributed Systems Administration team as its US-based member. You will report to, and work day to day with, the Associate Director, Systems Administration in the UK, and work alongside our Systems Administrator in Colombia and the IT Support team across the Americas.

You will own the day-to-day health of the systems every employee relies on — identity, email security, device management and office networking — act as the escalation point for the Support team during US hours, and carry infrastructure projects from request to completion. This is a generalist role with real depth in identity and email: you will spend more time in Okta, Google Admin and Mimecast than in cloud consoles.

What you will be doing.

  • Administer Okta: SAML, OIDC and SCIM application integrations, group rules driven by our HR system, lifecycle and session policies, Okta Workflows, and the troubleshooting that follows an HRprofile change.
  • Administer Google Workspace at admin-API depth: users, organizational units, shared drives, groups and distribution lists, Gmail routing and spam settings, Drive sharing policy, and scripted changes through GAM or the Directory API.
  • Administer email security in Mimecast: impersonation, spam, URL and attachment policies; permitted-sender hygiene; SPF, DKIM and DMARC for our domains.
  • Manage the endpoint fleet with our MDM platforms — Iru (formerly Kandji) for macOS and Kaseya VSA X for Windows — including Apple Business Manager enrollment, patch and compliance policy, and endpoint privilege management (Delinea).
  • Administer our SASE client (Cato) and office networking on Cisco Meraki: SSIDs, VLANs, uplinks and failover, firmware, and coordination with ISPs and facilities. The New York office is yours in person.
  • Act as IT's operational contact for our security providers (Sophos MDR, eSentire SOC, Tenable vulnerability scanning): alert follow-up, device hygiene and evidence for client security questionnaires with our Risk and Compliance team.
  • Be the escalation point for the IT Support team in the Americas on identity, Google Workspace, MDM and network issues, and turn recurring escalations into documented procedures Support can run.
  • Take part in integration and consolidation projects across acquired companies: Google Workspace tenant and domain moves, mail-flow cutover, mailbox archive imports, Slack and Box consolidation, and device re-enrollment.
  • Run the quarterly access audits with the team: export users from our systems, reconcile against the HR roster and asset inventory (Asset Panda), route removals for approval and keep the evidence trail.
  • Provision and support our SaaS estate through Okta groups and just-in-time provisioning —Adobe, Figma, Box, Miro, Zoom, Smartsheet, Coda and our AI tools (Claude Enterprise, Gemini) — and keep routing and approval notes current.
  • Manage IT's slice of cloud: Route 53 DNS, a small number of AWS resources, and Google Cloud project administration and IAM grants.
  • Automate recurring work in Python, Bash or Google Apps Script against vendor APIs, under team-owned service identities, with the code kept in our shared repository.
  • Support onboarding and offboarding from the infrastructure side: account activation, group and app assignment, device shipping and returns, and the offboarding checklist across every system.
  • Maintain the team's knowledge base: runbooks, procedures and vendor contacts, updated as you go.

What we like to see.

  • 5 or more years in systems administration or a comparable infrastructure role in a distributed, multi-office company. Role is scoped to grow into a Senior position. 
  • Deep, hands-on Okta administration beyond SSO: group rules, SCIM provisioning, attribute mappings from an HR source, Workflows, session and authenticator policy. Equivalent depth in Entra ID or OneLogin considered.
  • Google Workspace administration; comfort with GAM or the Admin SDK is a strong plus. Microsoft 365 administration is useful but secondary here.
  • Working knowledge of email authentication and filtering: SPF, DKIM, DMARC, and a secure email gateway such as Mimecast or Proofpoint.
  • Experience with an Apple MDM (Iru/Kandji, Jamf, Mosyle) and a Windows RMM or MDM (Kaseya, Intune).
  • Networking fundamentals — DNS, DHCP, VLANs, VPN, WAN failover — and comfort in a cloud-managed network dashboard such as Meraki.
  • Scripting to remove repetitive work: Python, Bash or Apps Script against REST APIs.
  • Project-level ownership: Creates tasks, executes them end to end, and drives cross-functional projects — acquisition integrations, access audits, platform consolidations — without hand-holding.
  • Working knowledge of at least one cloud IAM model (AWS or Google Cloud).
  • Strong documentation habits and clear written communication with a manager in another time zone.
  • Calm under escalation, self-directed, and comfortable owning a problem end to end.

This role is currently not available for hire or work in New Mexico, and Hawaii, USA.

About Huge.

Huge is an independent, human-first AI-native design and technology company. We make things that matter by bringing AI, people, design and technology together as one system. With more than 1,000 design and technology experts working in hub cities around the world, including Bogotá, Chicago, Ho Chi Minh City, London, Los Angeles, Medellín, New York, San Francisco, and Washington, DC, we partner with some of the world’s most ambitious brands, including Google, NBCU, PepsiCo, Vail Resorts, Atlantic Health, and Candescent. Learn more at hugeinc.com.

Huge is committed to creating an inclusive employee experience for all. Regardless of race, gender, religion, sexual orientation, age, disability, or if you’re parenting the next generation of innovators, we firmly believe that our work is at its best when everyone feels free to be their most authentic self.

Huge is an equal opportunity employer (EOE). We strongly support diversity in the workforce. We are committed to an inclusive, barrier-free recruitment and selection process and work environment. If you are contacted for a job opportunity, please advise us of any accommodation needed to ensure you have access to a fair and equitable process. Any information received relating to accommodation will be addressed confidentially.

Workers shall not be required to pay employers’ or agents’ recruitment fees or other related fees for their employment. If any such fees are found to have been paid by workers, such fees shall be repaid to the worker.

The salary range for this position is as listed below. Exactly where a prospective employee will be paid within this range will depend on, among other factors, the actual salary ranges for current and former employees who are either currently filling a similar role or did in the past; the candidate’s depth of experience and qualifications; the level of specialization the role requires; budgetary considerations; the market demand for that role and the local market conditions that exist where the employee will be based. For current Huge employees, tenure will also be a consideration.

Wage Disclosure

$70,000 - $90,000 USD

Create a Job Alert

Interested in building your career at HugeInc? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

Before submitting this application you must agree to Huge's Privacy Notice, Terms of Use, and California Privacy Notice (as applicable).

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in HugeInc’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...