Kaizenlabs
IT Operations Manager (Contract)
New York, NY
Apply through hirly
hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.
hirly's read of this role
- Role family
- Operations
- Seniority
- Lead / management
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 1 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services.
Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service.
Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year.
Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back.
The Role
Kaizen builds software for federal and local government. We are roughly ~40 people on a cloud-first, mostly macOS stack, and we sell into customers who impose real requirements on how we run our own corporate systems.
IT here is currently distributed across engineers and operators who all have other full-time jobs. It works, in the sense that people can log in. Selling into government means holding a higher bar on identity, devices and access than a side-of-desk model can sustain, so we are building the layer properly. This engagement does that and leaves behind something that runs without you.
Hands-on build work: deploying tools, writing policy, and cleaning up account sprawl rather than advising on it.
What You'd Own
Identity. We are partway through consolidating everything behind a single identity provider and the tail is where the value is: the applications nobody wanted to touch, the provisioning that still happens by hand, and the lifecycle rules that turn it into a system. You would finish it and then own it, including automated provisioning and deprovisioning.
Endpoints. Device management is a program you would stand up rather than one you would inherit. Our government customers set requirements on the devices used for their work, and this role owns meeting those requirements and evidencing them. You would select the tool, deploy it across the fleet, and write the policy that goes with it. This is the largest single deliverable in the engagement.
Employee lifecycle. Joiner, mover, leaver. Today both are documented processes rather than instrumented ones. You would turn them into a system with timing, an audit trail, and named owners, including credential and hardware return. One design constraint: some of our contracts specify tight windows for disabling access when someone departs, so the leaver path has to be built against a clock and produce evidence that it met it.
Access reviews. A recurring review of who has access to what, on a cadence, producing evidence rather than a screenshot. Our auditors and our government customers both ask for this, and you would own the cadence and the trail.
A scoped enclave. Some of our government work involves controlled information with handling requirements that do not apply to the rest of the business. You would stand up a separate, deliberately narrow environment for it, with its own identity, managed devices, controlled storage and a documented boundary, then write the runbook that keeps the scope from drifting. Keeping that boundary narrow over time is harder than building it.
The SaaS estate. Inventory, owners, renewal dates, who has admin, and what data sits where. Right now that knowledge is in people's heads.
Deliverables
What we expect to have in hand at each stage.
Weeks 1 to 4
A complete inventory of devices, applications, and accounts, each mapped to a named human and reconciled against current employment status
The identity provider rollout finished across the remaining applications, with the queued work closed out
A written joiner, mover and leaver process with the revocation step timed and evidenced
Weeks 5 to 12
Endpoint management selected, purchased and deployed across the fleet, with a device and acceptable-use policy that lets us evidence the software restrictions our contracts carry
A quarterly access review established, in a format an assessor will accept
Offboarding automated end to end, including credential and physical asset return with written confirmation
SaaS estate rationalized: inventory, owner, renewal date, admin list, and data posture for each
Months 3 to 6
Privileged access separated from standard access and documented
Identity and access evidence flowing to our compliance program on a schedule
The scoped enclave stood up and documented, with a defined user list and a boundary that holds
Readiness for certificate and smart-card based authentication, which some of our government work will require
Runbooks good enough that the program survives the end of this engagement
What You'll Bring
You have owned a modern identity provider, Okta, Entra or JumpCloud, as the administrator rather than a user. App onboarding, SCIM provisioning, lifecycle rules, and the unglamorous work of chasing down the last twelve applications
You have deployed endpoint management from zero across a real fleet. Jamf, Kandji, Hexnode or Intune. You know what breaks when you do this to people who have never had a managed device, and you have a plan for that conversation
You have paired endpoint management with an EDR tool and can speak to both halves. CrowdStrike, Huntress or similar
You have built a joiner, mover and leaver process that produced an audit trail, not a checklist someone remembers to open
You have run an access review that an auditor accepted. You know the difference between a spreadsheet and evidence
You are fluent in a cloud-first, mostly macOS environment: Google Workspace, a password manager, AWS console access, SSO everywhere
You write runbooks other people can follow. This engagement is judged partly on what still works after it ends
You are comfortable as the only IT person, with an engineering team who will help you but does not report to you
US person
Strong Candidates May Also
Have taken a company through SOC 2, FedRAMP or CMMC on the IT side and know exactly which access and device artifacts the assessor asks for. This is the single most valuable thing on this list and it moves our rate
Know certificate and smart-card authentication, PIV or CAC, and government PKI
Have handled device, software or account restrictions that flowed down from a government contract
Have come out of a managed service provider and want to build in-house instead of firefighting across twenty clients
Have done exactly this as a contract engagement before and can describe what made it work or fail
Scope of Work
Product engineering and our government hosting environments stay with employees. You would own corporate identity and corporate devices, not the production or federal environments. Security architecture decisions sit with our engineering lead; you would implement and operate.
Don't Apply If...
Your background is ticket triage and password resets. This engagement designs and builds systems, and there is no queue to work
You need an established stack and a documented environment to step into. Neither exists yet, and building them is the job
Your experience is Windows and on-premise Active Directory. It does not transfer cleanly to where we are
You want a retainer to advise. We need someone who buys the tool and deploys it
You would rather grow a team than do the work yourself. There is no team, and there will not be one during this engagement
What Kaizen Offers
Health & Insurance
100% coverage across the board: medical through Oxford/Unite
Is this role actually a fit for you?
hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.
Score it against my resume