DNSFilter

Director, IT

Tampa, Florida · Posted today

Opens boards.greenhouse.io

Get a version of your resume written for this job.

Salary
Not listed
Job type
Not specified
Work mode
Not specified
Source
Greenhouse (employer's hiring system)

Skills mentioned

SOC 2, Python, SaaS, Procurement

About the role

DNSFilter's mission is to protect our customers and partners with products they love to use! We are revolutionizing network security by providing fast, accurate, and reliable threat protection and content filtering. We're a rapidly growing company dedicated to creating a safer internet for businesses and organizations worldwide. Leveraging AI-driven threat intelligence, DNSFilter empowers our customers to proactively block threats before they impact their networks. We foster a collaborative, innovative, and results-oriented culture where every team member contributes to our mission of making the internet safer.

We are a security company, and how we run our own systems should reflect that. Our internal IT function has kept pace with a growing company through automation rather than headcount, and it is ready for someone to own it end to end. That's where you come in!

We are looking for a Director of IT, based in our Tampa office, to own internal identity, endpoints, and employee technology at DNSFilter. This is a hands-on leadership role, not an oversight role. You will run Okta, Google Workspace, and our MDM platforms yourself while leading one Senior IT Support Analyst, and you will be accountable for whether our controls actually work, not just whether they are configured. The ideal candidate has built an IT function at this stage before, is comfortable in the consoles, and would rather automate a recurring problem than staff it.

This role reports to the SVP of Operations and partners closely with Security, People, Finance, and every department that depends on getting access to their tools on day one.

This is a full-time hybrid-office role for our Tampa (Westchase), Florida office. 

Eligible candidates have worked successfully in a small- to mid-sized, fast-paced, hyper-growth SaaS start-up or scale-up.

We recognize that people come with a wealth of experience and talent beyond just the technical requirements of a job. If you feel like this job is for you, please apply. We believe diversity of experience and skills, including transferable skills, combined with passion, is a key to innovation and excellence; therefore, we encourage people from all backgrounds to apply to our positions!

In this role, you will:

Identity and Access

  • Own Okta day to day: user administration, SSO configuration, app assignments, MFA policy implementation, lifecycle rules, and Okta Desktop MFA across the fleet
  • Own Google Workspace administration, including groups, distribution lists, delegated access, and directory hygiene
  • Own the onboarding, offboarding, and change management lifecycle end to end, and be accountable for the number that says access was actually revoked on time
  • Partner with Security to define, and own the operation of, the access model for contractors and BYOD users, including what they can reach, how it is isolated from personal use, and how access and company data end when an engagement does
  • Reduce the volume of manual access requests through automation, group-based entitlements, and self-service, rather than by working the queue faster

Endpoint and Fleet

  • Own Mosyle for Apple and JumpCloud for everything else: enrollment, configuration profiles, app deployment, patch posture, and device inventory
  • Ensure every company device is enrolled through a supervised path, and close the gaps where it is not
  • Maintain accurate fleet coverage reporting, including whether our own machines run DNSFilter's Roaming Client under an enforcing policy
  • Support the Security team's rollout of endpoint security tooling on the devices you manage

Asset Lifecycle

  • Own hardware end to end: procurement through Insight and CDW, zero-touch enrollment and provisioning, asset tagging, drop-ship to employees, and return logistics
  • Redeploy returned devices under three years old before ordering new, and route anything three years or older to certified recycling
  • Maintain an accurate record of every deployed device that reconciles to headcount, MDM, and Finance's asset register
  • Manage warranty, repair, and replacement, and own the refresh cycle and the budget behind it
  • Own retirement: secure wipe, certified disposal, and the documentation that proves a device was sanitized before it left our hands
  • Own device recovery from departing employees and contractors, including the follow-up on equipment that has not been returned

Application Portfolio and Spend

  • Own the full inventory of business applications, including what sits outside SSO and how it got there
  • Manage licenses against actual usage, reclaim what is unused, and bring renewals forward with a recommendation rather than an invoice
  • Own the IT budget: build it, forecast it, and be able to explain why spend moved
  • Own IT vendor relationships and contracts, and make the call when a tool is no longer earning its cost

Workplace Technology

  • Own the technology in our Tampa office: the Ubiquiti stack end to end, including UniFi network and wifi, Access with facial recognition entry, and Protect cameras
  • Own physical access and surveillance systems in partnership with People Ops and Security, including who has access to what, retention of footage, and handling of biometric data
  • Own conference room AV, printers, and shared office equipment
  • Make in-office and hybrid meetings work reliably, because the ones that do not are the ones everyone remembers

Service Delivery

  • Own the Zendesk helpdesk: intake, taxonomy, priority definitions, SLAs, and customer satisfaction measurement
  • Report a small set of IT metrics monthly, and be the person who explains the number when it moves the wrong way
  • Publish a service catalog so the company knows what IT does, how to ask for it, and what to expect

Availability and Continuity

  • Define and run the escalation path for IT incidents, including lockouts, outages, and issues that hit people while traveling
  • Own IT business continuity: what we do when a core system is unavailable, and how we get people working again
  • Set clear expectations with the company on response, escalation, and after-hours coverage, and hold the team to them

Automation and AI

  • Extend our internal automation, which already covers onboarding, offboarding, directory sync, and ticket triage, and treat AI deflection as the way this team scales instead of headcount
  • Build integrations and reporting across Okta, Google, Mosyle, JumpCloud, and Zendesk so our compliance evidence assembles itself
  • Convert solved tickets into documented runbooks that feed the next automation

Security Partnership

  • Implement the controls Security defines, and give Security the evidence they need to verify those controls are working
  • Own the IT side of SOC 2 control operation and audit evidence, in partnership with our Security and Compliance team
  • Run access reviews through our compliance platform: quarterly for high-risk applications, annually for the full application portfolio
  • Escalate clearly and early when a configuration decision has security consequences

Growth and Integration

  • Lead the IT side of acquisitions: integrating identity, devices, applications, and support for an incoming team
  • Bring a plan for consolidating onto our stack, with a realistic sequence and an honest view of what breaks along the way

Leadership

  • Lead, coach, and grow one Senior IT Support Analyst, and build the technical depth of that role
  • Set the operating cadence: what gets reviewed weekly, what gets reported monthly, and what escalates immediately


To qualify for this role, you have:

  • 7+ years in IT, including 2+ years leading an internal IT function or team
  • Deep hands-on experience administering an enterprise identity provider, ideally Okta, including SSO, MFA policy, and lifecycle management
  • Hands-on experience administering Apple MDM at fleet scale, ideally Mosyle or Jamf, plus experience managing non-Apple endpoints
  • Experience owning Google Workspace or Microsoft 365 administration
  • Experience owning hardware asset lifecycle, including inventory accuracy, remote provisioning and returns, and secure device retirement
  • Experience owning an IT budget, vendor contracts, and software licensing
  • Demonstrated experience building or materially improving an onboarding, offboarding, and change management lifecycle
  • Experience operating IT controls under SOC 2 or a comparable framework, including producing audit evidence
  • A track record of automating recurring work rather than absorbing it
  • Ability to communicate clearly and directly with non-technical stakeholders, including executives, about what broke and what you are doing about it
  • Located in the Tampa, FL area and able to work on site from our Tampa office
  • Must be eligible to work in the region of hire without sponsorship now and/or in the future

Bonus points for:

  • Experience at a security company, or in an environment where IT hygiene is a customer-facing question
  • Scripting or automation experience, whether Python, Google Apps Script, or similar
  • Experience building with AI tooling, including agents, MCP servers, or LLM-assisted ticket deflection
  • Experience integrating an acquired company's identity, devices, and tooling
  • Familiarity with Zendesk, BambooHR, Ramp, Vanta, or 1Password
  • You are still comfortable in the console, and you have no interest in leading a team whose work you could not do yourself
  • You find the systemic cause behind a recurring ticket rather than closing it faster each time
  • You tell people what will happen before it happens, and what happened after it did


We Offer:

  • Pathway to promotion based on results and performance, not just time in the chair. You help us grow, and we will help you grow.
  • Passionate and intelligent colleagues who work hard and have a good time doing it
  • Paid company-wide week off at the end of each year
  • Flexible Vacation Policy
  • Awesome company swag
  • Full medical, dental, and vision benefits for US, UK, and Canada-based employees
  • Full short-term disability and life benefits; available long-term disability
  • Retirement savings account options with vested company matching for qualifying employees
  • In-person annual gatherings. Last time we all spent a week on a beach in the Dominican Republic!

DNSFilter is a pay-for-performance organization, which means there is an opportunity to advance your compensation based on performance over time. The hiring base pay is dependent on several factors, including level, function, training, transferable skills, work experience, business needs, and geographic location. As a hybrid company, our compensation reflects the cost of labor across several U.S. and global geographic markets. We pay differently based on those defined markets. Our Talent Team can share more about the specific salary range for the job location during the hiring process.

DNSFilter participates in the E-Verify program.

At DNSFilter, we utilize sophisticated software and tools to identify and eliminate Deepfake candidates. This approach helps us maintain the integrity of our hiring process, ensuring that we select the most qualified and genuine individuals to join our team.

U.S. hiring salary range

$140,000—$150,000 USD

Job ID gh-dnsfilter-5248648007 · Original posting ↗