LiveKit is building the infrastructure layer for the voice-driven era of computing. Our platform gives developers everything they need to build, test, deploy, scale, and observe agents in production. Founded in 2021, LiveKit powers voice AI applications for OpenAI, xAI, Salesforce, Coursera, Spotify, and thousands of others, collectively facilitating billions of calls each year.About You
This is an engineering role with a support component, not the other way around. The bulk of the job is building and owning systems: the identity model in Okta, endpoint baselines in Workspace ONE, governance across Google Workspace and the wider SaaS estate, and the automation that determines how much manual work IT has to absorb in the first place. You'll also carry escalations and some direct support — at our size there's no clean wall between the two, and the person in this role needs to stay close enough to the queue to know which problems are worth engineering away.
You'll work in an Okta, Workspace ONE, Google Workspace, and Slack stack, partnered closely with Security, Engineering, People, and Finance. Internal systems are in audit scope for SOC 2, ISO 27001, and PCI, so the controls you build have to hold up under an auditor's review, not just function day to day.
You'll thrive as an IT Engineer if you:
obsess with crafting code that is fast, reliable and practical for the problem
are known as the go-to person for tackling tough technical problems
work hard and can build and ship fast
can clearly explain complex technical concepts to others
are a fast learner, frequently picking up new languages and tools
As an IT Engineer at LiveKit, you will:
Own identity and access engineering in Okta — group strategy, app assignments, SSO configuration, lifecycle automation, and access request patterns that are secure without being miserable to use
Run endpoint engineering across a macOS-first fleet in Workspace ONE — provisioning, configuration baselines, patching, encryption posture, inventory hygiene, and compliance reporting
Administer Google Workspace and Slack at scale: user lifecycle, groups, shared drives, permissions, roles, and the governance patterns that keep them from drifting
Bring the SaaS estate under real governance — who owns each tool, who has access, what it costs, and what happens to all three when someone changes teams or leaves
Build the automation that keeps IT load from scaling with headcount — onboarding, deprovisioning, access reporting, device compliance, and whatever else you catch yourself doing twice
Translate security, compliance, and engineering requirements into IT controls that generate their own audit evidence instead of a quarterly scramble
Serve as the technical escalation point for complex issues across identity, access, endpoints, and internal infrastructure — and then engineer the class of problem out of existence
Who You Are4+ years in IT engineering, IT operations, systems administration, endpoint engineering, or identity engineering — ideally somewhere fast-moving and remote-first
You've administered Okta or a comparable identity provider as the owner: SSO, groups, app assignments, lifecycle workflows, real access management decisions
Hands-on with modern MDM — Workspace ONE or equivalent — including provisioning, configuration enforcement, patching, encryption, and inventory
Strong Google Workspace administration and genuine macOS endpoint depth
You've built or meaningfully improved operational workflows, automation, reporting, or internal controls — not just operated someone else's
An excellent writer. You can explain a technical decision clearly, document a system so the next person doesn't have to reverse-engineer it, and keep stakeholders informed without burying them
Strong ownership and judgment. You can prioritize under ambiguity and you build things that reduce future work rather than adding to it
You want to stay hands-on. This is an individual contributor role, and the work is building and operating systems, not managing people who do
Nice to HaveExperience supporting security and compliance work — SOC 2, ISO 27001, PCI, access reviews, audit evidence, or control implementation
Fluency with device security posture: EDR, disk encryption, patch compliance, vulnerability management, access hygiene
Scripting and automation with Bash, Python, Google Apps Script, Okta Workflows, or raw APIs
Experience designing IT processes that work across time zones for a globally distributed team, including the particular joy of international hardware logistics
Our Commitment to YouAn opportunity to build something truly impactful to the world
Work alongside world-class engineers building in the open
Competitive salary and equity package
Health, dental, and vision benefits
Flexible vacation policy
Remote work environment with the equipment you need
Ready to Apply?
If the idea of owning identity, endpoints, and automation end to end sounds like your kind of job, we'd love to hear from you.
LiveKit is an equal opportunity employer and does not discriminate on the basis of any characteristic protected by applicable law. If you require a reasonable accommodation during the application or interview process, please contact recruiting@livekit.io.