About Tunnl
Tunnl is building a future where artificial intelligence enables organizations to connect meaningfully with the people who matter most. We help organizations conduct research at scale, define the right audiences, surface real-time insights, identify optimal communication channels, and measure changing attitudes over time.
Tunnl serves brands, agencies, and advocacy groups alike - organizations navigating complex communications, reputational, and regulatory landscapes. These teams need smarter, faster ways to make audience-informed decisions that stand up to scrutiny and resonate across stakeholder groups. Whether you're building a brand, shaping public opinion, managing risk, or launching a new initiative, Tunnl empowers you to move from insight to impact with clarity & confidence.
Role Overview
The IT Engineer II owns the systems, tools, and infrastructure that keep the organization running. This is a hands-on role spanning SaaS administration, application integrations, network operations, and security — with direct exposure to audit and compliance work. You'll have real ownership and high visibility on a lean, high-trust team.
What You’ll Do
SaaS Administration
Own provisioning, deprovisioning, licensing, and access control across Tunnl's SaaS portfolio — Google Workspace, Slack, Zoom, Notion, and others.
Enforce least-privilege and RBAC standards; manage vendor relationships and escalations.
Monitor application health, usage, and license efficiency.
Integrations & Automation
Build and maintain integrations between SaaS platforms and Rippling, including SCIM provisioning, SSO, and workflow automation.
Identify and deploy configuration profiles and MDM policies to enforce IT and Security policy
Identify and automate manual processes; document all integration architecture and data flows.
Troubleshoot sync errors, auth failures, and integration breaks across connected systems.
Network Infrastructure
Monitor, configure, and maintain Cisco Meraki switching/wireless and Sophos XGS firewall infrastructure.
Manage VLANs, firewall rules, access policies, and traffic segmentation; coordinate ISP circuit management and upgrades.
Maintain current network topology documentation; follow change management procedures for all modifications.
Security Operations
Triage and remediate security alerts from SentinelOne; perform vulnerability assessments across endpoints, apps, and network.
Maintain Rippling MDM policies for endpoint compliance, configuration profiles, and patching.
Contribute to security policy development and stay current on emerging threats relevant to Tunnl's environment.
Function as “End of Tier” support for IT issues.
SOC 2 & Audit Support
Partner with Security and external auditors to support SOC 2 Type II — evidence collection, control documentation, and access reviews.
Maintain audit-ready records across access logs, change logs, and configuration baselines; respond to auditor requests directly.
Qualifications
4-6 years in an IT engineering or systems administration role in a fast-moving environment.
Google Workspace administration — user management, Drive policies, security settings.
Rippling or comparable HRIS/MDM platform experience, including device management and integrations.
Network administration with Cisco Meraki (switches and/or APs); Sophos XGS or equivalent next-gen firewall.
Endpoint security experience — SentinelOne, CrowdStrike, or similar EDR platforms.
Working knowledge of SCIM, SSO (SAML/OIDC), and identity lifecycle management.
Familiarity with SOC 2 or comparable compliance frameworks and evidence collection.
Ability to document systems clearly — network diagrams, runbooks, integration specs.
Scripting or automation experience (Python, Bash, and PowerShell) for workflow tasks
Preferred Qualifications
Relevant certifications: Google Workspace Admin, CompTIA Security+, Meraki ECMS, CCNA, CCNP, or equivalent.
SIEM or log aggregation experience (Splunk, Datadog, or similar).
Why You Should Apply:
Join a team driven by curiosity, teamwork, integrity, and a shared passion for solving big challenges.
A friendly, welcoming, and supportive culture with regular social and team events.
Comprehensive benefits with excellent medical, vision, and dental coverage.
Health Savings Account (HSA) and Flexible Spending Account (FSA) options.
Employer-paid life insurance & short-term & long-term disability, with other voluntary additional coverage available (accident, critical illness, hospital indemnity).
Flexible hybrid work policy.
Flexible paid vacation plus 80 hours of paid sick leave.
10 paid company holidays per year.
401(k) plan with 100% match up to 3%, plus 50% match up to 5% (subject to IRS limits).
Cell phone reimbursement stipend.
Monthly parking or commuter stipend for VA-based employees.