IT Administrator
Revel RoboticsAbout REVEL
REVEL captures the skill of experienced workers, turns it into robot intelligence, and deploys that capability where work is hard to staff. Neural Gambit captures the force, motion and intent behind expert work. RAI learns from that data. Genesis robots perform the resulting tasks on site.
The company was founded in 2025 and is building its founding team in the Czech Republic. The team is distributed across offices, a lab and a workshop, works with external contractors and partners, and handles customer and partner data that has to stay controlled.
The role
You will own the systems everyone logs into: Google Workspace, single sign-on and identity, company laptops and phones, and the SaaS applications the company runs on. You decide how accounts are created, what access they get, how devices are secured, and how a new person is productive on day one and fully removed on their last.
This is the first dedicated enterprise IT hire. The current setup is small, largely manual, and grew as the company did, so the first months are about taking it over, documenting it, tightening access, and automating the parts that are done by hand today. After that you set the direction: what the identity model looks like, which tools we standardise on, and what security baseline the company holds itself to as it grows and as customers, partners and investors start asking harder questions.
This role is paired with an IT Infrastructure Engineer who owns the network, servers, storage and compute. They own the physical and computational layer; you own the accounts, devices and applications on top of it. You will work closely together, and neither of you will be waiting on the other for the parts you own.
Responsibilities
Identity and access
Administer Google Workspace end to end: domains and aliases, mail routing, delivery and filtering, SPF, DKIM and DMARC, groups, shared drives, retention and eDiscovery.
Own single sign-on and the identity provider: SAML and OIDC application integrations, SCIM provisioning, multi-factor authentication including phishing-resistant keys, conditional access and session policy.
Design and run joiner, mover and leaver processes: automated provisioning on hire, access changes on role change, and complete, verifiable deprovisioning on exit, including contractors and interns.
Manage privileged and shared access: admin roles, break-glass accounts, service accounts, API keys and the company password manager.
Devices
Run mobile device management across macOS, Windows and Linux endpoints and company phones: enrolment, configuration profiles, disk encryption, patching, application deployment and compliance reporting.
Maintain the endpoint security baseline: screen lock, encryption, endpoint protection, browser and extension policy, and remote wipe.
Own the end-user hardware lifecycle: specification, procurement, asset inventory, warranty, repair and disposal.
SaaS and licences
Own the SaaS stack: application inventory, admin consoles, integrations, and the onboarding of new tools including security and data review before they are adopted.
Manage licences, renewals and spend, reclaim unused seats, and give the leadership team a clear picture of what IT costs and why.
Find and bring in shadow IT rather than leaving it unmanaged.
Security and compliance
Run periodic access reviews across Workspace, the identity provider and the main SaaS applications, and keep the evidence.
Define and maintain security policies and baselines, and the runbooks for incidents such as account compromise, lost device and phishing.
Prepare the company for ISO 27001 or SOC 2 style scrutiny and answer customer, partner and investor security questionnaires, working with the engineering and legal side on anything that touches product or contracts.
Track applicable Czech and EU obligations, including the Czech Cybersecurity Act (Act No. 264/2025 Coll., the NIS2 transposition) and GDPR, and advise the leadership team on what applies to us as we grow.
Support and enablement
Be the first line for IT problems: run a lightweight ticketing system, set expectations for response, and keep a record of what breaks and why.
Run new-hire setup and first-day onboarding, and offboarding on the other end.
Write documentation and short internal guides so common problems can be handled without you, and train the team on the security practices you introduce.
Automate the repetitive parts of all of the above with scripts and workflow tooling.
Requirements
Hands-on administration of an enterprise productivity suite, ideally Google Workspace, including mail flow and DNS records for email authentication.
Practical experience with single sign-on and an identity provider (Okta, Entra ID, Google as IdP, JumpCloud or similar): SAML, OIDC, SCIM provisioning and MFA.
Mobile device management experience on at least macOS or Windows (Jamf, Kandji, Mosyle, Intune or similar), including enrolment, policy and patching.
Understanding of access control in practice: least privilege, role-based access, joiner, mover and leaver workflows, and why access reviews matter.
Scripting for automation: Python, Google Apps Script, PowerShell, bash or equivalent, and comfort working against vendor APIs.
Working knowledge of networking fundamentals (DNS, DHCP, VPN, Wi-Fi authentication), enough to tell an account problem from a network problem and hand the latter over cleanly.
Communication skills, patience, and genuine willingness to work on other peopleβs problems, including explaining causes and fixes to non-specialists.
Working Czech and English. Much of the team and most of our documentation is in English; vendors, landlords and authorities are often not.
Nice to have
Experience taking over an undocumented environment and getting it under control.
ISO 27001, SOC 2 or NIS2 readiness work, or having answered enterprise security questionnaires.
Linux endpoint management, or supporting engineering and machine learning teams who run Linux workstations.
Identity governance and lifecycle automation beyond the basics, including workflow tools such as Okta Workflows, Torq or n8n.
Experience with ticketing and ITSM systems, and asset and procurement platforms.
Working in a lab, workshop or manufacturing environment where not everyone sits at a desk.
What we offer
Full ownership of the enterprise IT layer, including which systems we run and what the security baseline is.
A small company where the decisions you make are visible within days rather than filtered through several layers of process.
How to apply
Apply through the link on this posting. Include a short description of an environment you administered or took over: its size, what you changed about how access or devices were managed, and what you would do differently now.