Your information will be processed by AppsFlyer as detailed in our Job Candidates Privacy Notice
" ["label"]=> string(25) "Candidate Privacy Notice " ["required"]=> bool(false) ["fields"]=> array(1) { [0]=> object(stdClass)#2275 (3) { ["name"]=> string(22) "question_38759353002[]" ["type"]=> string(24) "multi_value_multi_select" ["values"]=> array(1) { [0]=> object(stdClass)#2274 (2) { ["label"]=> string(11) "Acknowledge" ["value"]=> int(256048743002) } } } } } } ["location_questions"]=> array(0) { } }Senior IT Infrastructure Operations - Herzliya
AppsFlyer is looking for a Senior IT Infrastructure Operations to join our IT Infrastructure team in Herzliya, Israel. IT at AppsFlyer is not a support function - it is the backbone of the company's transformation into an AI-native organization, and we are building an autonomous, AI-operated IT department: agents run the routine 24/7, humans stay in the loop, and autonomy is earned through gates.
You will join a small IT InfraOps team that owns the company's identity, endpoint, SaaS, IT-cloud, and network foundations - and turns them into a governed platform that both people and AI agents can operate. This is a hands-on role for someone who designs at the architecture level, ships production-grade automation and internal products end-to-end, and treats documentation as part of "done" so that agents can run on it.
What you'll do
Identity, Access & Core Systems
- Own and evolve our identity platform: Okta (SSO integrations, tier groups, Okta Workflows, SCIM, API Gateway), Just-In-Time access, and the full user and non-human identity lifecycle service accounts, API keys, break-glass, and audit.
- Administer and hard-core SaaS: Google Workspace, Slack, Zoom, Atlassian, Microsoft 365, and the AI platforms the company runs on (Claude, ChatGPT / OpenAI, Cursor, etc.).
- Serve as Tier 3 escalation with real diagnostic depth — certificates, auth chains, cross-platform policy conflicts, SaaS configurations, MDM edge cases.
Platform Engineering & Cloud
- Build and operate the IT Infra Platform on GCP: Cloud Run, VPC Service Controls, Cloud Armor, Terraform / IaC, GitHub Actions CI/CD, secret management, and image and dependency hygiene.
- Deliver internal products end-to-end - design → implement → IaC → CI/CD → secured deploy → operate - and contribute to the shared "paved road" so the whole team (and the agent fleet) can pull any task.
- Contribute to the AI Gateway layer, including usage governance, cost attribution, and model access control.
Automation & Integrations
- Design automation across Make.com, Okta Workflows, and code via deployed services, with APIs, webhooks, and MCP as first-class integration surfaces.
- Own the health of production automations: monitoring, alerting, failure runbooks, and clear ownership.
- Drive the IT automation backlog toward zero-touch self-service implementation.
AI-Native IT & Agents
- Build agentic solutions for IT operations: agents that execute real infra tasks with explicit action boundaries and stop/escalation conditions.
- Apply AI technology, prompt and context engineering, and evaluation to real-world IT use cases - from Tier-0 self-service through autonomous remediation.
- Contribute to the organization's evolving AI framework with skill and plugin ownership.
- Contribute to the Infra Knowledge Framework: resolution notes, ADRs, operational procedures, and project knowledge pages written so agents (and teammates) can act on them.
Endpoint, Network & Security Partnership
- Maintain global network and office infrastructure (Meraki, FortiGate, Palo Alto Prisma / GlobalProtect, physical access) alongside the endpoint management stack (Kandji, Intune, Airlock).
- Collaborate with Security on app and vendor risk assessments, shadow-AI and SaaS governance, IS-CAB/AI-CAB reviews, and audit preparedness, while transitioning manual approvals to policy-as-code.
What you have
- 5+ years hands-on in IT infrastructure, SysAdmin / InfraDevOps in a SaaS or high-growth tech environment.
- Deep, production-level command of Okta (or equivalent IdP) and of enterprise SaaS administration — Google Workspace, Slack, Atlassian, Microsoft 365.
- Real cloud engineering experience: GCP (preferred) or AWS / Azure, Terraform or other IaC, containers, CI/CD, secrets management.
- Strong scripting and integration skills — Python and/or TypeScript / JavaScript, REST APIs, webhooks, JSON, OAuth.
- Proven experience designing and operating automation at scale (Make.com, n8n, Workato, Okta Workflows or similar) — including monitoring and ownership of what you build.
- Hands-on experience building with LLMs (Claude and/or OpenAI APIs) and applying prompt and context engineering to real use cases.
- Security-minded by default: least privilege, zero trust, secret hygiene, audit trails.
- Architecture-level thinking with an end-to-end ownership mindset, and a habit of documenting so others — and agents — can run what you build.
- Self-directed: you originate improvements, not just execute tickets.
- Thrives in a fast-moving environment where frontier technologies are evaluated, adapted, and put into production constantly — comfortable learning a new tool this week and owning it in production the next.
- Strong communication in English (written and verbal).
Bonus points
- Experience building internal tools / full-stack apps (React / Node / Python) with SSO-backed auth.
- Advanced LLM engineering: RAG and vector stores, knowledge graphs, agent frameworks and agentic loops, building MCP servers, and LLM evaluation.
- AI gateway / LLM cost governance (LiteLLM, Bifrost, Vertex AI, AWS Bedrock).
- Relevant certifications, or equivalent hands-on experience, such as:
- Google Cloud: Associate Cloud Engineer, or Professional Cloud Architect / DevOps Engineer / Security Engineer.
- AWS: Solutions Architect (Associate or Professional), SysOps Administrator, or DevOps Engineer – Professional.
- Other: Microsoft Azure Administrator (AZ-104), HashiCorp Terraform Associate, or Okta Certified Administrator / Professional.
- MDM at depth (Kandji, Jamf, Intune) and cross-MDM scripting.
- Network fundamentals (Meraki, FortiGate, Palo Alto or similar systems), physical access systems, or global office rollouts.
- ITSM / ITIL practice and knowledge-management experience; FinOps for SaaS and AI spend.
Tools & technologies you'll work with
- Identity & Access: Okta (Workflows, SCIM, API Gateway), JIT systems, Cerby, Infinipoint, non-human identity & secrets lifecycle.
- Core SaaS: Google Workspace, Slack, Zoom, Jira / JSM / Harmony / Confluence, Microsoft 365, Torii.
- Cloud & Platform: GCP (Cloud Run, Cloud Compute, VPC-SC, Cloud Armor), Terraform, GitHub Actions, Docker, Secret Management; Azure, AWS, Cert Management.
- Automation & Integration: Make.com, Okta Workflows, REST / Webhooks / JSON, MCP, Python, TypeScript.
- AI Platform: Claude (API, Claude Code, Cowork, plug-ins & skills), OpenAI / ChatGPT, Cursor, Vertex AI, LiteLLM, RAG & vector stores, agent frameworks, evaluation of new tools.
- Endpoint & Network: Kandji, Intune, Airlock, Meraki, FortiGate, Palo Alto Strata, and physical access systems.
- Observability & Ops: PagerDuty, Infrastructure Guard monitoring.
Why this role
You will be one of a handful of engineers turning IT into a platform that agents operate — with a direct line to the Head of Global IT, real ownership of production systems used by the entire company, and a mandate to build the next generation of autonomous IT.
You'll also work at the frontier: new AI and infrastructure technologies land on our desk constantly, and you'll be the one evaluating them, adapting them to how AppsFlyer works, and taking the ones that earn it into production.
As a global company operating from 25 offices across 19 countries, we reflect the human mosaic of the diverse and multicultural world in which we live. We ensure equal opportunities for all of our employees and promote the recruitment of diverse talents to our global teams without consideration of race, gender, culture, or sexual orientation. We value and encourage curiosity, diversity, and innovation from all our employees, customers, and partners.
We sent an email to {email}
Head over to your inbox and click on the link to confirm your account.