Назад
2 дня назад

Systems Engineer (Corporate Security)

144 000 - 199 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Релокация
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Systems Engineer (Corporate Security): Building and operating security controls for device fleets, identity systems, network enforcement, and enterprise AI deployments with an accent on configuration-as-code, endpoint remediation, and automated access controls. Focus on integrating Okta, Cloudflare, endpoint security, and AI platforms through APIs while detecting drift, remediating identity posture gaps, and maintaining control coverage.

Location: Hybrid in New York, NY; relocation expense coverage to NYC or San Francisco if needed

Salary: $144,000–$199,000 annual target base salary for SF/NY, plus equity

Company

Ramp builds financial infrastructure that automates payment authorization, risk detection, spend categorization, and financial close for more than 70,000 companies.

What you will do

  • Maintain operating-system and software update policies and keep newly introduced applications in the patching cadence.
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and related tooling.
  • Maintain device configuration baselines as code, including drift detection and hardening standards.
  • Configure Okta SSO, MFA, authenticator enrollment, device trust, and conditional access policies.
  • Remediate identity posture gaps such as stale accounts, orphaned service principals, excessive OAuth grants, MFA gaps, and excess privileges.
  • Implement controls for enterprise AI usage, automate platform integrations through APIs, and report on control coverage.

Requirements

  • 3–5 years of experience in client platform engineering, endpoint engineering, identity and access management, or corporate security.
  • Hands-on macOS management at scale with MDM tools such as Jamf, Fleet, Kandji, or equivalent.
  • Working knowledge of Okta or a similar identity provider, including SSO, authenticator policies, SCIM provisioning, and conditional access.
  • Scripting experience in Python, Go, or Bash, with experience automating platform APIs.
  • Experience with EDR and endpoint vulnerability management, such as CrowdStrike.
  • Ability to evaluate and explain tradeoffs between technical enforcement, policy, and user friction.

Nice to have

  • osquery, Fleet, or other query-based fleet visibility tooling.
  • Identity posture management, access review, or governance platforms.
  • Cloudflare Zero Trust or similar proxy, DNS, network enforcement, and TLS inspection experience.
  • AI and LLM security experience, including agent authorization, tool calls, model gateways, and data leakage prevention.
  • Infrastructure-as-code, CI/CD, Terraform, GitHub Actions, Windows fleet management, or SOC 2 and PCI compliance experience.

Culture & Benefits

  • Flexible PTO and centralized home-office equipment ordering.
  • Medical, dental, and vision coverage, with additional regional insurance and retirement benefits.
  • Health and wellness, fertility, pet insurance, and employee assistance benefits.
  • Parental leave of up to 16 weeks for birthing and bonding or 8 weeks for bonding only, with full pay.
  • In-office meals, snacks, drinks, weekly coffee stipend, and intra-office travel budget.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →