IT & Security Engineer

Ultimate Staffing Services

San Francisco (CA)

Hybrid

USD 120,000 - 140,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Ultimate Staffing Services in San Francisco, CA seeks an IT & Security Engineer to own IT hardware/software lifecycle, security operations, and cloud/network security. Hybrid role with focus on Windows, Linux, macOS, and cross-functional collaboration.

5+ years in IT/system administration or security engineering required; experience with ISO 27001, NIST CSF 2.0, Okta, Google Workspace, GCP, Cloudflare, and SIEM is preferred. Regional collaborations across teams expected.

Qualifications

  • 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.
  • Hands-on experience with ISO 27001 and NIST CSF 2.0 frameworks.
  • Hands-on experience with Okta, Google Workspace, and Jira/Atlassian.

Responsibilities

  • Own full lifecycle of IT hardware and software across Linux, Windows, and macOS.
  • Drive security posture with vulnerability management, SIEM, and security training.
  • Manage SaaS procurement, licenses, renewals, and access controls.

Skills

IT system administration
Security engineering
Windows
Linux
macOS
Cloud security
Security incident response

Education

Bachelor-level or equivalent in IT or related field

Tools

Okta
Google Workspace
Jira/Atlassian
GCP
Cloudflare
Wazuh
HashiCorp Vault
SIEM (Splunk)
Kubernetes security
Jamf

Job description

IT & Security Engineer (JN -082026-429492) San Francisco, California

Salary: USD120000 - USD140000 per year

We are currently seeking aIT and Security Engineerto join a client inSalt Lake City UT and SFO CA. This is a full-time, direct hire position. The role isHybrid

  • Scope of Ownership:Owns the full lifecycle of IT hardware and software across Linux, Windows, and macOS (including the asset inventory and the employee onboarding and offboarding process) together with Company’s security operations stack: vulnerability management, HIDS/SIEM, secrets and PKI, cloud and network security controls, and identity administration. Accountable for the reliability of these systems and for the state of the controls they enforce.
  • Decision Authority:Final call on endpoint, network, and access configuration standards, on remediation priority and timelines for identified vulnerabilities, and on tooling choices within the IT and security estate. Recommends and escalates on risk acceptance, budget, and policy decisions.
  • Autonomy:Operates independently as the hands-on owner of a broad, mixed workload. Sets priorities across incident response, project delivery, and support commitments, and reprioritizes without waiting for direction when a security event or business need demands it.
  • Cross-Functional Influence:Works across Engineering, Platform, Legal & Compliance, People Operations, and Finance — partnering with engineering teams on Kubernetes and cloud security reviews, with People Operations on onboarding and offboarding, and with Finance on SaaS procurement and renewals. Drives security awareness across the whole company through training and phishing simulation.
  • External Representation:Serves as the escalation point for complex IT and security issues across global teams, is the primary technical contact for the HackerOne VDP and its researchers, and represents Company’s controls to auditors and to vendors.
  • Typical Experience:5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.

Key Responsibilities

  • Infrastructure & Endpoints:Manage the full lifecycle of IT hardware and software across Linux, Windows, and macOS. Own VPNs, backups, disaster recovery, MDM, and endpoint security, and serve as the escalation point for complex issues across global teams.
  • Security Operations:Drive Company’s security posture in alignment with ISO 27001 and NIST CSF 2.0. Own vulnerability management, the HackerOne vulnerability disclosure program, and security incident response. Administer Wazuh HIDS/SIEM and HashiCorp Vault (secrets and PKI), and run phishing simulations and security awareness training.
  • Cloud & Network Security:Own GCP IAM and Security Command Center. Manage Cloudflare Access (Zero Trust) and WAF rules, and own Kubernetes security (including RBAC, pod security standards, and workload reviews).
  • Identity & Compliance:Administer Okta for SSO, MFA, and provisioning. Enforce least privilege across all systems and support ISO 27001 and NIST CSF 2.0 audit activities.
  • Asset Management:Own the IT asset inventory end to end. Tracking hardware, software, and licence assignments from procurement through deployment, reassignment, and secure decommissioning or disposal. Keep asset records accurate and reconciled against purchasing and licence data, and use them to drive refresh cycles, spend decisions, and audit evidence.
  • Onboarding & Offboarding:Own the IT side of employee onboarding and offboarding in partnership with Human Resources. Provision devices, accounts, and role-appropriate access for new hires, and on exit revoke access promptly across all systems, recover and wipe company hardware, and handle data retention and transfer correctly. Keeps the process documented, repeatable, and auditable.
  • Platforms & Vendors:Own SaaS procurement, licence audits, and renewals. Administer Google Workspace, Atlassian, and other core tools, ensuring configurations meet security standards.
  • Projects & Support:Run IT and security projects from scoping through delivery. Resolve issues via ticketing and in-person support, maintain SLAs, and keep documentation and runbooks current.
  • Additional duties as assigned.

Required Qualifications

  • 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.
  • Working knowledge of the ISO 27001 and NIST CSF 2.0 frameworks and their practical application.
  • Hands-on experience with Okta, Google Workspace, and Jira/Atlassian.
  • Hands-on GCP experience, including IAM, Security Command Center, org-level security policies, and audit logging.
  • Experience with Cloudflare — WAF/security rules, Access (Zero Trust), DNS, and API protection.
  • Experience managing a vulnerability disclosure program or bug bounty programme (HackerOne or equivalent).
  • Hands-on experience with the Wazuh Security Platform or a comparable HIDS/security monitoring platform.
  • Experience with HashiCorp Vault for secrets management and PKI/certificate authority operations.
  • Experience operating a SIEM (Splunk or equivalent), including rule authoring, alert triage, and incident reporting.
  • Familiarity with Kubernetes security — RBAC, pod security, and workload hardening.
  • Vulnerability management experience across scanning, triage, and remediation tracking.
  • MDM platform experience with Jamf or equivalent.
  • Experience owning IT asset management — maintaining an accurate hardware, software, and licence inventory from procurement through secure decommissioning.
  • Experience running employee IT onboarding and offboarding, including device provisioning, account and access setup, and prompt access revocation and hardware recovery on exit.
  • Demonstrable commitment to least privilege access and access lifecycle management.
  • Proven ability to deliver IT and security projects independently.
  • Excellent written and verbal English, and comfort working across global, cross-functional teams.

Preferred Qualifications

  • Security certification such as CISSP, CompTIA Security+, Google Professional Cloud Security Engineer, or equivalent.
  • ISO 27001 Lead Implementer or Lead Auditor certification.
  • Experience designing or implementing a full Zero Trust network architecture.
  • Scripting ability in Python or Bash for security automation and tooling.
  • Experience with asset management tools such as Snipe-IT or equivalent.
  • Familiarity with container security tooling such as Trivy, Falco, or equivalent.
  • Prior experience in a high-growth tech or scale-up environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT & Security Engineer
IT & Security Engineer

Ultimate Staffing Services • Salt Lake City (UT)

On-site
USD 120,000 - 140,000
IT & Security Engineer
IT & Security Engineer

Ultimate Staffing • Salt Lake City (UT)

Hybrid
USD 100,000 - 140,000
Hybrid work model
IT & Security Engineer
IT & Security Engineer

Ultimate Staffing • San Francisco (CA)

Hybrid
USD 120,000 - 180,000
Senior IT & Security Engineer - Hybrid & Cloud Security
Senior IT & Security Engineer - Hybrid & Cloud Security

Ultimate Staffing Services • San Francisco (CA)

Hybrid
USD 120,000 - 140,000
Hybrid IT & Security Engineer: Own Secure Infra
Hybrid IT & Security Engineer: Own Secure Infra

Ultimate Staffing Services • Salt Lake City (UT)

Hybrid
USD 120,000 - 140,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Security Engineer
Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 120,000 - 160,000
Endpoint Security Engineer
Endpoint Security Engineer

CriticalRiver Inc. • San Francisco (CA)

On-site
USD 170,000 - 230,000
Information Technology Network Administrator
Information Technology Network Administrator

LMK Recruiting Solutions • Hillside (IL)

Hybrid
USD 70,000 - 90,000
Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

Hybrid
USD 110,000 - 170,000