IT & Security Engineer

Ultimate Staffing Services

San Francisco (CA)

On-site

USD 130,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ultimate Staffing, a Talent Solutions leader, seeks an IT and Security Engineer for a direct-hire role with an electronics manufacturing client in San Francisco and Salt Lake City. You will own the full IT hardware/software lifecycle across Linux, Windows, and macOS, manage the security stack, vulnerability management, SIEM, PKI, and cloud/network controls.

The role requires cross‑functional collaboration with Engineering, Legal, People Ops, and Finance, plus on‑call incident response and

Qualifications

  • 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.
  • Working knowledge of ISO 27001 and NIST CSF 2.0 frameworks with practical application.
  • Hands-on experience with Okta, Google Workspace, and Jira/Atlassian.
  • GCP IAM, Security Command Center, and audit logging experience.
  • Cloudflare WAF/Zero Trust and DNS management experience.
  • Vulnerability disclosure programs (HackerOne) experience preferred.
  • Wazuh or similar HIDS/SIEM, and HashiCorp Vault for secrets management.
  • SIEM experience (Splunk or equivalent) with rule writing and incident reporting.
  • Kubernetes security basics: RBAC, pod hardening, workload reviews.
  • MDM like Jamf experience useful; strong documentation and audit capabilities.

Responsibilities

  • Infrastructure & Endpoints: manage lifecycle of IT hardware/software across OSs; handle VPNs, backups, disaster recovery, MDM, and endpoint security; escalate complex issues globally.
  • Security Operations: drive security posture per ISO 27001/NIST CSF; own vulnerability management, HackerOne program, and incident response; run phishing simulations.
  • Cloud & Network Security: own GCP IAM, Security Command Center; manage Cloudflare Access and WAF; oversee Kubernetes security and RBAC.
  • Identity & Compliance: administer Okta for SSO/MFA; enforce least privilege and support ISO 27001/NIST CSF audits.
  • Asset Management: manage inventory from procurement to disposal; drive refresh cycles and cost decisions.
  • Onboarding & Offboarding: handle device provisioning, access provisioning, and prompt revocation; coordinate with HR.
  • Platforms & Vendors: SaaS procurement, license audits/renewals; manage core tools configurations to security standards.
  • Projects & Support: run IT/security projects from scoping to delivery; maintain SLAs and runbooks; provide hands-on support.
  • Other duties as assigned.

Skills

IT administration
Security engineering
HIDS/SIEM
GCP IAM
Kubernetes security
Zero Trust
Onboarding/offboarding
Vulnerability management
Cloud security
OKTA
Vault PKI
Wazuh

Education

Bachelor's degree in CS/IT or equivalent experience

Tools

Google Workspace
Jira/Atlassian
HashiCorp Vault
Wazuh/HIDS
Cloudflare
Splunk or SIEM
Terraform
Kubernetes
Okta

Job description

My name is Archana. I am a Talent Acquisition Manager at Ultimate Staffing, a part of leading Talent Solutions company Roth Staffing. We have an excellent opportunity for you with an Electronics Manufacturing company. Please Let me know what you think about the below JD and I am looking forward to having a brief conversation with you. Please find the JD below and share a copy of you updated resume. I will call you to discuss further. We are currently seeking a IT and Security Engineer to join a client in Salt Lake City UT and SFO CA. This is a full‑time, direct hire position.

Scope & Leveling Indicators

Scope of Ownership: Owns the full lifecycle of IT hardware and software across Linux, Windows, and macOS (including the asset inventory and the employee onboarding and offboarding process) together with Company's security operations stack: vulnerability management, HIDS/SIEM, secrets and PKI, cloud and network security controls, and identity administration. Accountable for the reliability of these systems and for the state of the controls they enforce.

Decision Authority: Final call on endpoint, network, and access configuration standards, on remediation priority and timelines for identified vulnerabilities, and on tooling choices within the IT and security estate. Recommends and escalates on risk acceptance, budget, and policy decisions.

Autonomy: Operates independently as the hands‑on owner of a broad, mixed workload. Sets priorities across incident response, project delivery, and support commitments, and reprioritizes without waiting for direction when a security event or business need demands it.

Cross‑Functional Influence: Works across Engineering, Platform, Legal & Compliance, People Operations, and Finance – partnering with engineering teams on Kubernetes and cloud security reviews, with People Operations on onboarding and offboarding, and with Finance on SaaS procurement and renewals. Drives security awareness across the whole company through training and phishing simulation.

External Representation: Serves as the escalation point for complex IT and security issues across global teams, is the primary technical contact for the HackerOne VDP and its researchers, and represents Company's controls to auditors and to vendors.

Typical Experience

5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.

Key Responsibilities
  • Infrastructure & Endpoints: Manage the full lifecycle of IT hardware and software across Linux, Windows, and macOS. Own VPNs, backups, disaster recovery, MDM, and endpoint security, and serve as the escalation point for complex issues across global teams.
  • Security Operations: Drive Company's security posture in alignment with ISO 27001 and NIST CSF 2.0. Own vulnerability management, the HackerOne vulnerability disclosure program, and security incident response. Administer Wazuh HIDS/SIEM and HashiCorp Vault (secrets and PKI), and run phishing simulations and security awareness training.
  • Cloud & Network Security: Own GCP IAM and Security Command Center. Manage Cloudflare Access (Zero Trust) and WAF rules, and own Kubernetes security (including RBAC, pod security standards, and workload reviews).
  • Identity & Compliance: Administer Okta for SSO, MFA, and provisioning. Enforce least privilege across all systems and support ISO 27001 and NIST CSF 2.0 audit activities.
  • Asset Management: Own the IT asset inventory end to end. Tracking hardware, software, and licence assignments from procurement through deployment, reassignment, and secure decommissioning or disposal. Keep asset records accurate and reconciled against purchasing and licence data, and use them to drive refresh cycles, spend decisions, and audit evidence.
  • Onboarding & Offboarding: Own the IT side of employee onboarding and offboarding in partnership with Human Resources. Provision devices, accounts, and role‑appropriate access for new hires, and on exit revoke access promptly across all systems, recover and wipe company hardware, and handle data retention and transfer correctly. Keeps the process documented, repeatable, and auditable.
  • Platforms & Vendors: Own SaaS procurement, licence audits, and renewals. Administer Google Workspace, Atlassian, and other core tools, ensuring configurations meet security standards.
  • Projects & Support: Run IT and security projects from scoping through delivery. Resolve issues via ticketing and in‑person support, maintain SLAs, and keep documentation and runbooks current.
  • Additional duties as assigned.
Required Qualifications
  • 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.
  • Working knowledge of the ISO 27001 and NIST CSF 2.0 frameworks and their practical application.
  • Hands‑on experience with Okta, Google Workspace, and Jira/Atlassian.
  • Hands‑on GCP experience, including IAM, Security Command Center, org‑level security policies, and audit logging.
  • Experience with Cloudflare – WAF/security rules, Access (Zero Trust), DNS, and API protection.
  • Experience managing a vulnerability disclosure program or bug bounty programme (HackerOne or equivalent).
  • Hands‑on experience with the Wazuh Security Platform or a comparable HIDS/security monitoring platform.
  • Experience with HashiCorp Vault for secrets management and PKI/certificate authority operations.
  • Experience operating a SIEM (Splunk or equivalent), including rule authoring, alert triage, and incident reporting.
  • Familiarity with Kubernetes security – RBAC, pod security, and workload hardening.
  • Vulnerability management experience across scanning, triage, and remediation tracking.
  • MDM platform experience with Jamf or equivalent.
  • Experience owning IT asset management – maintaining an accurate hardware, software, and licence inventory from procurement through secure decommissioning.
  • Experience running employee IT onboarding and offboarding, including device provisioning, account and access setup, and prompt access revocation and hardware recovery on exit.
  • Demonstrable commitment to least privilege access and access lifecycle management.
  • Proven ability to deliver IT and security projects independently.
  • Excellent written and verbal English, and comfort working across global, cross‑functional teams.
Preferred Qualifications
  • Security certification such as CISSP, CompTIA Security+, Google Professional Cloud Security Engineer, or equivalent.
  • ISO 27001 Lead Implementer or Lead Auditor certification.
  • Experience designing or implementing a full Zero Trust network architecture.
  • Scripting ability in Python or Bash for security automation and tooling.
  • Experience with asset management tools such as Snipe‑IT or equivalent.
  • Familiarity with container security tooling such as Trivy, Falco, or equivalent.
  • Prior experience in a high‑growth tech or scale‑up environment.

All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT & Security Engineer
IT & Security Engineer

Ultimate Staffing • San Francisco (CA)

Hybrid
USD 120,000 - 180,000
IT & Security Engineer
IT & Security Engineer

Ultimate Staffing Services • Salt Lake City (UT)

On-site
USD 110,000 - 140,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Network Security Engineer
Senior Network Security Engineer

Ledgent Technology • Portland (OR)

On-site
USD 120,000 - 150,000
SOC Manager
SOC Manager

TEKsystems • Rocklin (CA)

On-site
USD 96,000 - 103,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+5
Global Cybersecurity Engineer
Global Cybersecurity Engineer

Ledgent Technology • Manassas (VA)

Hybrid
USD 140,000 - 145,000
Medical insurance
Dental insurance
Vision insurance
+5
Lead Engineer, Infrastructure Security
Lead Engineer, Infrastructure Security

Randstad Digital Americas • Newport Beach (CA)

On-site
USD 133,000 - 185,000
Medical
Prescription
Dental
+5
Security Engineer
Security Engineer

TEKsystems • Rocklin (CA)

On-site
USD 96,000 - 103,000
Medical, dental & vision
401(k) Retirement Plan - Pre-tax and R
Life Insurance (Voluntary Life & AD&D)
+5
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Engineer
Application Security Engineer

Awardco • Lindon (UT)

On-site
USD 140,000 - 170,000