Staff IT Systems Engineer

Obsidian Security

Palo Alto (CA)

Hybrid

USD 203,000 - 224,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Equity and 401k
Healthcare coverage
PTO & holidays
Parental leave
Development resources

Job summary

Obsidian Security is hiring a Staff IT Systems Engineer to own the identity, endpoint, and IT platform foundation. You will drive identity flows from HRIS to Okta, manage a fleet of Mac devices via Jamf Pro, and codify configurations as part of an infrastructure-as-code operating model.

You will lead AI-assisted operations, automate access provisioning, and raise the bar for security-first IT practices in a rapidly growing company.

Qualifications

  • 8+ years building and operating IT systems, identity, or platform infrastructure in production.
  • Deep ownership of Okta across SSO, MFA, Lifecycle Management, and conditional access.
  • Hands-on Jamf Pro expertise managing a production Mac fleet.
  • Infrastructure-as-code ownership with Terraform/OpenTofu.
  • Daily use of AI coding tools to ship production work.

Responsibilities

  • Own the identity foundation and Okta tenancy end-to-end.
  • Operate IT as code across Google Cloud, Jamf, and policy governance.
  • Lead AI-assisted IT operations and self-service workflows.
  • Manage endpoint security, device trust, and zero-trust access controls.
  • Mentor teammates and set IT standards for scalable operations.

Skills

Okta ownership
Jamf Pro
Terraform/OpenTofu
GitOps/GitHub Actions
Python/PowerShell scripting
AI-assisted operations
Zero-trust concepts
Identity & access governance

Tools

Jamf Pro
Terraform
OpenTofu
GitHub Actions
Google Workspace

Job description

Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, including many of the world’s largest Fortune 1000 and Global 2000 companies.

Founded in 2017 and backed by top investors like Greylock, Obsidian was built to close a critical gap: securing SaaS apps where business happens—Microsoft 365, Salesforce, and hundreds more. The company does this by offering a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Obsidian was built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. Now, they’re transforming how SaaS is secured.

With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise ahead, Obsidian is scaling rapidly toward long-term growth and IPO readiness.

We're hiring an experienced Staff IT Systems Engineer to be the senior technical owner of Obsidian's identity, endpoint, and IT platform foundation, and to help us operate that foundation as code. You will own how identity flows from our HR system into Okta and out to every application, how our device fleet is managed and hardened, and how the configuration behind all of it lives as version-controlled, AI- and human-authored code. You will set the bar for how a modern, security-first IT organization runs in an AI-forward company.

This is a high-leverage seat at a pivotal moment. Our identity platform is being stood up with a lifecycle orchestration layer in front of it, and we are moving the whole stack onto an infrastructure-as-code operating model. We are looking for a senior technical owner to set the bar for identity architecture, configuration-as-code, AI-augmented operations, and how a lean IT function leverages AI and automation to grow the function.

You will report directly to the VP of Business Systems, Data & IT. You will partner closely with Security, DevOps, HR, Finance, and the go-to-market teams, and you will collaborate with teammates across the Business Systems, Data & IT function.

What You'll Do

Own the identity foundation

  • Serve as the senior technical owner of Okta as our primary identity provider, covering Universal Directory, SSO, MFA (Okta Verify FastPass and FIDO2), conditional access, Device Access, and Okta Identity Governance for access certifications and reporting.
  • Own the lifecycle orchestration that turns HR events into access. This includes joiner, mover, and leaver flows from our HRIS through the orchestration layer into Okta, with same-hour offboarding.
  • Own the SSO application catalog across our estate of applications: sequence the integrations, enforce group-based access by role, and make the catalog the definition of what is sanctioned.

Operate IT as code

  • Manage core platform configuration as version-controlled code in our corporate GitHub organization. This spans Okta policies, groups, group rules, app assignments, and governance campaigns; Jamf profiles, policies, and smart groups; the GitHub organization itself; and the underlying Google Cloud foundation, using OpenTofu and Terraform.
  • Bring imperative surfaces under the same discipline. Manage Google Workspace through scripts in git, run keyless through Workload Identity Federation, with verification and drift reporting where true state management is not possible.

Set the standard for AI-augmented operations

  • Author configuration with AI assistance from the start. You will set the team standard for what good looks like here.
  • Use read-only tooling for live observability, drift triage, and log investigation, with humans gating every production change.
  • Build AI-assisted IT support and self-service workflows on our automation platform so routine requests for access, provisioning, and license changes resolve without a ticket queue and a manual handoff.

Automate and harden the fleet

  • Own endpoint management across platforms with device trust and assurance wired into access policies, automated third-party patching, and application allowlisting.
  • Advance zero-trust network access and secrets-management patterns so identity and device health decide access.

Raise the bar across IT

  • Set technical standards for the IT function, document them so they scale beyond your own hands, mentor teammates, and be the person others learn identity and automation from.
  • Partner with the VP to shape IT priorities and sequencing, and represent IT's requirements in cross-functional security, compliance, and platform decisions.
What You'll Bring

We know few candidates match every line below. If you own most of the required list and are excited by the rest, we want to hear from you.

Requirements:

  • 8 or more years building and operating IT systems, identity, or platform infrastructure in production, with clear ownership of the systems you ran.
  • Deep, hands-on Okta ownership across SSO, MFA, Universal Directory, Lifecycle Management, and conditional access, ideally including Identity Governance. You have owned an Okta tenant end to end.
  • Hands-on Jamf Pro expertise managing a production Mac fleet, including configuration profiles, policies, smart groups, and patch workflows.
  • Proven infrastructure-as-code ownership with Terraform or OpenTofu managing real infrastructure or SaaS configuration in production, shipped through a pull-request-based GitOps workflow such as GitHub Actions.
  • Daily use of AI coding tools to ship production work.
  • Hands-on MDM depth with Jamf or Intune at fleet scale, including device compliance and trust.
  • Scripting fluency in Python, PowerShell, or a comparable language, and comfort automating against SaaS and platform APIs.
  • Clear written and verbal communication. You can explain an access policy or automation decision to an engineer and to a business stakeholder with equal clarity.

Preferred

  • Experience with a lifecycle or identity-governance orchestration layer and with HRIS-driven provisioning (Rippling, Workday, or similar).
  • Google Workspace administration at scale, including GAM7.
  • Secrets and non-human credential management (HashiCorp Vault, Doppler, Secret Manager, or equivalent).
  • Workflow and integration automation on an iPaaS or agent platform such as Workato, including human-in-the-loop steps and MCP-style tooling.
  • Exposure to compliance-driven controls and evidence automation for SOC 2 or ISO 27001 and 27701, and tooling such as Drata.
  • Google Cloud Platform and familiarity with agentic or MCP tooling for operations.
  • B2B SaaS or cybersecurity domain background.

Employee Benefits

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home. Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here .

Pay Transparancy

Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.

At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization. If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com

Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy .

Base Salary Range

$203,000 - $224,000 USD

Apply for this job

*

indicates a required field

First Name *

Last Name *

Preferred First Name

Email *

Phone

Country

Phone

Resume/CV *

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

LinkedIn Profile *

This is a hybrid role. Will you be able to come onsite our Palo Alto office 2-3 times per week? * Select...

Do you have relatives that currently work at Obsidian Security? * Select...

Will you now or in the future require visa sponsorship to work in the country where this role is based? * Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Obsidian Security’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305

Page 1 of 1

OMB Control Number 1250-0005

Expires 04/30/2026

Voluntary Self-Identification of Disability
Form CC-305 Page 1 of 1 OMB Control Number 1250-0005 Expires 04/30/2026
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp .

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury

Disability Status Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff IT Systems Engineer
Staff IT Systems Engineer

Obsidian-Security • Palo Alto (CA)

Hybrid
USD 203,000 - 224,000
Competitive compensation with equity
401k benefits
Comprehensive healthcare with dental &
+3
Enterprise Account Executive - San Francisco Bay Area - HYBRID
Enterprise Account Executive - San Francisco Bay Area - HYBRID

Obsidian Security • Palo Alto (CA)

On-site
USD 125,000 - 176,000
Competitive compensation with equity
Comprehensive healthcare
Flexible paid time off
+2
DevOps Engineer New York, New York, United States
DevOps Engineer New York, New York, United States

Octus Intelligence, Inc. • New York (NY)

On-site
USD 165,000 - 190,000
Competitive health benefits
Matched 401k plan
Generous parental leave
+1
Analytics Manager New San Francisco, California, United States
Analytics Manager New San Francisco, California, United States

Forge Global • San Francisco (CA), Northern (KY)

Hybrid
USD 120,000 - 150,000
DevOps Engineer - AWS/Ansible/Linux/Python
DevOps Engineer - AWS/Ansible/Linux/Python

Captivation Software • San Antonio (TX)

On-site
USD 130,000 - 270,000
Up to 20% 401k contribution
$3,600 HSA Contribution
Company Paid Employee Medical/Dental/Vision Insurance
Digital Optimization Lead New New York, New York, United States
Digital Optimization Lead New New York, New York, United States

Octus • New York (NY)

On-site
USD 90,000 - 105,000
Health benefits
401k matching
PTO
+4
Program Manager
Program Manager

Myriad360 • Northern (KY)

Hybrid
USD 145,000 - 155,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans for all
Company-funded 401k contributions
+1
Systems Administrator 2 - Linux/CI/CD/Ansible/Terraform/DevOps
Systems Administrator 2 - Linux/CI/CD/Ansible/Terraform/DevOps

Captivation-Software • Maryland

On-site
USD 130,000 - 270,000
Staff Product Manager, Cloud Namespace & Capacity
Staff Product Manager, Cloud Namespace & Capacity

Temporal • Northern (KY)

Hybrid
USD 185,000 - 260,000
Unlimited PTO
Holidays + Floating Holidays
Medical, Dental, Vision coverage
+1
Engineering Manager, Experimentation
Engineering Manager, Experimentation

Cervin • United States

On-site
USD 163,000 - 263,670
RSUs
Health, vision, and dental insurance
Mental health benefits
+1