Systems Engineer, Corporate Security

Ramp

New York (NY)

On-site

USD 150,000 - 210,000

Full time

44 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible PTO
Home-office equipment stipend
Health and wellness stipend
Travel budget
Weekly coffee stipend

Job summary

Ramp is seeking a Systems Engineer to join Corporate Security in New York. The role is hands‑on, writing code and building agentic loops to automate security across device fleets, identities, and AI tooling.

You will report to the Corporate Security lead and collaborate with IT, Security Engineering, and AI DevX. You will integrate Okta, Cloudflare, and other controls, manage macOS at scale, and automate tasks via APIs, delivering coverage reporting and scalable security operations in a

Qualifications

  • 3–5 years in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security.
  • Hands‑on macOS management at scale with MDM (Jamf, Fleet, Kandji, or equivalent).
  • Working knowledge of an identity provider (Okta or similar): SSO, MFA, policies, and conditional access.
  • Scripting ability in Python, Go, or Bash, and experience automating against platform APIs.

Responsibilities

  • Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence.
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling.
  • Maintain device configuration baselines as code, including drift detection and hardening standards.
  • Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access.
  • Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over‑scoped OAuth grants, MFA gaps, and excess privileges.
  • Implement and operate controls for enterprise AI usage, including identity‑aware access, logging and retention, DLP where appropriate, and enforcement.
  • Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated.

Skills

macOS management at scale
Okta / IAM
Python/Go/Bash scripting
EDR / vulnerability management
Policy tradeoffs communication

Tools

Jamf/MDM tooling
Cloudflare Zero Trust
CI/CD tooling (Terraform)

Job description

About Ramp

Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books.

About Ramp

Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. The problems are high-stakes, data-dense, and unforgiving. We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it.

About The Role

Corporate Security at Ramp owns the security of our internal environment: the device fleet, the identity and access layer, and the AI tools employees use for their work. We are hiring a Systems Engineer to build and operate the controls across these systems. The role is hands‑on, writing code and building agentic loops wherever possible rather than solving problems manually. You will help manage device configuration and patching via configuration-as-code, authentication and authenticator policies in Okta, network and gateway enforcement in Cloudflare, and the controls around our enterprise Claude and OpenAI deployments. These systems overlap heavily in practice, and the work is largely about integrating them and automating what would otherwise be manual administration. You will report to the Corporate Security lead and work closely with IT, Security Engineering, and AI DevX.

What you'll do
  • Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling — detecting missing, stale, or unhealthy agents and bringing devices back into compliance
  • Maintain device configuration baselines as code, including drift detection and hardening standards
  • Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access
  • Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over‑scoped OAuth grants, MFA gaps, and excess privileges
  • Implement and operate controls for enterprise AI usage, including identity‑aware access, logging and retention, DLP where appropriate, and enforcement
  • Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated
What you need
  • 3–5 years of experience in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security
  • Hands‑on macOS management at scale: MDM (Jamf, Fleet, Kandji, or equivalent) and macOS update mechanisms
  • Working knowledge of an identity provider (Okta or similar): SSO, authentication and authenticator policies, SCIM provisioning, and conditional access
  • Scripting ability in Python, Go, or Bash, and experience automating against platform APIs
  • Experience with EDR and endpoint vulnerability management (CrowdStrike or similar)
  • Ability to evaluate tradeoffs between technical enforcement, policy, and user friction, and to explain those tradeoffs clearly
Nice to have
  • osquery and Fleet, or other query-based fleet visibility tooling
  • Identity posture management (ISPM) tooling, or access review and governance platforms
  • Cloudflare Zero Trust, or other proxy, DNS, or network-layer enforcement, including TLS inspection
  • Exposure to AI and LLM security concerns: agent authorization, tool calls, model gateways, data leakage through AI tooling
  • Infrastructure‑as‑code and CI/CD experience (Terraform, GitHub Actions)
  • Windows fleet management alongside macOS
  • Compliance frameworks (SOC 2, PCI) as they apply to endpoints and access
Benefits Available To All Full-time Ramp Employees (Global)
  • Flexible PTO
  • Centralized home‑office equipment ordering
  • Health and wellness stipend
  • Budget for intra‑office travel
  • Weekly coffee stipend
United States
  • 100% medical, dental & vision insurance coverage for you, with partial coverage for dependents
  • One Medical annual membership
  • 401(k), including employer match on contributions made while employed by Ramp
  • Fertility HRA (up to $10,000 per year)
  • Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay
  • Pet insurance
  • In‑office perks: lunch, snacks, drinks, and more
  • Relocation expense coverage to NYC or SF (if needed)
Canada
  • Group medical, dental, and vision coverage through Sun Life
  • Life, AD&D, and disability coverage
  • Fertility drug coverage (up to $4,000 lifetime)
  • Group Retirement Plan with employer match (RRSP + DPSP)
  • Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay, with additional time available at reduced pay
  • Employee Assistance Program and virtual care through Lumino Health
United Kingdom
  • Private medical insurance through Freedom Elite
  • Virtual GP and at‑home care via eMed x Livi
  • Workplace pension through Penfold, with salary sacrifice option
  • Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay with additional time available at reduced pay
Referral Instructions

If you are being referred for the role, please contact that person to apply on your behalf.

Other Notices

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Beware of recruiting scams: Ramp will only contact you through official @Ramp.com email addresses and will never ask for payment or sensitive personal information during the hiring process.

Ramp Applicant Privacy Notice

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Engineer, Corporate Security
Systems Engineer, Corporate Security

Apply • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Flexible PTO
Home-office equipment ordering
Health and wellness stipend
+7
Systems Engineer, Corporate Security
Systems Engineer, Corporate Security

Ramp Corp. • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 210,000
Flexible PTO
Home-office equipment
Health and wellness stipend
+7
Security Engineer, Product
Security Engineer, Product

Visa Hunt • New York (NY)

On-site
USD 140,000 - 210,000
Medical insurance
One Medical annual membership
401(k) with employer match
+2
Security Engineer, Cloud
Security Engineer, Cloud

Visa Hunt • New York (NY)

On-site
USD 140,000 - 190,000
Flexible PTO
Home-office equipment
Health and wellness stipend
+2
Software Engineer, Engineering Platform
Software Engineer, Engineering Platform

Visa Hunt • United States

On-site
USD 180,000 - 240,000
Flexible PTO
Centralized home-office equipment
Health and wellness stipend
+6
Senior Security Engineer, Endpoint
Senior Security Engineer, Endpoint

Segment (Twilio) • New York (NY)

On-site
USD 180,000 - 240,000
Flexible PTO
Health insurance
401(k) with employer match
+1
Software Engineer, Enterprise Product
Software Engineer, Enterprise Product

Ramp • San Francisco (CA)

On-site
USD 140,000 - 210,000
Flexible PTO
Centralized home-office equipment
Health and wellness stipend
+2
Senior Security Engineer, Endpoint
Senior Security Engineer, Endpoint

Visa Hunt • New York (NY)

On-site
USD 140,000 - 210,000
Flexible PTO
Home-office stipend
Health stipend
+2
Security Engineer (Product)
Security Engineer (Product)

Ramp • New York (NY)

On-site
USD 120,000 - 160,000
100% medical, dental & vision insurance
401k with employer match
Flexible PTO
+8
Software Engineer, Forward Deployed
Software Engineer, Forward Deployed

Ramp Corp. • San Francisco (CA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Flexible PTO
Health and wellness stipend
Relocation assistance
+2