Systems Engineer, Corporate Security & IAM

Ramp

New York (NY)

On-site

USD 150,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible PTO
Home-office equipment stipend
Health and wellness stipend
Travel budget
Weekly coffee stipend

Job summary

Ramp is seeking a Systems Engineer to join Corporate Security in New York. The role is hands‑on, writing code and building agentic loops to automate security across device fleets, identities, and AI tooling.

You will report to the Corporate Security lead and collaborate with IT, Security Engineering, and AI DevX. You will integrate Okta, Cloudflare, and other controls, manage macOS at scale, and automate tasks via APIs, delivering coverage reporting and scalable security operations in a

Qualifications

  • 3–5 years in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security.
  • Hands‑on macOS management at scale with MDM (Jamf, Fleet, Kandji, or equivalent).
  • Working knowledge of an identity provider (Okta or similar): SSO, MFA, policies, and conditional access.
  • Scripting ability in Python, Go, or Bash, and experience automating against platform APIs.

Responsibilities

  • Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence.
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling.
  • Maintain device configuration baselines as code, including drift detection and hardening standards.
  • Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access.
  • Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over‑scoped OAuth grants, MFA gaps, and excess privileges.
  • Implement and operate controls for enterprise AI usage, including identity‑aware access, logging and retention, DLP where appropriate, and enforcement.
  • Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated.

Skills

macOS management at scale
Okta / IAM
Python/Go/Bash scripting
EDR / vulnerability management
Policy tradeoffs communication

Tools

Jamf/MDM tooling
Cloudflare Zero Trust
CI/CD tooling (Terraform)

Job description

Ramp is seeking a Systems Engineer to join Corporate Security in New York. The role is hands‑on, writing code and building agentic loops to automate security across device fleets, identities, and AI tooling.

You will report to the Corporate Security lead and collaborate with IT, Security Engineering, and AI DevX. You will integrate Okta, Cloudflare, and other controls, manage macOS at scale, and automate tasks via APIs, delivering coverage reporting and scalable security operations in a

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Engineer, Corporate Security & IAM Automation
Systems Engineer, Corporate Security & IAM Automation

Apply • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Flexible PTO
Home-office equipment ordering
Health and wellness stipend
+7
Remote Systems Engineer, Corporate Security & IAM Automation
Remote Systems Engineer, Corporate Security & IAM Automation

Triwill Group • New York (NY), Northern (KY)

Hybrid
USD 120,000 - 190,000
Flexible PTO
Home-office equipment
Health and wellness stipend
+1
Automation-Driven Systems Engineer, Corporate Security
Automation-Driven Systems Engineer, Corporate Security

Ramp Corp. • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 210,000
Flexible PTO
Home-office equipment
Health and wellness stipend
+7
Systems Engineer, Corporate Security
Systems Engineer, Corporate Security

Ramp • New York (NY)

On-site
USD 150,000 - 210,000
Flexible PTO
Home-office equipment stipend
Health and wellness stipend
+2
Endpoint Security Architect — macOS/Windows, IaC
Endpoint Security Architect — macOS/Windows, IaC

Segment (Twilio) • New York (NY)

On-site
USD 180,000 - 240,000
Flexible PTO
Health insurance
401(k) with employer match
+1
IT Systems Engineer – Identity & Endpoint Security
IT Systems Engineer – Identity & Endpoint Security

Path Robotics, Inc. • Columbus (OH)

On-site
USD 90,000 - 120,000
Daily free lunch
Flexible PTO
Medical, dental & vision coverage
+2
Senior Security Engineer
Senior Security Engineer

Chris Baily • New York (NY)

On-site
USD 150,000 - 190,000
On-site in NYC
Competitive salary
IT Systems Engineer — Secure, Scalable IT Ops
IT Systems Engineer — Secure, Scalable IT Ops

Path Robotics • Columbus (OH)

On-site
USD 85,000 - 120,000
Daily free lunch
Flexible PTO
Medical, dental, and vision coverage
+3
Security Operations Engineer — Automate, Detect & Defend
Security Operations Engineer — Automate, Detect & Defend

K Health • New York (NY), Northern (KY)

Hybrid
USD 125,000 - 150,000
Stock options
Paid parental leave
Health, dental, and vision insurance
IT Systems Engineer: Cloud & Security Ops
IT Systems Engineer: Cloud & Security Ops

Socket.dev • Columbus (OH)

On-site
USD 90,000 - 130,000
Daily free lunch
Flexible PTO
Comprehensive medical, dental, vision
+3