Systems Engineer, Corporate Security & IAM Automation

Apply

New York, Northern (NY, KY)

Hybrid

USD 140,000 - 190,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible PTO
Home-office equipment ordering
Health and wellness stipend
Intra-office travel budget
Weekly coffee stipend
Medical, dental & vision insurance (US
One Medical membership
401(k) with employer match
Parental leave
Pet insurance

Job summary

Ramp is seeking a Systems Engineer for Corporate Security to own the security of our internal environment: device fleet, identity and access layer, and AI tooling. The role is hands-on, with code and automation, using configuration-as-code, Okta policies, Cloudflare enforcement, and enterprise AI controls.

You will partner with IT, Security Engineering, and AI DevX to implement, monitor, and automate these controls, document operation, handle patching cadence, and report on coverage and risk

Qualifications

  • 3–5 years of experience in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security.
  • Hands-on macOS management at scale: MDM (Jamf, Fleet, Kandji, or equivalent) and macOS update mechanisms.
  • Working knowledge of an identity provider (Okta or similar): SSO, authentication and authenticator policies, SCIM provisioning, and conditional access.
  • Scripting ability in Python, Go, or Bash, and experience automating against platform APIs.
  • Experience with EDR and endpoint vulnerability management (CrowdStrike or similar).
  • Ability to evaluate tradeoffs between technical enforcement, policy, and user friction, and to explain those tradeoffs clearly.

Responsibilities

  • Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence.
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling — detecting missing, stale, or unhealthy agents and bringing devices back into compliance.
  • Maintain device configuration baselines as code, including drift detection and hardening standards.
  • Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access.
  • Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges.
  • Implement and operate controls for enterprise AI usage, including identity-aware access, logging and retention, DLP where appropriate, and enforcement.
  • Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated.

Skills

macOS management at scale
Okta SSO & MFA
Scripting: Python/Go/Bash
APIs automation
EDR & vulnerability management
IAM & policy tradeoffs

Tools

Jamf
Fleet
Kandji
Okta
Cloudflare Zero Trust
Terraform
GitHub Actions

Job description

Ramp is seeking a Systems Engineer for Corporate Security to own the security of our internal environment: device fleet, identity and access layer, and AI tooling. The role is hands-on, with code and automation, using configuration-as-code, Okta policies, Cloudflare enforcement, and enterprise AI controls.

You will partner with IT, Security Engineering, and AI DevX to implement, monitor, and automate these controls, document operation, handle patching cadence, and report on coverage and risk

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Engineer, Corporate Security & IAM
Systems Engineer, Corporate Security & IAM

Ramp • New York (NY)

On-site
USD 150,000 - 210,000
Flexible PTO
Home-office equipment stipend
Health and wellness stipend
+2
Automation-Driven Systems Engineer, Corporate Security
Automation-Driven Systems Engineer, Corporate Security

Ramp Corp. • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 210,000
Flexible PTO
Home-office equipment
Health and wellness stipend
+7
Remote Systems Engineer, Corporate Security & IAM Automation
Remote Systems Engineer, Corporate Security & IAM Automation

Triwill Group • New York (NY), Northern (KY)

Hybrid
USD 120,000 - 190,000
Flexible PTO
Home-office equipment
Health and wellness stipend
+1
Systems Engineer, Corporate Security
Systems Engineer, Corporate Security

Ramp • New York (NY)

On-site
USD 150,000 - 210,000
Flexible PTO
Home-office equipment stipend
Health and wellness stipend
+2
Cloud Security Engineer: FedRAMP & AI‑Driven Automation
Cloud Security Engineer: FedRAMP & AI‑Driven Automation

Pegasystems • Virginia (MN)

On-site
USD 86,000 - 130,000
Employee equity
Annual bonus
Benefits program
Security Engineer: Infra & Client Platform
Security Engineer: Infra & Client Platform

Reliable Robotics Corporation • United States

Remote
USD 120,000 - 180,000
Endpoint Security Architect — macOS/Windows, IaC
Endpoint Security Architect — macOS/Windows, IaC

Segment (Twilio) • New York (NY)

On-site
USD 180,000 - 240,000
Flexible PTO
Health insurance
401(k) with employer match
+1
Fraud & Identity Systems Engineer
Fraud & Identity Systems Engineer

Ramp • United States

Remote
USD 130,000 - 170,000
Senior Enterprise Security Engineer - IAM & AI Automation
Senior Enterprise Security Engineer - IAM & AI Automation

Pave • San Francisco (CA)

Hybrid
USD 210,000 - 240,000
Equity
Medical, dental, vision
Flexible PTO
+5
Senior Corporate Security Engineer — IAM & AI Automation
Senior Corporate Security Engineer — IAM & AI Automation

Trov • San Francisco (CA), Northern (KY)

Hybrid
USD 210,000 - 260,000
Health, dental, and vision coverage
Flexible PTO
Commuter stipend
+3