Skip to content
RampRamp

Systems Engineer, Corporate Security

Build and operate automated corporate security controls across endpoint devices, identity, network access, and enterprise AI tooling. The role requires 3–5 years of endpoint, identity, or corporate security experience, strong macOS and Okta expertise, and scripting skills.

About the job

Responsibilities

  • Maintain OS and software update policies and monitor the device fleet to bring newly introduced applications into the patching cadence.
  • Automate endpoint security agent remediation across EDR, DLP, VPN, and related tooling by detecting missing, stale, or unhealthy agents and restoring device compliance.
  • Maintain device configuration baselines as code, including drift detection and hardening standards.
  • Configure Okta authentication and authenticator policies, including SSO, MFA, authenticator enrollment, device trust, and conditional access.
  • Remediate identity posture gaps such as stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges.
  • Implement and operate enterprise AI usage controls, including identity-aware access, logging and retention, DLP, and enforcement.
  • Automate across platforms using APIs, build control-coverage reporting, and document operating procedures.

Requirements

  • 3–5 years of experience in client platform/endpoint engineering, identity and access management, or corporate security.
  • Hands-on macOS management at scale using MDM such as Jamf, Fleet, Kandji, or equivalent, including macOS update mechanisms.
  • Working knowledge of an identity provider such as Okta, including SSO, authentication and authenticator policies, SCIM provisioning, and conditional access.
  • Scripting ability in Python, Go, or Bash, with experience automating against platform APIs.
  • Experience with EDR and endpoint vulnerability management, such as CrowdStrike.
  • Ability to evaluate tradeoffs among technical enforcement, policy, and user friction and explain them clearly.

Nice to have

  • osquery, Fleet, or other query-based fleet visibility tooling.
  • Identity security posture management or access review and governance platforms.
  • Cloudflare Zero Trust or other proxy, DNS, or network-layer enforcement, including TLS inspection.
  • Exposure to AI and LLM security concerns, including agent authorization, tool calls, model gateways, and data leakage through AI tooling.
  • Infrastructure as code and CI/CD experience with Terraform and GitHub Actions.
  • Windows fleet management alongside macOS.
  • Experience applying SOC 2 or PCI compliance frameworks to endpoints and access.

Benefits

  • Flexible PTO, home-office equipment, health and wellness stipend, intra-office travel budget, and weekly coffee stipend.
  • United States employees receive medical, dental, and vision coverage, One Medical membership, 401(k) with employer match, fertility HRA, paid parental leave, pet insurance, in-office perks, and possible relocation coverage to New York City or San Francisco.

Skills

macOS, MDM, Jamf, Fleet, Kandji, Okta, SSO, MFA, SCIM, Python, Go, Bash, Crowdstrike, Cloudflare Zero Trust, Terraform

OnePay

OnePay

United States

Security and Threat Operations Engineer
$140k+/yrRemote5+ YOESecurity Engineering

Protects a cloud-native fintech environment by building detections, investigating threats, operating vulnerability management, and automating security workflows. Requires 5+ years in security operations or related fields, strong Python skills, cloud experience, and expertise in telemetry-driven threat detection.

Datadog

Datadog

New York, NY

Security Engineer 2 - Cyber Threat Intelligence
$140k+/yrHybridSecurity Engineering

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.

Coinbase

Coinbase

United States

Analyst, Privacy
$135k+/yrRemote3+ YOESecurity Engineering

Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.