← Back to jobs

Systems Engineer, Corporate Security

Company
Ramp
Location
New York, NY
Work type
Full Time
Posted
2026-09-14

Job description

About the role
Corporate Security at Ramp owns the security of our internal environment: the device fleet, the identity and access layer, and the AI tools employees use for their work. We are hiring a Systems Engineer to build and operate the controls across these systems.

The role is hands-on, writing code and building agentic loops wherever possible rather than solving problems manually. You will help manage device configuration and patching via configuration-as-code, authentication and authenticator policies in Okta, network and gateway enforcement in Cloudflare, and the controls around our enterprise Claude and OpenAI deployments. These systems overlap heavily in practice, and the work is largely about integrating them and automating what would otherwise be manual administration.

You will report to the Corporate Security lead and work closely with IT, Security Engineering, and AI DevX.

What you'll do
Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence

Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling — detecting missing, stale, or unhealthy agents and bringing devices back into compliance

Maintain device configuration baselines as code, including drift detection and hardening standards

Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access

Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges

Implement and operate controls for enterprise AI usage, including identity-aware access, logging and retention, DLP where appropriate, and enforcement

Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated

What you need
3–5 years of experience in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security

Hands-on macOS management at scale: MDM (Jamf, Fleet, Kandji, or equivalent) and macOS update mechanisms

Working knowledge of an identity provider (Okta or similar): SSO, authentication and authenticator policies, SCIM provisioning, and conditional access

Scripting ability in Python, Go, or Bash, and experience automating against platform APIs

Experience with EDR and endpoint vulnerability management (CrowdStrike or similar)

Ability to evaluate tradeoffs between technical enforcement, policy, and user friction, and to explain those tradeoffs clearly

Nice to have
osquery and Fleet, or other query-based fleet visibility tooling

Identity posture management (ISPM) tooling, or access review and governance platforms

Cloudflare Zero Trust, or other proxy, DNS, or network-layer enforcement, including TLS inspection

Exposure to AI and LLM security concerns: agent authorization, tool calls, model gateways, data leakage through AI tooling

Infrastructure-as-code and CI/CD experience (Terraform, GitHub Actions)

Windows fleet management alongside macOS

Compliance frameworks (SOC 2, PCI) as they apply to endpoints and access

Original source