SlipstreamJobsFresh Startup & VC-Backed Jobs

Systems Engineer, Corporate Security

Ramp - New York, NY, United States - In-office - posted 2026-09-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Ramp is building smart infrastructure for finance teams, automating how over $200B in annualized spend flows through 70,000+ companies. The Corporate Security team owns the security of Ramp's internal environment: device fleet, identity and access layer, and AI tools used by employees. You will be a hands-on Systems Engineer responsible for building and operating controls across these interconnected systems. The role emphasizes writing code and building automation rather than manual administration. You will manage device configuration and patching via configuration-as-code, handle authentication and authenticator policies in Okta, enforce network and gateway controls in Cloudflare, and implement controls around enterprise Claude and OpenAI deployments. The work involves integrating these systems and automating what would otherwise be manual administration tasks. Key responsibilities include: - Maintain OS and software update policies, monitor the fleet, and bring newly introduced applications into the patching cadence - Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tools—detecting missing, stale, or unhealthy agents and restoring device compliance - Maintain device configuration baselines as code with drift detection and hardening standards - Configure authentication and authenticator policies in Okta: SSO, MFA enrollment, device trust, and conditional access - Remediate identity posture gaps: stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges - Implement and operate controls for enterprise AI usage, including identity-aware access, logging, retention, DLP, and enforcement - Automate across platforms using APIs, build reporting on control coverage, and document operations You will report to the Corporate Security lead and work closely with IT, Security Engineering, and AI DevX teams. REQUIREMENTS: - 3–5 years of experience in Client Platform Engineering, Endpoint Engineering, Identity Access & Management, or Corporate Security - Hands-on macOS management at scale: MDM (Jamf, Fleet, Kandji, or equivalent) and macOS update mechanisms - Working knowledge of an identity provider (Okta or similar): SSO, authentication and authenticator policies, SCIM provisioning, and conditional access - Scripting ability in Python, Go, or Bash, and experience automating against platform APIs - Experience with EDR and endpoint vulnerability management (CrowdStrike or similar) - Ability to evaluate tradeoffs between technical enforcement, policy, and user friction, and to explain those tradeoffs clearly NICE TO HAVE: - osquery and Fleet, or other query-based fleet visibility tooling - Identity posture management (ISPM) tooling or access review and governance platforms - Cloudflare Zero Trust or other proxy, DNS, or network-layer enforcement, including TLS inspection - Exposure to AI and LLM security concerns: agent authorization, tool calls, model gateways, data leakage through AI tooling - Infrastructure-as-code and CI/CD experience (Terraform, GitHub Actions) - Windows fleet management alongside macOS - Compliance frameworks (SOC 2, PCI) as they apply to endpoints and access

Similar roles