Obsidian Security logo
Obsidian SecurityPosted 1 month ago

Staff IT Systems Engineer

$203,000–$224,000 year

On-sitePalo Alto, California, United States

Full TimeSenior LevelSmallCybersecurity

Job Summary

Own the identity foundation by serving as the senior technical owner of Okta, managing Universal Directory, SSO, MFA, conditional access, and lifecycle orchestration from HRIS to offboarding. Operate IT as code by managing core platform configuration in version-controlled GitHub, including Okta policies, Jamf profiles, and Google Cloud infrastructure using Terraform and OpenTofu. Set standards for AI-augmented operations by authoring configuration with AI assistance, building self-service workflows for access and provisioning, and automating fleet management with zero-trust network access patterns. Partner with Security, DevOps, HR, and go-to-market teams to shape IT priorities while establishing technical standards that scale beyond individual hands.

Required Qualifications

  • 8 or more years building and operating IT systems, identity, or platform infrastructure in production, with clear ownership of the systems you ran
  • Deep, hands-on Okta ownership across SSO, MFA, Universal Directory, Lifecycle Management, and conditional access, ideally including Identity Governance. You have owned an Okta tenant end to end
  • Hands-on Jamf Pro expertise managing a production Mac fleet, including configuration profiles, policies, smart groups, and patch workflows
  • Proven infrastructure-as-code ownership with Terraform or OpenTofu managing real infrastructure or SaaS configuration in production, shipped through a pull-request-based GitOps workflow such as GitHub Actions
  • Daily use of AI coding tools to ship production work
  • Hands-on MDM depth with Jamf or Intune at fleet scale, including device compliance and trust
  • Scripting fluency in Python, PowerShell, or a comparable language, and comfort automating against SaaS and platform APIs
  • Clear written and verbal communication. You can explain an access policy or automation decision to an engineer and to a business stakeholder with equal clarity

Desired Qualifications

  • Experience with a lifecycle or identity-governance orchestration layer and with HRIS-driven provisioning (Rippling, Workday, or similar)
  • Google Workspace administration at scale, including GAM7
  • Secrets and non-human credential management (HashiCorp Vault, Doppler, Secret Manager, or equivalent)
  • Workflow and integration automation on an iPaaS or agent platform such as Workato, including human-in-the-loop steps and MCP-style tooling
  • Zero-trust network access (Jamf Connect, Zscaler, Tailscale, or similar) and enterprise browser deployments
  • Exposure to compliance-driven controls and evidence automation for SOC 2 or ISO 27001 and 27701, and tooling such as Drata
  • Google Cloud Platform and familiarity with agentic or MCP tooling for operations
  • B2B SaaS or cybersecurity domain background

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce