The opportunity
Corporate Security at Ramp owns the security of our internal environment: the device fleet, the identity and access layer, and the AI tools employees use for their work. We are hiring a Systems Engineer to build and operate the controls across these systems.
What you'll do
Maintain update policies for both OS and software, and monitor the fleet so: that newly introduced applications are brought into the patching cadence
Build automation for endpoint security agent remediation across EDR, DLP,: VPN, and similar tooling — detecting missing, stale, or unhealthy agents and bringing devices back into compliance
Maintain device configuration baselines as code, including drift detection and hardening standards
Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access
Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges
Implement and operate controls for enterprise AI usage, including: identity-aware access, logging and retention, DLP where appropriate, and enforcement
What they're looking for
- Automate across these platforms using their APIs, build reporting on control: coverage, and document how the controls you build are operated