系统工程师,企业安全
Systems Engineer, Corporate Security
关于Ramp
Ramp正在构建财务团队的智能基础设施,嵌入企业每一美元支出的交易流程中。我们自动化处理超过2000亿美元的年度支出在70,000多家公司中的流动:授权支付、标记风险、分类支出和结账。
这些问题具有高风险、数据密集且不容错误。
我们招聘具有高度自主性和紧迫感的人才。我们更看重的是你所构建的东西,而不是你在哪里学习的。在Ramp,每个人都是从头到尾负责问题的建造者,并做出影响结果的重要决策。
Ramp的平均客户在第一年节省了5%的成本,并实现了16%的收入增长——远超没有使用Ramp的企业。我们认为每家有抱负的公司都值得拥有同样的工具。
如果你希望构建直接塑造公司如何移动和管理数十亿美元的系统,Ramp就是你的选择。
关于该职位
Ramp的公司安全团队负责我们内部环境的安全性:设备群、身份和访问层,以及员工用于工作的AI工具。我们正在招聘一名系统工程师,以在这些系统上构建和运营控制措施。
该职位需要亲自动手,尽可能通过编写代码和构建代理循环来解决问题,而不是手动解决。你将帮助通过配置即代码管理设备配置和补丁,配置Okta中的认证和认证策略,Cloudflare中的网络和网关强制执行,以及我们企业级Claude和OpenAI部署的控制措施。这些系统在实践中高度重叠,工作主要是集成它们并自动化原本需要手动管理的部分。
你将向公司安全负责人汇报,并与IT、安全工程和AI开发体验团队紧密合作。
你将负责:
- 维护操作系统和软件的更新策略,并监控设备群,确保新引入的应用程序纳入补丁周期
- 为EDR、DLP、VPN和类似工具中的端点安全代理修复建立自动化流程——检测缺失、过期或不健康的代理,并将设备带回合规状态
- 将设备配置基线作为代码维护,包括漂移检测和加固标准
- 在Okta中配置认证和认证策略:单点登录、多因素认证和认证注册、设备信任以及条件访问
- 修复身份姿态差距
查看英文原文
ABOUT RAMP
Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books.
The problems are high-stakes, data-dense, and unforgiving.
We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome.
The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same.
If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it.
ABOUT THE ROLE
Corporate Security at Ramp owns the security of our internal environment: the device fleet, the identity and access layer, and the AI tools employees use for their work. We are hiring a Systems Engineer to build and operate the controls across these systems.
The role is hands-on, writing code and building agentic loops wherever possible rather than solving problems manually. You will help manage device configuration and patching via configuration-as-code, authentication and authenticator policies in Okta, network and gateway enforcement in Cloudflare, and the controls around our enterprise Claude and OpenAI deployments. These systems overlap heavily in practice, and the work is largely about integrating them and automating what would otherwise be manual administration.
You will report to the Corporate Security lead and work closely with IT, Security Engineering, and AI DevX.
WHAT YOU'LL DO
- Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence
- Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling — detecting missing, stale, or unhealthy agents and bringing devices back into compliance
- Maintain device configuration baselines as code, including drift detection and hardening standards
- Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access
- Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges
- Implement and operate controls for enterprise AI usage, including identity-aware access, logging and retention, DLP where appropriate, and enforcement
- Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated
WHAT YOU NEED
- 3–5 years of experience in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security
- Hands-on macOS management at scale: MDM (Jamf, Fleet, Kandji, or equivalent) and macOS update mechanisms
- Working knowledge of an identity provider (Okta or similar): SSO, authentication and authenticator policies, SCIM provisioning, and conditional access
- Scripting ability in Python, Go, or Bash, and experience automating against platform APIs
- Experience with EDR and endpoint vulnerability management (CrowdStrike or similar)
- Ability to evaluate tradeoffs between technical enforcement, policy, and user friction, and to explain those tradeoffs clearly
NICE TO HAVE
- osquery and Fleet, or other query-based fleet visibility tooling
- Identity posture management (ISPM) tooling, or access review and governance platforms
- Cloudflare Zero Trust, or other proxy, DNS, or network-layer enforcement, including TLS inspection
- Exposure to AI and LLM security concerns: agent authorization, tool calls, model gateways, data leakage through AI tooling
- Infrastructure-as-code and CI/CD experience (Terraform, GitHub Actions)
- Windows fleet management alongside macOS
- Compliance frameworks (SOC 2, PCI) as they apply to endpoints and access
BENEFITS AVAILABLE TO ALL FULL-TIME RAMP EMPLOYEES (GLOBAL)
- Flexible PTO
- Centralized home-office equipment ordering
- Health and wellness stipend
- Budget for intra-office travel
- Weekly coffee stipend
UNITED STATES
- 100% medical, dental & vision insurance coverage for you, with partial coverage for dependents
- One Medical annual membership
- 401(k), including employer match on contributions made while employed by Ramp
- Fertility HRA (up to $10,000 per year)
- Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay
- Pet insurance
- In-office perks: lunch, snacks, drinks, and more
- Relocation expense coverage to NYC or SF (if needed)
CANADA
- Group medical, dental, and vision coverage through Sun Life
- Life, AD&D, and disability coverage
- Fertility drug coverage (up to $4,000 lifetime)
- Group Retirement Plan with employer match (RRSP + DPSP)
- Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay, with additional time available at reduced pay
- Employee Assistance Program and virtual care through Lumino Health
UNITED KINGDOM
- Private medical insurance through Freedom Elite
- Virtual GP and at-home care via eMed x Livi
- Workplace pension through Penfold, with salary sacrifice option
- Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay with additional time available at reduced pay
REFERRAL INSTRUCTIONS
If you are being referred for the role, please contact that person to apply on your behalf.
OTHER NOTICES
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Beware of recruiting scams: Ramp will only contact you through official @Ramp.com http://Ramp.com email addresses and will never ask for payment or sensitive personal information during the hiring process.
Ramp Applicant Privacy Notice https://ramp.com/legal/applicant-privacy-notice