Remote job
IT Systems Engineer
Job details
About this role
Role overview An engineering-focused position owns the full corporate IT stack—identity, device management, endpoint security, and the automation that connects them. The role is hands-on and emphasizes software-engineering rigor over help desk work, applying modern infrastructure practices to internal systems within a crypto/blockchain organization.
Responsibilities - Design and automate the end-to-end identity lifecycle from HRIS through Okta into SaaS applications, removing manual provisioning and offboarding gaps - Build and maintain SSO and SCIM integrations across the entire SaaS portfolio - Operate Jamf Pro at production scale, including PreStage enrollment, configuration profiles, software update management, and certificate distribution on macOS - Deploy and tune an EDR platform such as SentinelOne, covering policy configuration, MDM-driven rollout, and alert triage - Expand SIEM coverage and author detection and alerting rules using a detection-as-code methodology - Move IT tooling toward infrastructure-as-code management with Terraform and GitHub Actions - Resolve complex identity, device, and access escalations that exceed first-line support - Advance SOC 2 readiness by unifying audit trails across identity, device, and security systems
Requirements - 4+ years in IT engineering roles - Production Okta administration skills, including SSO, SCIM, SAML/OIDC integrations, lifecycle policies, and Okta Workflows, with an HRIS-as-source-of-truth model - Hands-on Jamf Pro experience covering PreStage enrollment, configuration profiles, software updates, and certificate distribution on macOS - Experience deploying and operating an EDR platform (SentinelOne or comparable), including policy tuning and alert triage - Strong scripting ability in Python, Bash, or Go, plus comfort with REST APIs, webhooks, JSON, auth flows, and event-driven workflows - Git-based configuration management, CI/CD with GitHub Actions, and Terraform or equivalent tooling - Working knowledge of DNS, certificates and PKI, ZTNA solutions such as Tailscale, and modern access control models
Nice to have - Security exposure to crypto and blockchain environments, including multisig or hardware-wallet workflows, phishing defense, and high-value signer threat modeling - Detection-as-code experience with Panther Python models, Sigma, or similar rule formats - Deep Apple platform expertise beyond basic Jamf, including DDM, MDM protocol internals, notarization, signing, packaging, and macOS security frameworks such as TCC and system extensions - Familiarity mapping controls to SOC 2, ISO 27001, NIST CSF, or CIS frameworks and producing audit-ready evidence - Experience building Slack-driven workflows, bots, or self-service internal tooling - Public open-source contributions to IT or security tooling