Obsidian Security Logo

Obsidian Security

Staff IT Systems Engineer

Reposted 16 Days Ago
Be an Early Applicant
In-Office
Palo Alto, CA, USA
203K-224K Annually
Senior level
In-Office
Palo Alto, CA, USA
203K-224K Annually
Senior level
Senior IT Systems Engineer owns identity, endpoint, and IT platform foundation. Lead Okta lifecycle and SSO, manage Jamf Mac fleet, implement infrastructure-as-code (Terraform/OpenTofu) in GitHub, build AI-augmented operations, automate device compliance and provisioning, mentor teammates, and partner cross-functionally on security, compliance, and platform priorities.
The summary above was generated by AI

Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, including many of the world’s largest Fortune 1000 and Global 2000 companies.

Founded in 2017 and backed by top investors like Greylock, Obsidian was built to close a critical gap: securing SaaS apps where business happens—Microsoft 365, Salesforce, and hundreds more. The company does this by offering a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Obsidian was built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. Now, they’re transforming how SaaS is secured.

With AI driving rapid SaaS growth and complexity, agentic AI tools gain privileged access to sensitive data through integrations, creating new risks most security tools miss. Obsidian uniquely detects anomalous OAuth token activity and manages integration risks. Major announcements are on the horizon. Recognizing that SaaS security needs to evolve, Obsidian enables growing organizations to start with a lightweight, prevention-focused browser extension and expand coverage over time.

With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise ahead, Obsidian is scaling rapidly toward long-term growth and IPO readiness.

We're hiring an experienced Staff IT Systems Engineer to be the senior technical owner of Obsidian's identity, endpoint, and IT platform foundation, and to help us operate that foundation as code. You will own how identity flows from our HR system into Okta and out to every application, how our device fleet is managed and hardened, and how the configuration behind all of it lives as version-controlled, AI- and human-authored code. You will set the bar for how a modern, security-first IT organization runs in an AI-forward company.

This is a high-leverage seat at a pivotal moment. Our identity platform is being stood up with a lifecycle orchestration layer in front of it, and we are moving the whole stack onto an infrastructure-as-code operating model. We are looking for a senior technical owner to set the bar for identity architecture, configuration-as-code, AI-augmented operations, and how a lean IT function leverages AI and automation to grow the function. 

You will report directly to the VP of Business Systems, Data & IT. You will partner closely with Security, DevOps, HR, Finance, and the go-to-market teams, and you will collaborate with teammates across the Business Systems, Data & IT function.

What You'll Do

Own the identity foundation

  • Serve as the senior technical owner of Okta as our primary identity provider, covering Universal Directory, SSO, MFA (Okta Verify FastPass and FIDO2), conditional access, Device Access, and Okta Identity Governance for access certifications and reporting.
  • Own the lifecycle orchestration that turns HR events into access. This includes joiner, mover, and leaver flows from our HRIS through the orchestration layer into Okta, with same-hour offboarding.
  • Own the SSO application catalog across our estate of applications: sequence the integrations, enforce group-based access by role, and make the catalog the definition of what is sanctioned.

Operate IT as code

  • Manage core platform configuration as version-controlled code in our corporate GitHub organization. This spans Okta policies, groups, group rules, app assignments, and governance campaigns; Jamf profiles, policies, and smart groups; the GitHub organization itself; and the underlying Google Cloud foundation, using OpenTofu and Terraform.
  • Bring imperative surfaces under the same discipline. Manage Google Workspace through scripts in git, run keyless through Workload Identity Federation, with verification and drift reporting where true state management is not possible.

Set the standard for AI-augmented operations

  • Author configuration with AI assistance from the start. You will set the team standard for what good looks like here.
  • Use read-only tooling for live observability, drift triage, and log investigation, with humans gating every production change.
  • Build AI-assisted IT support and self-service workflows on our automation platform so routine requests for access, provisioning, and license changes resolve without a ticket queue and a manual handoff.

Automate and harden the fleet

  • Own endpoint management across platforms with device trust and assurance wired into access policies, automated third-party patching, and application allowlisting.
  • Advance zero-trust network access and secrets-management patterns so identity and device health decide access.

Raise the bar across IT

  • Set technical standards for the IT function, document them so they scale beyond your own hands, mentor teammates, and be the person others learn identity and automation from.
  • Partner with the VP to shape IT priorities and sequencing, and represent IT's requirements in cross-functional security, compliance, and platform decisions.
What You'll Bring

We know few candidates match every line below. If you own most of the required list and are excited by the rest, we want to hear from you.

Requirements:

  • 8 or more years building and operating IT systems, identity, or platform infrastructure in production, with clear ownership of the systems you ran.
  • Deep, hands-on Okta ownership across SSO, MFA, Universal Directory, Lifecycle Management, and conditional access, ideally including Identity Governance. You have owned an Okta tenant end to end.
  • Hands-on Jamf Pro expertise managing a production Mac fleet, including configuration profiles, policies, smart groups, and patch workflows.
  • Proven infrastructure-as-code ownership with Terraform or OpenTofu managing real infrastructure or SaaS configuration in production, shipped through a pull-request-based GitOps workflow such as GitHub Actions.
  • Daily use of AI coding tools to ship production work.
  • Hands-on MDM depth with Jamf or Intune at fleet scale, including device compliance and trust.
  • Scripting fluency in Python, PowerShell, or a comparable language, and comfort automating against SaaS and platform APIs.
  • Clear written and verbal communication. You can explain an access policy or automation decision to an engineer and to a business stakeholder with equal clarity.

Preferred

  • Experience with a lifecycle or identity-governance orchestration layer and with HRIS-driven provisioning (Rippling, Workday, or similar).
  • Google Workspace administration at scale, including GAM7.
  • Secrets and non-human credential management (HashiCorp Vault, Doppler, Secret Manager, or equivalent).
  • Workflow and integration automation on an iPaaS or agent platform such as Workato, including human-in-the-loop steps and MCP-style tooling.
  • Zero-trust network access (Jamf Connect, Zscaler, Tailscale, or similar) and enterprise browser deployments.
  • Exposure to compliance-driven controls and evidence automation for SOC 2 or ISO 27001 and 27701, and tooling such as Drata.
  • Google Cloud Platform and familiarity with agentic or MCP tooling for operations.
  • B2B SaaS or cybersecurity domain background.

Employee Benefits

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.  Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off 
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here.

Pay Transparancy

Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.

At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization.  If you have a need that requires accommodation, please contact [email protected]

Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy.

Base Salary Range
$203,000$224,000 USD

Obsidian Security Palo Alto, California, USA Office

577 College Ave , Palo Alto, United States, 94306

Similar Jobs

16 Days Ago
In-Office
San Jose, CA, USA
152K-190K Annually
Mid level
152K-190K Annually
Mid level
Aerospace
The Staff IT Systems Engineer will manage IT infrastructure, contribute to systems architecture, administer collaboration tools, ensure compliance, and drive integration in a growth-oriented environment.
Top Skills: AtlassianGoogle WorkspaceIdentity Management (Okta/Entra)MiroNotionSaas PlatformsSlackVdiWindows Operating SystemsZoom
2 Days Ago
In-Office
115K-140K Annually
Senior level
115K-140K Annually
Senior level
Aerospace
The Senior IT Systems Engineer will enhance IT systems, manage cloud infrastructure, support deployments, automate processes, troubleshoot issues, and ensure effective operations.
Top Skills: Active DirectoryAutomationAWSAzureCertificate ManagementConfiguration ManagementDhcpDnsGroup PolicyInfrastructure As CodeKubernetesLinuxNetappO365Pure StorageServer And Storage HardwareVMwareVoip Phone SystemsWindows Server
An Hour Ago
Hybrid
Menlo Park, CA, USA
75K-125K Annually
Senior level
75K-125K Annually
Senior level
Digital Media • Information Technology • News + Entertainment
Responsible for selling Comcast Internet, Data, Video and Voice services to small and mid-size businesses. Generate new leads, deliver face-to-face presentations, promote bundled solutions, manage a territory and pipeline, meet/exceed sales targets, and coordinate with technical and support teams to ensure customer satisfaction.
Top Skills: Comcast Business ServicesComcast InternetComcast VideoComcast VoiceHosted PbxPri

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account