Systems Engineer

WorkOS, Inc.
United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services User Authentication Bash Shell Software as a Service Cloud Computing Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language)
+16 more
Networking Basics OAuth Security Assertion Markup Language (SAML) Systems Integration Scripting Okta Large Language Models Firewalls (Computer Science) Information Technology Casper Suite Gsuite Restful APIs Terraform Webhooks GPT User Administration

Job description

As a Systems Engineer at WorkOS, you will be the technical backbone of our internal IT organization - designing the systems, automations, and infrastructure that scale our internal operations. This is not a help desk role: you will architect endpoint management workflows, write scripts, ship automation, and build the foundation that keeps a fast-growing company running smoothly.

We have an MSP partner handling tier 1 support. Your job is to architect the systems the MSP executes against, automate everything upstream, and serve as the escalation point for complex tier 2/3 issues. You will own identity, device management, SaaS lifecycle, and the automation layer that ties it all together., * Own and evolve our identity infrastructure - Okta (SSO, MFA, Workflows, SCIM provisioning, lifecycle management), Google Workspace, and downstream SaaS integrations

  • Architect and ship automation across the IT stack - onboarding/offboarding workflows, access controls, license governance, and SaaS lifecycle management
  • Own macOS endpoint management end-to-end - zero-touch provisioning, policy enforcement, detection and remediation scripting via MDM
  • Manage infrastructure as code using Terraform for identity, SaaS, and cloud resources
  • Serve as the escalation point for complex systems issues (tier 2/3) - working with our MSP partner to ensure smooth resolution
  • Evaluate and enable new SaaS tools - pilot emerging technologies including AI-powered IT automation
  • Create documentation and runbooks that reduce operational toil and increase durability
  • Drive an automation-first culture across the IT function - if it can be automated, it should be

Requirements

We’re looking for engineers who build and automate, not just operate. You think in systems - understanding how identity, devices, SaaS tools, and cloud infrastructure connect - and your instinct is to eliminate manual work. You might be a great fit if you:

  • Have deep Okta expertise - not just user administration, but Workflows, integrations, and policy design
  • Write scripts (Python, Bash) to automate what others do manually
  • Use Terraform to manage infrastructure as code - not just for cloud, but for identity and SaaS configuration
  • Understand SSO protocols (SAML, OAuth, SCIM) deeply enough to troubleshoot and architect, not just configure
  • Are comfortable managing a macOS fleet end-to-end - zero-touch provisioning, policy enforcement, MDM
  • Think about AI as a tool for IT automation - you are curious about using LLMs and agentic workflows to eliminate toil
  • Take ownership, work independently, and follow through from identifying a problem to shipping a solution, * 7+ years in IT systems, infrastructure, or identity engineering roles - with clear examples of designing, building, and automating at scale (not just operating)
  • Deep experience with Okta - Workflows, integrations, policy design, SCIM provisioning (not just user administration)
  • Proficiency in scripting (Python, Bash) and comfort with REST APIs, webhooks, and authentication flows
  • Hands-on Terraform experience for managing infrastructure and configuration as code
  • Strong macOS fleet management - MDM (Jamf, Kandji, or equivalent), scripting, zero-touch provisioning
  • Deep understanding of SSO protocols (SAML, OAuth 2.0) and SCIM provisioning patterns
  • Experience with Google Workspace administration at scale
  • Solid understanding of networking fundamentals - DNS, HTTP, APIs, VPNs, firewalls

Nice to Have

  • Experience with AI/LLM tools for IT automation (agentic workflows, ChatGPT/Claude for scripting, Okta + AI integrations)
  • GitOps or declarative approaches to device and identity management
  • Cloud infrastructure experience (GCP or AWS)
  • SOC 2 or ISO 27001 compliance experience
  • Experience operating in an MSP-augmented IT model

Benefits & conditions

At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.

Benefits include:

  • Competitive pay

  • Substantial equity grants

  • Healthcare insurance (Medical, Dental and Vision) for you and your family

  • 401k matching

  • Wellness and fitness monthly allowances

  • PTO + paid holidays + unlimited sick leave

About the company

WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations. We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Vercel, and Plaid. As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control-helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com

Good distractions

Talks and stories from around this role β€” technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 Β· Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz Β· WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 Β· LIVE

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 Β· WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz Β· WWC Europe 2026

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu Β· WWC 2023

Videos

See all

Related articles

See all