> Markdown version of [/jobs/ext/2280437-it-security-engineer](https://www.wearedevelopers.com/jobs/ext/2280437-it-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT & Security Engineer - **Company:** Ultimate Staffing Services - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Access, Microsoft Windows, Application Programming Interfaces (APIs), Apple Mac Systems, JIRA, Audit Trail, Backup Devices, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Data Retention, Linux, Disaster Recovery, Domain Name System (DNS), Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Key Management, Network Security, Public Key Infrastructure, Role-Based Access Control, Phishing, Zero Trust Network Access, Security Information and Event Management, Tripwire, Software Vulnerability Management, Scripting, Okta, Kubernetes, Information Technology, Atlassian Tools, Hashicorp, Cloudflare, Casper Suite, Gsuite, Splunk, Security Orchestration, Automation & Response - **Published:** August 28, 2026 - **Apply:** https://www.jofdav.com/jobs/59422640-it-security-engineer ## About the Role Typical Experience: 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS., * 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS. * Working knowledge of the ISO 27001 and NIST CSF 2.0 frameworks and their practical application. * Hands-on experience with Okta, Google Workspace, and Jira/Atlassian. * Hands-on GCP experience, including IAM, Security Command Center, org-level security policies, and audit logging. * Experience with Cloudflare - WAF/security rules, Access (Zero Trust), DNS, and API protection. * Experience managing a vulnerability disclosure program or bug bounty programme (HackerOne or equivalent). * Hands-on experience with the Wazuh Security Platform or a comparable HIDS/security monitoring platform. * Experience with HashiCorp Vault for secrets management and PKI/certificate authority operations. * Experience operating a SIEM (Splunk or equivalent), including rule authoring, alert triage, and incident reporting. * Familiarity with Kubernetes security - RBAC, pod security, and workload hardening. * Vulnerability management experience across scanning, triage, and remediation tracking. * MDM platform experience with Jamf or equivalent. * Experience owning IT asset management - maintaining an accurate hardware, software, and licence inventory from procurement through secure decommissioning. * Experience running employee IT onboarding and offboarding, including device provisioning, account and access setup, and prompt access revocation and hardware recovery on exit. * Demonstrable commitment to least privilege access and access lifecycle management. * Proven ability to deliver IT and security projects independently. * Excellent written and verbal English, and comfort working across global, cross-functional teams. Preferred Qualifications * Security certification such as CISSP, CompTIA Security+, Google Professional Cloud Security Engineer, or equivalent. * ISO 27001 Lead Implementer or Lead Auditor certification. * Experience designing or implementing a full Zero Trust network architecture. * Scripting ability in Python or Bash for security automation and tooling. * Experience with asset management tools such as Snipe-IT or equivalent. * Familiarity with container security tooling such as Trivy, Falco, or equivalent. * Prior experience in a high-growth tech or scale-up environment. ## Description Scope of Ownership: Owns the full lifecycle of IT hardware and software across Linux, Windows, and macOS (including the asset inventory and the employee onboarding and offboarding process) together with Company's security operations stack: vulnerability management, HIDS/SIEM, secrets and PKI, cloud and network security controls, and identity administration. Accountable for the reliability of these systems and for the state of the controls they enforce. * Decision Authority: Final call on endpoint, network, and access configuration standards, on remediation priority and timelines for identified vulnerabilities, and on tooling choices within the IT and security estate. Recommends and escalates on risk acceptance, budget, and policy decisions. * Autonomy: Operates independently as the hands-on owner of a broad, mixed workload. Sets priorities across incident response, project delivery, and support commitments, and reprioritizes without waiting for direction when a security event or business need demands it. * Cross-Functional Influence: Works across Engineering, Platform, Legal & Compliance, People Operations, and Finance - partnering with engineering teams on Kubernetes and cloud security reviews, with People Operations on onboarding and offboarding, and with Finance on SaaS procurement and renewals. Drives security awareness across the whole company through training and phishing simulation. * External Representation: Serves as the escalation point for complex IT and security issues across global teams, is the primary technical contact for the HackerOne VDP and its researchers, and represents Company's controls to auditors and to vendors., * Infrastructure & Endpoints: Manage the full lifecycle of IT hardware and software across Linux, Windows, and macOS. Own VPNs, backups, disaster recovery, MDM, and endpoint security, and serve as the escalation point for complex issues across global teams. * Security Operations: Drive Company's security posture in alignment with ISO 27001 and NIST CSF 2.0. Own vulnerability management, the HackerOne vulnerability disclosure program, and security incident response. Administer Wazuh HIDS/SIEM and HashiCorp Vault (secrets and PKI), and run phishing simulations and security awareness training. * Cloud & Network Security: Own GCP IAM and Security Command Center. Manage Cloudflare Access (Zero Trust) and WAF rules, and own Kubernetes security (including RBAC, pod security standards, and workload reviews). * Identity & Compliance: Administer Okta for SSO, MFA, and provisioning. Enforce least privilege across all systems and support ISO 27001 and NIST CSF 2.0 audit activities. * Asset Management: Own the IT asset inventory end to end. Tracking hardware, software, and licence assignments from procurement through deployment, reassignment, and secure decommissioning or disposal. Keep asset records accurate and reconciled against purchasing and licence data, and use them to drive refresh cycles, spend decisions, and audit evidence. * Onboarding & Offboarding: Own the IT side of employee onboarding and offboarding in partnership with Human Resources. Provision devices, accounts, and role-appropriate access for new hires, and on exit revoke access promptly across all systems, recover and wipe company hardware, and handle data retention and transfer correctly. Keeps the process documented, repeatable, and auditable. * Platforms & Vendors: Own SaaS procurement, licence audits, and renewals. Administer Google Workspace, Atlassian, and other core tools, ensuring configurations meet security standards. * Projects & Support: Run IT and security projects from scoping through delivery. Resolve issues via ticketing and in-person support, maintain SLAs, and keep documentation and runbooks current. * Additional duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)