> Markdown version of [/jobs/ext/2583045-staff-it-systems-engineer](https://www.wearedevelopers.com/jobs/ext/2583045-staff-it-systems-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff IT Systems Engineer - **Company:** Obsidian Security, Inc. - **Location:** Palo Alto, CA, United States - **Experience:** Expert - **Salary:** $203,000.0 - $224,000.0 - **Contract:** Permanent contract - **Skills:** Access Network, Artificial Intelligence, Business Systems, Software as a Service, DevOps, Human Resources Information System (HRIS), Github, Identity and Access Management, Python (Programming Language), Windows PowerShell, Zero Trust Network Access, Scripting, Google Cloud, Okta, Zapier, Core Api, Git, Microsoft InTune, Infrastructure Automation Frameworks, Information Technology, Hashicorp, Casper Suite, Gsuite, Virtual Agents, Terraform, Workday - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3b150043b0c7879f ## About the Role * 8 or more years building and operating IT systems, identity, or platform infrastructure in production, with clear ownership of the systems you ran. * Deep, hands-on Okta ownership across SSO, MFA, Universal Directory, Lifecycle Management, and conditional access, ideally including Identity Governance. You have owned an Okta tenant end to end. * Hands-on Jamf Pro expertise managing a production Mac fleet, including configuration profiles, policies, smart groups, and patch workflows. * Proven infrastructure-as-code ownership with Terraform or OpenTofu managing real infrastructure or SaaS configuration in production, shipped through a pull-request-based GitOps workflow such as GitHub Actions. * Daily use of AI coding tools to ship production work. * Hands-on MDM depth with Jamf or Intune at fleet scale, including device compliance and trust. * Scripting fluency in Python, PowerShell, or a comparable language, and comfort automating against SaaS and platform APIs. * Clear written and verbal communication. You can explain an access policy or automation decision to an engineer and to a business stakeholder with equal clarity. Preferred * Experience with a lifecycle or identity-governance orchestration layer and with HRIS-driven provisioning (Rippling, Workday, or similar). * Google Workspace administration at scale, including GAM7. * Secrets and non-human credential management (HashiCorp Vault, Doppler, Secret Manager, or equivalent). * Workflow and integration automation on an iPaaS or agent platform such as Workato, including human-in-the-loop steps and MCP-style tooling. * Zero-trust network access (Jamf Connect, Zscaler, Tailscale, or similar) and enterprise browser deployments. * Exposure to compliance-driven controls and evidence automation for SOC 2 or ISO 27001 and 27701, and tooling such as Drata. * Google Cloud Platform and familiarity with agentic or MCP tooling for operations. * B2B SaaS or cybersecurity domain background. ## Description You will report directly to the VP of Business Systems, Data & IT. You will partner closely with Security, DevOps, HR, Finance, and the go-to-market teams, and you will collaborate with teammates across the Business Systems, Data & IT function., * Serve as the senior technical owner of Okta as our primary identity provider, covering Universal Directory, SSO, MFA (Okta Verify FastPass and FIDO2), conditional access, Device Access, and Okta Identity Governance for access certifications and reporting. * Own the lifecycle orchestration that turns HR events into access. This includes joiner, mover, and leaver flows from our HRIS through the orchestration layer into Okta, with same-hour offboarding. * Own the SSO application catalog across our estate of applications: sequence the integrations, enforce group-based access by role, and make the catalog the definition of what is sanctioned. Operate IT as code * Manage core platform configuration as version-controlled code in our corporate GitHub organization. This spans Okta policies, groups, group rules, app assignments, and governance campaigns; Jamf profiles, policies, and smart groups; the GitHub organization itself; and the underlying Google Cloud foundation, using OpenTofu and Terraform. * Bring imperative surfaces under the same discipline. Manage Google Workspace through scripts in git, run keyless through Workload Identity Federation, with verification and drift reporting where true state management is not possible. Set the standard for AI-augmented operations * Author configuration with AI assistance from the start. You will set the team standard for what good looks like here. * Use read-only tooling for live observability, drift triage, and log investigation, with humans gating every production change. * Build AI-assisted IT support and self-service workflows on our automation platform so routine requests for access, provisioning, and license changes resolve without a ticket queue and a manual handoff. Automate and harden the fleet * Own endpoint management across platforms with device trust and assurance wired into access policies, automated third-party patching, and application allowlisting. * Advance zero-trust network access and secrets-management patterns so identity and device health decide access. Raise the bar across IT * Set technical standards for the IT function, document them so they scale beyond your own hands, mentor teammates, and be the person others learn identity and automation from. * Partner with the VP to shape IT priorities and sequencing, and represent IT's requirements in cross-functional security, compliance, and platform decisions. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Let developers develop again](https://www.wearedevelopers.com/videos/463-let-developers-develop-again) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Stop Committing Your Secrets - GIt Hooks To The Rescue!](https://www.wearedevelopers.com/videos/573-stop-committing-your-secrets-git-hooks-to-the-rescue) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)