RAMP Holdings

Systems Engineer, Corporate Security

RAMP Holdings$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years in Client Platform or Endpoint Engineering, Identity Access & Management, or Corporate Security
  • Hands-on management experience with macOS using MDM tools
  • Familiarity with identity providers like Okta, including SSO and conditional access
  • Proficient in scripting languages like Python, Go, or Bash for automation
  • Experience with endpoint vulnerability management tools like CrowdStrike

Responsibilities

  • Maintain update policies and monitor software fleet for new applications
  • Build automation for endpoint security agent remediation
  • Maintain device configuration baselines and detect configuration drift
  • Configure authentication policies in Okta, including multifactor authentication
  • Remediate identity posture gaps identified by ISPM tools
  • Implement controls for enterprise AI usage and logging
  • Use APIs to automate processes and document control operations

Benefits

  • Flexible PTO
  • Centralized home-office equipment ordering
  • Health and wellness stipend
  • Budget for intra-office travel
  • Weekly coffee stipend
  • 100% medical, dental & vision insurance in the US
  • 401(k) with employer match in the US
  • Up to 16 weeks parental leave at full pay
Full Job Description
About the role

Corporate Security at Ramp owns the security of our internal environment: the device fleet, the identity and access layer, and the AI tools employees use for their work. We are hiring a Systems Engineer to build and operate the controls across these systems.

The role is hands-on, writing code and building agentic loops wherever possible rather than solving problems manually. You will help manage device configuration and patching via configuration-as-code, authentication and authenticator policies in Okta, network and gateway enforcement in Cloudflare, and the controls around our enterprise Claude and OpenAI deployments. These systems overlap heavily in practice, and the work is largely about integrating them and automating what would otherwise be manual administration.

You will report to the Corporate Security lead and work closely with IT, Security Engineering, and AI DevX.

What you'll do
  • Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence
  • Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling - detecting missing, stale, or unhealthy agents and bringing devices back into compliance
  • Maintain device configuration baselines as code, including drift detection and hardening standards
  • Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access
  • Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges
  • Implement and operate controls for enterprise AI usage, including identity-aware access, logging and retention, DLP where appropriate, and enforcement
  • Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated
What you need
  • 3-5 years of experience in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security
  • Hands-on macOS management at scale: MDM (Jamf, Fleet, Kandji, or equivalent) and macOS update mechanisms
  • Working knowledge of an identity provider (Okta or similar): SSO, authentication and authenticator policies, SCIM provisioning, and conditional access
  • Scripting ability in Python, Go, or Bash, and experience automating against platform APIs
  • Experience with EDR and endpoint vulnerability management (CrowdStrike or similar)
  • Ability to evaluate tradeoffs between technical enforcement, policy, and user friction, and to explain those tradeoffs clearly
Nice to have
  • osquery and Fleet, or other query-based fleet visibility tooling
  • Identity posture management (ISPM) tooling, or access review and governance platforms
  • Cloudflare Zero Trust, or other proxy, DNS, or network-layer enforcement, including TLS inspection
  • Exposure to AI and LLM security concerns: agent authorization, tool calls, model gateways, data leakage through AI tooling
  • Infrastructure-as-code and CI/CD experience (Terraform, GitHub Actions)
  • Windows fleet management alongside macOS
  • Compliance frameworks (SOC 2, PCI) as they apply to endpoints and access


Benefits available to all full-time Ramp employees (Global)
  • Flexible PTO
  • Centralized home-office equipment ordering
  • Health and wellness stipend
  • Budget for intra-office travel
  • Weekly coffee stipend


United States
  • 100% medical, dental & vision insurance coverage for you, with partial coverage for dependents
  • One Medical annual membership
  • 401(k), including employer match on contributions made while employed by Ramp
  • Fertility HRA (up to $10,000 per year)
  • Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay
  • Pet insurance
  • In-office perks: lunch, snacks, drinks, and more
  • Relocation expense coverage to NYC or SF (if needed)
Canada
  • Group medical, dental, and vision coverage through Sun Life
  • Life, AD&D, and disability coverage
  • Fertility drug coverage (up to $4,000 lifetime)
  • Group Retirement Plan with employer match (RRSP + DPSP)
  • Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay, with additional time available at reduced pay
  • Employee Assistance Program and virtual care through Lumino Health


United Kingdom
  • Private medical insurance through Freedom Elite
  • Virtual GP and at-home care via eMed x Livi
  • Workplace pension through Penfold, with salary sacrifice option
  • Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay with additional time available at reduced pay


Referral Instructions

If you are being referred for the role, please contact that person to apply on your behalf.

About RAMP Holdings

RAMP Holdings is a software company that provides video and audio search solutions to clients in various industries. The company was founded in 2008 and is headquartered in New York City. RAMP's products include a video platform, a media management system, and a transcription service. The company has worked with clients such as NBCUniversal, Fox News, and the PGA Tour.
Learn more about RAMP Holdings
Size
100 employees
Industry
Founded
2018

Similar Jobs

More Jobs at RAMP Holdings

More Information Technology Jobs

Find similar Systems Engineer, Corporate Security jobs: