Systems Engineer, Corporate Security
Ramp · New York, NY (HQ)
🔥8 people viewed this job
About the Role
About Ramp
Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books.
The problems are high-stakes, data-dense, and unforgiving.
We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you've built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome.
The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same.
If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it.
About the role
Corporate Security at Ramp owns the security of our internal environment: the device fleet, the identity and access layer, and the AI tools employees use for their work. We are hiring a Systems Engineer to build and operate the controls across these systems.
The role is hands-on, writing code and building agentic loops wherever possible rather than solving problems manually. You will help manage device configuration and patching via configuration-as-code, authentication and authenticator policies in Okta, network and gateway enforcement in Cloudflare, and the controls around our enterprise Claude and OpenAI deployments. These systems overlap heavily in practice, and the work is largely about integrating them and automating what would otherwise be manual administration.
You will report to the Corporate Security lead and work closely with IT, Security Engineering, and AI DevX.
What you'll do
Maintain update policies for both OS and software, and monitor the fleet so that newly introduced applications are brought into the patching cadence
Build automation for endpoint security agent remediation across EDR, DLP, VPN, and similar tooling — detecting missing, stale, or unhealthy agents and bringing devices back into compliance
Maintain device configuration baselines as code, including drift detection and hardening standards
Configure authentication and authenticator policies in Okta: SSO, MFA and authenticator enrollment, device trust, and conditional access
Remediate identity posture gaps surfaced by ISPM tooling: stale accounts, orphaned service principals, over-scoped OAuth grants, MFA gaps, and excess privileges
Implement and operate controls for enterprise AI usage, including identity-aware access, logging and retention, DLP where appropriate, and enforcement
Automate across these platforms using their APIs, build reporting on control coverage, and document how the controls you build are operated
What you need
3–5 years of experience in Client Platform Engineer/Endpoint Engineering, Identity Access & Management, or Corporate Security
Hands-on macOS management at scale: MDM (Jamf, Fleet, Kandji, or equivalent) and macOS update mechanisms
Working knowledge of an identity provider (Okta or similar): SSO, authentication and authenticator policies, SCIM provisioning, and conditional access
Scripting ability in Python, Go, or Bash, and experience automating against platform APIs
Experience with EDR and endpoint vulnerability management (CrowdStrike or similar)
Ability to evaluate tradeoffs between technical enforcement, policy, and user friction, and to explain those tradeoffs clearly
Nice to have
osquery and Fleet, or other query-based fleet visibility tooling
Identity posture management (ISPM) tooling, or access review and governance platforms
Cloudflare Zero Trust, or other proxy, DNS, or network-layer enforcement, including TLS inspection
Exposure to AI and LLM security concerns: agent authorization, tool calls, model gateways, data leakage through AI tooling
Infrastructure-as-code and CI/CD experience (Terraform, GitHub Actions)
Windows fleet management alongside macOS
Compliance frameworks (SOC 2, PCI) as they apply to endpoints and access
Benefits available to all full-time Ramp employees (Global)
Flexible PTO
Centralized home-office equipment ordering
Health and wellness stipend
Budget for intra-office travel
Weekly coffee stipend
United States
100% medical, dental & vision insurance coverage for you, with partial coverage for dependents
One Medical annual membership
401(k), including employer match on contributions made while employed by Ramp
Fertility HRA (up to $10,000 per year)
Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay
Pet insurance
In-office perks: lunch, snacks, drinks, and more
Relocation expense coverage to NYC or SF (if needed)
Canada
Group medical, dental, and vision coverage through Sun Life
Life, AD&D, and disability coverage
Fertility drug coverage (up to $4,000 lifetime)
Group Retirement Plan with employer match (RRSP + DPSP)
Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay, with additional time available at reduced pay
Employee Assistance Program and virtual care through Lumino Health
United Kingdom
Private medical insurance through Freedom Elite
Virtual GP and at-home care via eMed x Livi
Workplace pension through Penfold, with salary sacrifice option
Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay with additional time available at reduced pay
Referral Instructions
If you are being referred for the role, please contact that person to apply on your behalf.
Other notices
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Beware of recruiting scams: Ramp will only contact you through official @Ramp.com email addresses and will never ask for payment or sensitive personal information during the hiring process.
An inclined plane, also known as a ramp, is a flat supporting surface tilted at an angle from the vertical direction, with one end higher than the other, used as an aid for raising or lowering a load. The inclined plane is one of the six classical simple machines defined by Renaissance scientists. Inclined planes are used to move heavy loads over vertical obstacles. Examples vary from a ramp used to load goods into a truck, to a person walking up a pedestrian ramp, to an automobile or railroad train climbing a grade.
💬 Developer Questions
Ask the team a question — answers show up here
What does the interview process look like?
What AI/vibe coding tools does the team use daily?
How big is the engineering team?
Is the team fully async or are there required meetings?
What does onboarding look like for remote hires?
Can you share more about the tech stack and architecture?
What does career growth look like in this role?
What does a typical day look like?
Is there a salary range you can share?
Is equity or stock options part of the package?
Are there timezone requirements or preferences?
Do you sponsor work visas?
🏢 Is this your listing? Claim it to answer questions
Similar Jobs
Helpful resources
How to Land a Remote Vibe Coding Job
Step-by-step guide to getting hired at async-first companies.
The Complete Vibe Coding Workflow
Real tools and processes for building with AI in 2026.
Companies That Skip Leetcode Interviews
What practical interview formats look like instead.
Remote Developer Salary Guide 2026
Salary ranges by level, stack, and location.
Hiring for a similar role? Post your job here — it's free →
