أبلاي إيدج ابدأ البحث عن عمل

IT & Security Engineer

Ultimate Staffing · San Francisco County, CA

قدّم وتابع مع أبلاي إيدج
My name is Archana. I am a Talent Acquisition Manager at Ultimate Staffing , a part of leading Talent Solutions company Roth Staffing. We have an excellent opportunity for you with an Electronics Manufacturing company. Please Let me know what you think about the below JD and I am looking forward to having a brief conversation with you. Please find the JD below and share a copy of you updated resume. I will call you to discuss further. We are currently seeking a IT and Security Engineer to join a client in Salt Lake City UT and SFO CA. This is a full-time, direct hire position. The role is Hybrid Scope & Leveling IndicatorsScope of Ownership: Owns the full lifecycle of IT hardware and software across Linux, Windows, and macOS (including the asset inventory and the employee onboarding and offboarding process) together with Company's security operations stack: vulnerability management, HIDS/SIEM, secrets and PKI, cloud and network security controls, and identity administration. Accountable for the reliability of these systems and for the state of the controls they enforce.Decision Authority: Final call on endpoint, network, and access configuration standards, on remediation priority and timelines for identified vulnerabilities, and on tooling choices within the IT and security estate. Recommends and escalates on risk acceptance, budget, and policy decisions.Autonomy: Operates independently as the hands-on owner of a broad, mixed workload. Sets priorities across incident response, project delivery, and support commitments, and reprioritizes without waiting for direction when a security event or business need demands it.Cross-Functional Influence: Works across Engineering, Platform, Legal & Compliance, People Operations, and Finance - partnering with engineering teams on Kubernetes and cloud security reviews, with People Operations on onboarding and offboarding, and with Finance on SaaS procurement and renewals. Drives security awareness across the whole company through training and phishing simulation.External Representation: Serves as the escalation point for complex IT and security issues across global teams, is the primary technical contact for the HackerOne VDP and its researchers, and represents Company's controls to auditors and to vendors.Typical Experience: 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.Key ResponsibilitiesInfrastructure & Endpoints: Manage the full lifecycle of IT hardware and software across Linux, Windows, and macOS. Own VPNs, backups, disaster recovery, MDM, and endpoint security, and serve as the escalation point for complex issues across global teams.Security Operations: Drive Company's security posture in alignment with ISO 27001 and NIST CSF 2.0. Own vulnerability management, the HackerOne vulnerability disclosure program, and security incident response. Administer Wazuh HIDS/SIEM and HashiCorp Vault (secrets and PKI), and run phishing simulations and security awareness training.Cloud & Network Security: Own GCP IAM and Security Command Center. Manage Cloudflare Access (Zero Trust) and WAF rules, and own Kubernetes security (including RBAC, pod security standards, and workload reviews).Identity & Compliance: Administer Okta for SSO, MFA, and provisioning. Enforce least privilege across all systems and support ISO 27001 and NIST CSF 2.0 audit activities.Asset Management: Own the IT asset inventory end to end. Tracking hardware, software, and licence assignments from procurement through deployment, reassignment, and secure decommissioning or disposal. Keep asset records accurate and reconciled against purchasing and licence data, and use them to drive refresh cycles, spend decisions, and audit evidence.Onboarding & Offboarding: Own the IT side of employee onboarding and offboarding in partnership with Human Resources. Provision devices, accounts, and role-appropriate access for new hires, and on exit revoke access promptly across all systems, recover and wipe company hardware, and handle data retention and transfer correctly. Keeps the process documented, repeatable, and auditable.Platforms & Vendors: Own SaaS procurement, licence audits, and renewals. Administer Google Workspace, Atlassian, and other core tools, ensuring configurations meet security standards.Projects & Support: Run IT and security projects from scoping through delivery. Resolve issues via ticketing and in-person support, maintain SLAs, and keep documentation and runbooks current.Additional duties as assigned.Required Qualifications5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.Working knowledge of the ISO 27001 and NIST CSF 2.0 frameworks and their practical application.Hands-on experience with Okta, Google Workspace, and Jira/Atlassian.Hands-on GCP experience, including IAM, Security Command Center, org-level security policies, and audit logging.Experience with Cloudflare - WAF/security rules, Access (Zero Trust), DNS, and API protection.Experience managing a vulnerability disclosure program or bug bounty programme (HackerOne or equivalent).Hands-on experience with the Wazuh Security Platform or a comparable HIDS/security monitoring platform.Experience with HashiCorp Vault for secrets management and PKI/certificate authority operations.Experience operating a SIEM (Splunk or equivalent), including rule authoring, alert triage, and incident reporting.Familiarity with Kubernetes security - RBAC, pod security, and workload hardening.Vulnerability management experience across scanning, triage, and remediation tracking.MDM platform experience with Jamf or equivalent.Experience owning IT asset management - maintaining an accurate hardware, software, and licence inventory from procurement through secure decommissioning.Experience running employee IT onboarding and offboarding, including device provisioning, account and access setup, and prompt access revocation and hardware recovery on exit.Demonstrable commitment to least privilege access and access lifecycle management.Proven ability to deliver IT and security projects independently.Excellent written and verbal English, and comfort working across global, cross-functional teams.Preferred QualificationsSecurity certification such as CISSP, CompTIA Security+, Google Professional Cloud Security Engineer, or equivalent.ISO 27001 Lead Implementer or Lead Auditor certification.Experience designing or implementing a full Zero Trust network architecture.Scripting ability in Python or Bash for security automation and tooling.Experience with asset management tools such as Snipe-IT or equivalent.Familiarity with container security tooling such as Trivy, Falco, or equivalent.Prior experience in a high-growth tech or scale-up environment.All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.