Security Automation Engineer

StacklineSeattle, WA
Hybrid

About The Position

The Security Automation Engineer is a hands-on role responsible for Stackline's security posture, compliance program, and identity and endpoint platform. This covers a single Entra ID tenant, around a dozen federated applications, roughly 265 managed endpoints across macOS and Windows, and a SOC 2 Type II program tracked in Vanta with an external auditor. This role replaces the previous model of a generalist administrator with an engineer who automates procedural tasks such as evidence collection, offboarding, monitoring, and reconciliation using scripts, services, and LLM agents. It builds on an existing internal repository of PowerShell and Python tooling, freeing capacity for tasks requiring judgment like closing security gaps, hardening endpoints, driving vulnerability remediation, and managing the compliance program. The role is split approximately 40% security and compliance, 35% building automation, and 25% hands-on platform and deskside support. To support the on-site component, this position is based at our Seattle office 4 days per week.

Requirements

  • Production-quality Python or PowerShell, and the ability to read the other.
  • Deep, hands-on identity experience. Entra ID or Azure AD at depth: conditional access, authentication methods, SAML/SCIM integrations, Graph API. Okta or Google Workspace depth works if you're ready to go deep on Entra quickly.
  • Endpoint management at fleet scale. Intune or Jamf — configuration profiles, compliance policy, application packaging, enrollment, and what happens when a device falls out of compliance.
  • Experience carrying a compliance framework, not just surviving one. SOC 2, ISO 27001, or similar, from the inside — you know the difference between a control that's documented and one that's operating.
  • Experience building automation other people depended on. Scheduled jobs, API integrations, least-privilege service identities, and alerting for when it breaks at 3am.
  • Comfortable being the whole function. No tier one beneath you, no second administrator beside you. You decide, document, and say plainly when something is above your line.
  • Bachelor's degree in information technology, computer science, cybersecurity, or a related technical field, or an equivalent combination of education, certifications, and relevant professional experience.

Nice To Haves

  • Shipped something real with LLM agents and tool use — Claude Code, MCP servers, or an agent framework — and can talk about what broke in production, not just what demoed well.
  • macOS security depth: endpoint detection, privilege management, unified logging.
  • Networking you've configured yourself: VLANs, dual-WAN failover, Meraki or UniFi.
  • Automated against an ITSM platform's API and hit the credential-scope wall everyone hits.
  • Incident investigation: sign-in forensics, audit log analysis, mailbox rule and OAuth grant abuse.

Responsibilities

  • Own the majority of Stackline's ~50 SOC 2 Type II controls in Vanta; route the rest to owners in Engineering, HR, Finance, and Legal.
  • Drive vulnerability remediation to SLA — critical in 15 days, high in 30, medium in 90 — across endpoint findings.
  • Run quarterly access reviews, the annual risk assessment, policy and vendor reassessment, and the leadership security council.
  • Coordinate the annual penetration test and track findings to closure.
  • Own incident response for identity and endpoint compromise: investigate, contain, document.
  • Identify operational work that repeats and replace it with software that runs unattended and alerts when it fails.
  • Extend the nightly evidence-collection pipeline into a maintainable, company-owned system.
  • Automate employee offboarding to match the orchestration already in place for onboarding.
  • Build certificate and secret expiry monitoring across federated applications and app registrations.
  • Reconcile assets between the endpoint management platform and the ITSM system of record.
  • Automate ticket triage, first-response drafting, and knowledge retrieval against IT documentation.
  • Build with production rigor: scoped service identities, idempotent runs, structured logs, real failure alerts.
  • Administer Microsoft Entra ID: conditional access, authentication methods, groups and role assignment, SAML/SCIM integrations, app registrations.
  • Administer Microsoft Intune across macOS and Windows: compliance policies, configuration profiles, application packaging and deployment, enrollment, Apple Business Manager.
  • Close endpoint-hardening gaps: EDR on macOS, local administrator privilege management, centralized endpoint logging.
  • Federate standalone-authenticating applications so disabling one account revokes everything.

Benefits

  • Comprehensive medical, dental, and vision coverage that actually supports you — including HSA with company match and FSA options
  • Fertility benefits to support your path to parenthood
  • 401(k) with company match to help you plan ahead
  • Company-paid life insurance
  • 20 days of PTO + 9 company holidays to truly unplug
  • Paid parental leave for all parents
  • Summer Fridays (log off at 3pm and enjoy it)
  • Regular in-office social events including happy hours and catered lunches
  • A thoughtfully stocked kitchen with healthy snacks and fresh fruit
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service