Security Automation Engineer

StacklineSeattle, WA
$140,000 - $160,000Hybrid

About The Position

Stackline is seeking a Security Automation Engineer to manage the company's security posture, compliance program, and identity and endpoint platform. This role involves overseeing a single Entra ID tenant, federated applications, approximately 265 managed endpoints (macOS and Windows), and a SOC 2 Type II program. The position is designed to automate procedural tasks such as evidence collection, offboarding, monitoring, and reconciliation, moving away from a manual, generalist administrator model. The engineer will leverage existing PowerShell and Python tooling, and potentially LLM agents, to free up capacity for critical security work like closing gaps, hardening endpoints, driving vulnerability remediation, and managing the compliance program. The role is a blend of security and compliance (40%), automation building (35%), and hands-on platform/support (25%), with a requirement to be in the Seattle office four days per week.

Requirements

  • Production-quality Python or PowerShell coding skills, and the ability to read the other language.
  • Deep, hands-on identity experience with Entra ID or Azure AD at depth: conditional access, authentication methods, SAML/SCIM integrations, Graph API. Okta or Google Workspace depth is acceptable if ready to quickly learn Entra.
  • Fleet-scale endpoint management experience with Intune or Jamf: configuration profiles, compliance policy, application packaging, enrollment, and handling devices out of compliance.
  • Experience managing a compliance framework (SOC 2, ISO 27001, or similar) from an internal perspective, understanding the difference between documented and operating controls.
  • Experience building automation relied upon by others, including scheduled jobs, API integrations, least-privilege service identities, and alerting for failures.
  • Comfort being the sole person responsible for a function, making decisions, documenting processes, and clearly stating limitations.
  • Bachelor's degree in information technology, computer science, cybersecurity, or a related technical field, or an equivalent combination of education, certifications, and relevant professional experience.

Nice To Haves

  • Shipped production systems using LLM agents and tool use (e.g., Claude Code, MCP servers, agent frameworks), with experience discussing real-world production issues.
  • Deep macOS security knowledge: endpoint detection, privilege management, unified logging.
  • Experience configuring networking components like VLANs, dual-WAN failover, using platforms such as Meraki or UniFi.
  • Experience automating against an ITSM platform's API and encountering credential-scope limitations.
  • Experience with incident investigation, including sign-in forensics, audit log analysis, and identifying mailbox rule and OAuth grant abuse.

Responsibilities

  • Own the majority of Stackline's ~50 SOC 2 Type II controls in Vanta; route the rest to owners in Engineering, HR, Finance, and Legal.
  • Drive vulnerability remediation to SLA — critical in 15 days, high in 30, medium in 90 — across endpoint findings.
  • Run quarterly access reviews, the annual risk assessment, policy and vendor reassessment, and the leadership security council.
  • Coordinate the annual penetration test and track findings to closure.
  • Own incident response for identity and endpoint compromise: investigate, contain, document.
  • Identify operational work that repeats and replace it with software that runs unattended and alerts on failure.
  • Extend the nightly evidence-collection pipeline into a maintainable, company-owned system.
  • Automate employee offboarding to match the orchestration already in place for onboarding.
  • Build certificate and secret expiry monitoring across federated applications and app registrations.
  • Reconcile assets between the endpoint management platform and the ITSM system of record.
  • Automate ticket triage, first-response drafting, and knowledge retrieval against IT documentation.
  • Build with production rigor: scoped service identities, idempotent runs, structured logs, real failure alerts.
  • Administer Microsoft Entra ID: conditional access, authentication methods, groups and role assignment, SAML/SCIM integrations, app registrations.
  • Administer Microsoft Intune across macOS and Windows: compliance policies, configuration profiles, application packaging and deployment, enrollment, Apple Business Manager.
  • Close endpoint-hardening gaps: EDR on macOS, local administrator privilege management, centralized endpoint logging.
  • Federate standalone-authenticating applications so disabling one account revokes everything.

Benefits

  • Comprehensive medical, dental, and vision coverage
  • HSA with company match
  • FSA options
  • Fertility benefits
  • 401(k) with company match
  • Company-paid life insurance
  • 20 days of PTO
  • 9 company holidays
  • Paid parental leave
  • Summer Fridays
  • Regular in-office social events (happy hours, catered lunches)
  • Stocked kitchen with healthy snacks and fresh fruit
  • Pay transparency
  • Annual bonuses
  • Short- and long-term incentives
  • Team-specific awards
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service