Staff IT Systems Engineer

Obsidian SecurityPalo Alto, CA

About The Position

Obsidian Security is seeking an experienced Staff IT Systems Engineer to be the senior technical owner of the company's identity, endpoint, and IT platform foundation. This role involves operating this foundation as code, managing identity flows from HR systems to applications, overseeing device fleet management and hardening, and maintaining configuration as version-controlled code. The engineer will set the standard for a modern, security-first IT organization in an AI-forward company, focusing on identity architecture, configuration-as-code, AI-augmented operations, and leveraging AI and automation for IT function growth. The position reports directly to the VP of Business Systems, Data & IT and collaborates with Security, DevOps, HR, Finance, go-to-market teams, and other members of the Business Systems, Data & IT function.

Requirements

  • 8 or more years building and operating IT systems, identity, or platform infrastructure in production, with clear ownership.
  • Deep, hands-on Okta ownership across SSO, MFA, Universal Directory, Lifecycle Management, and conditional access, ideally including Identity Governance.
  • Hands-on Jamf Pro expertise managing a production Mac fleet, including configuration profiles, policies, smart groups, and patch workflows.
  • Proven infrastructure-as-code ownership with Terraform or OpenTofu managing real infrastructure or SaaS configuration in production, shipped through a pull-request-based GitOps workflow.
  • Daily use of AI coding tools to ship production work.
  • Hands-on MDM depth with Jamf or Intune at fleet scale, including device compliance and trust.
  • Scripting fluency in Python, PowerShell, or a comparable language, and comfort automating against SaaS and platform APIs.
  • Clear written and verbal communication skills.

Nice To Haves

  • Experience with a lifecycle or identity-governance orchestration layer and with HRIS-driven provisioning (Rippling, Workday, or similar).
  • Google Workspace administration at scale, including GAM7.
  • Secrets and non-human credential management (HashiCorp Vault, Doppler, Secret Manager, or equivalent).
  • Workflow and integration automation on an iPaaS or agent platform such as Workato, including human-in-the-loop steps and MCP-style tooling.
  • Zero-trust network access (Jamf Connect, Zscaler, Tailscale, or similar) and enterprise browser deployments.
  • Exposure to compliance-driven controls and evidence automation for SOC 2 or ISO 27001 and 27701, and tooling such as Drata.
  • Google Cloud Platform and familiarity with agentic or MCP tooling for operations.
  • B2B SaaS or cybersecurity domain background.

Responsibilities

  • Own the identity foundation, serving as the senior technical owner of Okta, including Universal Directory, SSO, MFA, conditional access, Device Access, and Okta Identity Governance.
  • Manage the lifecycle orchestration for joiner, mover, and leaver flows from HRIS through the orchestration layer into Okta, ensuring same-hour offboarding.
  • Own the SSO application catalog, sequencing integrations, enforcing group-based access by role, and defining sanctioned applications.
  • Operate IT as code by managing core platform configuration (Okta policies, Jamf profiles, GitHub organization, Google Cloud foundation) as version-controlled code in GitHub, using OpenTofu and Terraform.
  • Manage Google Workspace through scripts in git, run keyless through Workload Identity Federation, with verification and drift reporting.
  • Set the standard for AI-augmented operations, using AI assistance for configuration authoring and setting team standards.
  • Utilize read-only tooling for live observability, drift triage, and log investigation, with humans gating all production changes.
  • Build AI-assisted IT support and self-service workflows on the automation platform to resolve routine requests without manual intervention.
  • Automate and harden the fleet, managing endpoint management across platforms with device trust and assurance, automated third-party patching, and application allowlisting.
  • Advance zero-trust network access and secrets-management patterns.
  • Set technical standards for the IT function, document them, mentor teammates, and be a source of knowledge for identity and automation.
  • Partner with the VP to shape IT priorities and sequencing, and represent IT's requirements in cross-functional decisions.

Benefits

  • Competitive compensation with equity
  • 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off
  • Paid holiday time off
  • 12 weeks of new parent or family leave
  • Personal and professional development resources
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service