Obsidian Security
Staff IT Systems Engineer
Palo Alto, CA · Staff+
Sponsorship not specified$203k-$224kDetected 23 hours ago
PythonPowerShellGitSnowflakeDatabricksGCPCloud PlatformsTerraformDevOpsRESTOAuthAgentic AICybersecurityComplianceSalesforceHRISSystems EngineeringZero Trust
> stay_score
odds of building a lasting career here
37Unrated
Cap-exempt (no lottery)0
Sponsors this role0
Entry-level history0
PERM / green-card track0
Lottery odds (Level IV)94
Fits your clock70
No strong sponsorship signal in the public record yet. In the full product we resolve the exact legal entity and show its filing history with a confidence score — treat as unverified until then.
Lottery odds assume a STEM candidate.
Personalize to your clock →> community_outcomes
No reports yet — be the first to help the next applicant.
About the role
- We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand, including many of the world's largest Fortune 1000 and Global 2000 companies.
Responsibilities
- Own the identity foundation
- Own the lifecycle orchestration that turns HR events into access. This includes joiner, mover, and leaver flows from our HRIS through the orchestration layer into Okta, with same-hour offboarding.
- Own the SSO application catalog across our estate of applications: sequence the integrations, enforce group-based access by role, and make the catalog the definition of what is sanctioned.
- Manage core platform configuration as version-controlled code in our corporate GitHub organization. This spans Okta policies, groups, group rules, app assignments, and governance campaigns
- Bring imperative surfaces under the same discipline. Manage Google Workspace through scripts in git, run keyless through Workload Identity Federation, with verification and drift reporting where true state management is not possible.
- Build AI-assisted IT support and self-service workflows on our automation platform so routine requests for access, provisioning, and license changes resolve without a ticket queue and a manual handoff.
- Manage core platform configuration as version-controlled code in our corporate GitHub organization.
- Own endpoint management across platforms with device trust and assurance wired into access policies, automated third-party patching, and application allowlisting.
- Set technical standards for the IT function, document them so they scale beyond your own hands, mentor teammates, and be the person others learn identity and automation from.
- Partner with the VP to shape IT priorities and sequencing, and represent IT's requirements in cross-functional security, compliance, and platform decisions.
Requirements
- You have owned an Okta tenant end to end.
- Hands-on Jamf Pro expertise managing a production Mac fleet, including configuration profiles, policies, smart groups, and patch workflows.
- Proven infrastructure-as-code ownership with Terraform or OpenTofu managing real infrastructure or SaaS configuration in production, shipped through a pull-request-based GitOps workflow such as GitHub Actions.
- You can explain an access policy or automation decision to an engineer and to a business stakeholder with equal clarity.
- Experience with a lifecycle or identity-governance orchestration layer and with HRIS-driven provisioning (Rippling, Workday, or similar).
- In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization.
Skills
- Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia.
- Greylock, Obsidian was built to close a critical gap:
- securing SaaS apps where business happens-Microsoft 365, Salesforce, and hundreds more.
- Obsidian was built by leaders who redefined endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black.
- Now, they're transforming how SaaS is secured.
- Major announcements are on the horizon.
- This is a high-leverage seat at a pivotal moment.
Compensation
- $203,000 - $224,000 USD
Benefits
- Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.
- Competitive compensation with equity and 401k
- Comprehensive healthcare with dental and vision coverage
- Flexible paid time off and paid holiday time off
- 12 weeks of new parent or family leave
- For more details on our US benefits, or for information on our international benefits, please see here.
- In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.
- Advance zero-trust network access and secrets-management patterns so identity and device health decide access.
Company info
- Founded in 2017 and backed by top investors like Greylock, Obsidian was built to close a critical gap: securing SaaS apps where business happens-Microsoft 365, Salesforce, and hundreds more.
- Our identity platform is being stood up with a lifecycle orchestration layer in front of it, and we are moving the whole stack onto an infrastructure-as-code operating model.
- We are looking for a senior technical owner to set the bar for identity architecture, configuration-as-code, AI-augmented operations, and how a lean IT function leverages AI and automation to grow the function.
- At Obsidian, we are proud to be an equal-opportunity employer.
Equal opportunity
- If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com
Apply directly at Obsidian Security →Create a free account for alerts like thisView Obsidian Security immigration profile
This listing is sourced directly from Obsidian Security's careers page and normalized into a canonical job model.