Join Arena as a senior IT and security engineer to design and own the identity and access model in a hands-on role.
Posted by employer 1 day ago
First seen on Joblaze 12 hours ago
Last verified on the company career page 12 hours ago
Skills & Technologies
What you'll build
Must have
Nice to have
AI in the day-to-day
You use AI to build, script, and troubleshoot.
Not disclosed in this posting: compensation, years of experience, visa sponsorship.
Benefits
Joblaze summary
In this role, the senior IT and security engineer is responsible for shaping the technical direction of identity and access management, focusing on automation and operational readiness. Key skills include hands-on experience with Okta, endpoint management across Apple devices, and a strong understanding of security principles like least privilege and conditional access. This position is suited for someone with a proven track record in managing IT functions and making architectural decisions, particularly in environments undergoing rapid growth.
Joblaze insights
Quick facts
From the original posting
We are looking for a senior IT and security engineer to own that function's technical
direction. You will set how identity, endpoints, and access actually work here, decide what gets automated rather than done by hand, and be the person the team defers to on the hard calls.
This is a hands-on seat. You will do the work, not direct it from a distance.
You are not starting from zero. Identity is centralized with automated provisioning, the fleet is managed and enrolled with endpoint protection deployed, and remote access runs through a zero-trust layer. The foundations work. We need someone to deepen them, extend the model to areas it doesn't reach yet, and document what currently lives in people's heads.
The scope goes past enterprise systems. Our engineers build on source control, cloud data and analytics platforms, hosting, and managed infrastructure, and access to those carries
consequences that a wiki or a calendar does not. You will own how entitlement works there too.
This role is onsite in our San Francisco office.
Design the identity and access model, not just administer it. Okta is the center of gravity: SSO and SCIM, group and role design, lifecycle automation for joiners, movers, and leavers, and access reviews that produce evidence an auditor accepts. You decide what determines group membership and what the source of truth is.
Own endpoint strategy across a heavily Apple fleet. Intune, Apple Business Manager, and CrowdStrike Falcon: enrollment, compliance baselines, patching, and the full lifecycle from procurement to retirement.
Set the posture across enterprise and production systems. Enterprise platforms plus the developer and production systems our engineers depend on: source control, cloud data and analytics, hosting, and managed infrastructure. One standard applied across all of it, third-party application access, and a real answer for what an application can reach once authorized.
Extend the access model to production. Entitlement to developer and data platforms is a harder problem than enterprise SaaS: the blast radius is larger, the roles are less uniform, and the review evidence is what auditors scrutinize most. You own how that works.
Decide what stops being manual. Much of the current request queue is automatable, and nobody has had time. Okta Workflows, Google APIs, Python, PowerShell, or Bash- whatever fits.
Deepen operational readiness. An on-call rotation exists. Runbooks, escalation paths, and documentation are thinner than they should be, and much of the environment is still undocumented. You write it so a colleague can do the work without you.
Own onboarding and offboarding end to end, including the evidence trail compliance depends on.
Partner with the security function on device trust, conditional access, and privileged
access. This seat sits inside security rather than next to it.
Deep, current, hands-on experience. You can describe what you built or configured in the last three months at keyboard level.
You have owned a function, not just a queue. You have made architectural calls about how identity and endpoint management should work somewhere, defended them, and lived with what they cost. You can name one you got wrong and changed.
Real identity depth. Okta or comparable. You can explain what determines group membership, what happens to a mover rather than only a joiner and leaver, and how your model holds up as a company grows quickly.
Automation instinct. You can name a category of work that no longer exists because you eliminated it, and say what you deliberately left manual.
Endpoint management at scale across mixed platforms. Intune, Jamf, or equivalent, plus an endpoint security agent fleet.
Security depth for this domain. Least privilege, conditional access, device trust,
privileged access, and what an auditor will ask for.
Judgment about production and developer access, where over-granting is quietly expensive and under-granting stops engineers working. You have held that line somewhere.
Hands-on with AI tooling in your own work. You use AI to build, script, and troubleshoot, and you know where it belongs in an enterprise environment and where it doesn't.
Comfort inheriting something partly built and partly undocumented, and improving it rather than rebuilding it.
Calm under competing demands. You will support engineers, researchers, and executives, and need to tell a real emergency from a loud one.
Compliance evidence work: SOC 2 or ISO 27001 access reviews, asset inventory, offboarding records
Experience supporting a company through a period of rapid headcount growth
Zero-trust or conditional-access architecture
Governing AI tool adoption across a workforce: access, data handling, and sanctioned versus shadow usage
Cloudflare One administration and policy configuration
Hardware-key MFA rollouts (YubiKey, FIDO2)
AV, networking, or office buildout experience
Linux and cloud platforms (GCP, AWS, Azure)
We offer competitive compensation aligned to the markets where our team members are based. The compensation range for each role is listed on its posting and will depend on the candidate's experience and work location.
Standard company text repeated across Arena's postings is omitted here.