IT & Security Engineer
Ultimate Staffing · Salt Lake City, UT · Yesterday
HybridFull-time
Key Responsibilities
- Manage the full lifecycle of IT hardware and software across Linux, Windows, and macOS.
- Own VPNs, backups, disaster recovery, MDM, and endpoint security.
- Serve as the escalation point for complex issues across global teams.
- Drive Company's security posture in alignment with ISO 27001 and NIST CSF 2.0.
- Own vulnerability management, the HackerOne vulnerability disclosure program, and security incident response.
- Administer Wazuh HIDS/SIEM and HashiCorp Vault (secrets and PKI).
- Run phishing simulations and security awareness training.
- Own GCP IAM and Security Command Center.
- Manage Cloudflare Access (Zero Trust) and WAF rules.
- Own Kubernetes security (including RBAC, pod security standards, and workload reviews).
- Administer Okta for SSO, MFA, and provisioning.
- Enforce least privilege across all systems and support ISO 27001 and NIST CSF 2.0 audit activities.
- Own the IT asset inventory end to end.
- Provision devices, accounts, and role-appropriate access for new hires.
- On exit revoke access promptly across all systems, recover and wipe company hardware, and handle data retention and transfer correctly.
- Keep the process documented, repeatable, and auditable.
- Own SaaS procurement, licence audits, and renewals.
- Administer Google Workspace, Atlassian, and other core tools, ensuring configurations meet security standards.
- Run IT and security projects from scoping through delivery.
- Resolve issues via ticketing and in-person support, maintain SLAs, and keep documentation and runbooks current.
Required Qualifications
- 5+ years in IT system administration and/or security engineering across Windows, Linux, and macOS.
- Working knowledge of the ISO 27001 and NIST CSF 2.0 frameworks and their practical application.
- Hands-on experience with Okta, Google Workspace, and Jira/Atlassian.
- Hands-on GCP experience, including IAM, Security Command Center, org-level security policies, and audit logging.
- Experience with Cloudflare - WAF/security rules, Access (Zero Trust), DNS, and API protection.
- Experience managing a vulnerability disclosure program or bug bounty programme (HackerOne or equivalent).
- Hands-on experience with the Wazuh Security Platform or a comparable HIDS/security monitoring platform.
- Experience with HashiCorp Vault for secrets management and PKI/certificate authority operations.
- Experience operating a SIEM (Splunk or equivalent), including rule authoring, alert triage, and incident reporting.
- Familiarity with Kubernetes security - RBAC, pod security, and workload hardening.
- Vulnerability management experience across scanning, triage, and remediation tracking.
- MDM platform experience with Jamf or equivalent.
- Experience owning IT asset management - maintaining an accurate hardware, software, and licence inventory from procurement through secure decommissioning.
- Experience running employee IT onboarding and offboarding, including device provisioning, account and access setup, and prompt access revocation and hardware recovery on exit.
- Demonstrable commitment to least privilege access and access lifecycle management.
- Proven ability to deliver IT and security projects independently.
- Excellent written and verbal English, and comfort working across global, cross-functional teams.