IT Systems Engineer
Tempo · Remote
MeritLog read this listing from Tempo's Ashby job board and last checked it on September 11, 2026.
Source: the employer's Ashby job board. Open the original listing for current details.
Job details
- Work model
- Remote
- Salary
- Not listed by source
- Location
- USA (Remote)
Hiring context
How this role compares at Tempo
Tempo has 16 live roles in MeritLog’s catalog across 3 job families, and 13 of them are in engineering. 0 of those listings publish a pay range, a disclosure rate of 0%.
Tempo concentrates this hiring in:
Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.
What the role asks for
What you'd do
- Architect and automate the full identity lifecycle - HRIS → Okta → SaaS apps - eliminating manual provisioning and off boarding gaps
- Complete and maintain SSO/SCIM integrations across the entire SaaS stack
- Own Jamf Pro end to end: PreStage enrollment, configuration profiles, software updates, certificate distribution
- Deploy and tune endpoint security (SentinelOne) - policy management, MDM-driven deployment, alert triage
- Expand SIEM coverage and write detection/alerting rules with a detection-as-code approach
- Build toward infrastructure-as-code management of all IT tooling (Terraform, GitHub Actions)
- Resolve hard identity, device, and access escalations that get past first-line support
- Drive SOC 2 readiness - unified audit trails across identity, device, and security systems
What they're asking for
- 4+ years in IT engineering rolesExperience
- Hands-on Okta administration: SSO, SCIM, SAML/OIDC integrations, lifecycle policies, Okta Workflows. Understands HRIS-as-source-of-truth (Rippling or similar)Skill
- Production Jamf Pro experience: PreStage enrollment, configuration profiles, software update management, certificate distribution. macOS-firstSkill
- Deployed and operated an EDR platform (SentinelOne or comparable) - policy tuning, MDM deployment, alert triageSkill
- Strong scripting (Python/Bash/Go preferred), comfortable with REST APIs, webhooks, JSON, auth flows, and event-driven workflowsSkillPreferred
- Git-based config management, CI/CD pipelines (GitHub Actions), Terraform or equivalentSkill
- Solid grasp of DNS, certificates/PKI, ZTNA (Tailscale or similar), and modern access control modelsSkill
- Crypto/blockchain security exposure - multisig/hardware-wallet workflows (Fireblocks or similar), phishing/lookalike-domain campaigns, high-value signer threat modelsSkillPreferred
- Detection-as-code: SIEM detections as version-controlled rules (Panther Python models, Sigma, or equivalent)SkillPreferred
- Apple platform depth beyond basic Jamf - DDM, MDM protocol internals, notarization/signing/packaging, macOS security frameworks (TCC, system extensions)SkillPreferred
- Mapped controls to SOC 2, ISO 27001, NIST CSF, or CIS - understands what audit-ready evidence looks likeSkillPreferred
- Built Slack-driven workflows, bots, or self-service internal toolingSkillPreferred
- Public open-source contributions to IT/security toolingSkillPreferred
Parsed by MeritLog from the employer’s own posting. The full description follows below.
Job description
Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe’s experience in global payments and Paradigm’s expertise in crypto tech. Tempo’s payment-first design provides a scalable, low-cost predictable backbone that meets the needs of high-volume payment use cases. Our goal is to move money reliably, cheaply, and at scale. Our north star is simplicity for users: fintechs, traditional banks, merchants, platforms, and anyone else looking to move their payments into the 21st century. We're building Tempo with design partners who are global leaders in AI, e-commerce, and financial services: Anthropic, Coupang, Deutsche Bank, DoorDash, Mercury, Nubank, OpenAI, Revolut, Shopify, Standard Chartered, Visa, and more. We’re a team of crypto-optimists, building the infrastructure needed to bring real, substantial economic flows onchain. We like to move fast and swing for the fences - join us! THE ROLE You'll own and build Tempo's corporate IT infrastructure - identity, device management, endpoint security, and the automation that ties it all together. This is a hands-on engineering role, not a help desk seat. You'll bring software-engineering rigor to IT systems and help secure a company operating at the frontier of crypto. RESPONSIBILITIES - Architect and automate the full identity lifecycle - HRIS → Okta → SaaS apps - eliminating manual provisioning and off boarding gaps - Complete and maintain SSO/SCIM integrations across the entire SaaS stack - Own Jamf Pro end to end: PreStage enrollment, configuration profiles, software updates, certificate distribution - Deploy and tune endpoint security (SentinelOne) - policy management, MDM-driven deployment, alert triage - Expand SIEM coverage and write detection/alerting rules with a detection-as-code approach - Build toward infrastructure-as-code management of all IT tooling (Terraform, GitHub Actions) - Resolve hard identity, device, and access escalations that get past first-line support - Drive SOC 2 readiness - unified audit trails across identity, device, and security systems QUALIFICATIONS - 4+ years in IT engineering roles - Hands-on Okta administration: SSO, SCIM, SAML/OIDC integrations, lifecycle policies, Okta Workflows. Understands HRIS-as-source-of-truth (Rippling or similar) - Production Jamf Pro experience: PreStage enrollment, configuration profiles, software update management, certificate distribution. macOS-first - Deployed and operated an EDR platform (SentinelOne or comparable) - policy tuning, MDM deployment, alert triage - Strong scripting (Python/Bash/Go preferred), comfortable with REST APIs, webhooks, JSON, auth flows, and event-driven workflows - Git-based config management, CI/CD pipelines (GitHub Actions), Terraform or equivalent - Solid grasp of DNS, certificates/PKI, ZTNA (Tailscale or similar), and modern access control models NICE-TO-HAVES - Crypto/blockchain security exposure - multisig/hardware-wallet workflows (Fireblocks or similar), phishing/lookalike-domain campaigns, high-value signer threat models - Detection-as-code: SIEM detections as version-controlled rules (Panther Python models, Sigma, or equivalent) - Apple platform depth beyond basic Jamf - DDM, MDM protocol internals, notarization/signing/packaging, macOS security frameworks (TCC, system extensions) - Mapped controls to SOC 2, ISO 27001, NIST CSF, or CIS - understands what audit-ready evidence looks like - Built Slack-driven workflows, bots, or self-service internal tooling - Public open-source contributions to IT/security tooling