Corporate IT and Security Engineer
Summary
The Corporate IT and Security Engineer will manage internal IT systems, employee device security, identity management, and corporate network security. They will also lead SOC 2 compliance efforts, automate IT workflows, and partner with engineering on application security and risk assessment.
The Role
We’re looking for our first dedicated Corporate IT and Security Engineer. You’ll own the systems and controls that keep Rowspace secure and productive, from employee devices, identity, SaaS applications, and corporate networks to SOC 2 operations and security incident response.
This is a hands-on role with broad ownership. In a typical week, you might deploy a new device-management policy, automate an onboarding workflow, improve our SSO configuration, harden an office network, resolve a security finding, collect SOC 2 evidence, respond to a customer security questionnaire, or help a team adopt a new AI tool safely.
You’ll build the foundation for how corporate IT and security operate as Rowspace grows. You’ll work across the company and partner closely with Engineering, People, Operations, and external security partners. Engineering will continue to own secure product development. You’ll help establish standards, coordinate testing, assess risks, and track application-security findings through remediation.
What You’ll Do
Own employee IT across laptops, mobile devices, identity, access, onboarding, and offboarding
Configure and manage MDM, SSO, endpoint security, email security, and company-wide SaaS applications
Own corporate network security, including office networks, Wi-Fi, firewalls, DNS, VPNs, segmentation, and zero-trust access
Maintain an accurate inventory of devices, applications, accounts, licenses, and access
Build reliable onboarding and offboarding workflows with appropriate access controls
Run day-to-day security operations, including monitoring, vulnerability management, incident response, and remediation
Manage vulnerability scanning and coordinate remediation across corporate systems, endpoints, networks, and applications
Own continuous control monitoring, evidence collection, audit preparation, and coordination with external auditors
Conduct regular access reviews and maintain clear security policies, procedures, and runbooks
Lead vendor security reviews and help evaluate new software, integrations, and AI tools
Respond to customer security questionnaires and maintain reusable security and compliance materials
Partner with Engineering on threat modeling, penetration tests, application-security standards, product security, cloud infrastructure, and customer deployment reviews
Track security findings through remediation and verify that critical issues are resolved
Build automations that make IT, security, and compliance processes faster and more reliable
Help employees adopt AI tools and workflows with appropriate access, privacy, and data controls
Serve as the first point of contact for employee IT and security questions
What You Have
5+ years of experience across corporate IT, systems administration, information security, security operations, or related roles
Hands-on experience managing identity providers, SSO, MFA, MDM, endpoints, and enterprise SaaS applications
Experience operating in a primarily macOS environment
Experience with employee provisioning, access reviews, asset management, and onboarding and offboarding
Experience supporting a SOC 2 program, including control operation, evidence collection, and audit coordination
Working knowledge of network security, including segmentation, firewalls, VPNs, DNS, and secure access
Familiarity with application-security practices such as threat modeling, secure development, dependency scanning, vulnerability management, and penetration testing
Ability to work with engineers on technical security risks without needing to own product development
Working knowledge of endpoint security, incident response, vulnerability management, and vendor risk
Ability to automate workflows with scripting, APIs, or modern automation tools
Good judgment when balancing security, usability, and speed
Clear written communication and reliable operational follow-through
Comfort owning a broad function and solving problems directly in a fast-moving company
Nice to Have
Experience as an early IT or security hire at a growing software company
Experience supporting a fintech company or another regulated industry
Experience with tools such as Okta, Google Workspace, Microsoft 365, Kandji, Rippling, CrowdStrike, Cloudflare, Drata, or similar platforms
Experience responding to customer security questionnaires and enterprise diligence requests
Familiarity with cloud identity and security in AWS, Azure, or GCP
Experience using AI and automation to improve internal operations
Experience working with managed IT, compliance, or security providers
Compensation
$150,000-$200,000 · Offers equity
Perks & Benefits
Health & Wellness: Comprehensive medical, dental, and vision insurance
Future Planning: 401(k) plan including employer match on contributions made while employed by Rowspace
Food & Fuel: Monthly commuter stipend, plus free daily lunch and a fully stocked snack bar in the office
Team Culture: Regular team offsites to bond and strategize away from the desk
As published by ashby
Name, Email, Resume
- Will you now or in the future require visa sponsorship to work for our company? yes / no
- Portfolio optional
- We’re growing our San Francisco and New York teams! Rowspace operates in-person, so we’re looking for people who can work on-site in these cities. Does this work for you? Feel free to share any additional details about your situation. written answer
- Do you have any connections at Rowspace? Even a second-degree referral would be helpful if you're comfortable sharing. written answer · optional