{"schemaVersion":"jobsearcher.job.v1","id":"79a4adfb21932ce2d6ec415a","url":"https://jobsearcher.com/jobs/79a4adfb21932ce2d6ec415a","canonicalUrl":"https://jobsearcher.com/jobs/79a4adfb21932ce2d6ec415a","title":"IT Systems Engineer","description":"Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe’s experience in global payments and Paradigm’s expertise in crypto tech.\n\nTempo’s payment-first design provides a scalable, low-cost predictable backbone that meets the needs of high-volume payment use cases. Our goal is to move money reliably, cheaply, and at scale. Our north star is simplicity for users: fintechs, traditional banks, merchants, platforms, and anyone else looking to move their payments into the 21st century.\n\nWe're building Tempo with design partners who are global leaders in AI, e-commerce, and financial services: Anthropic, Coupang, Deutsche Bank, DoorDash, Mercury, Nubank, OpenAI, Revolut, Shopify, Standard Chartered, Visa, and more.\n\nWe’re a team of crypto-optimists, building the infrastructure needed to bring real, substantial economic flows onchain. We like to move fast and swing for the fences — join us!\n\nThe Role\n\nYou'll own and build Tempo's corporate IT infrastructure — identity, device management, endpoint security, and the automation that ties it all together. This is a hands-on engineering role, not a help desk seat. You'll bring software-engineering rigor to IT systems and help secure a company operating at the frontier of crypto.\n\nResponsibilities\n\nArchitect and automate the full identity lifecycle — HRIS Okta SaaS apps — eliminating manual provisioning and off boarding gaps\n\nComplete and maintain SSO/SCIM integrations across the entire SaaS stack\n\nOwn Jamf Pro end to end: PreStage enrollment, configuration profiles, software updates, certificate distribution\n\nDeploy and tune endpoint security (SentinelOne) — policy management, MDM-driven deployment, alert triage\n\nExpand SIEM coverage and write detection/alerting rules with a detection-as-code approach\n\nBuild toward infrastructure-as-code management of all IT tooling (Terraform, GitHub Actions)\n\nResolve hard identity, device, and access escalations that get past first-line support\n\nDrive SOC 2 readiness — unified audit trails across identity, device, and security systems\n\nQualifications\n\n4+ years in IT engineering roles\n\nHands-on Okta administration: SSO, SCIM, SAML/OIDC integrations, lifecycle policies, Okta Workflows. Understands HRIS-as-source-of-truth (Rippling or similar)\n\nProduction Jamf Pro experience: PreStage enrollment, configuration profiles, software update management, certificate distribution. macOS-first\n\nDeployed and operated an EDR platform (SentinelOne or comparable) — policy tuning, MDM deployment, alert triage\n\nStrong scripting (Python/Bash/Go preferred), comfortable with REST APIs, webhooks, JSON, auth flows, and event-driven workflows\n\nGit-based config management, CI/CD pipelines (GitHub Actions), Terraform or equivalent\n\nSolid grasp of DNS, certificates/PKI, ZTNA (Tailscale or similar), and modern access control models\n\nNice-to-Haves\n\nCrypto/blockchain security exposure — multisig/hardware-wallet workflows (Fireblocks or similar), phishing/lookalike-domain campaigns, high-value signer threat models\n\nDetection-as-code: SIEM detections as version-controlled rules (Panther Python models, Sigma, or equivalent)\n\nApple platform depth beyond basic Jamf — DDM, MDM protocol internals, notarization/signing/packaging, macOS security frameworks (TCC, system extensions)\n\nMapped controls to SOC 2, ISO 27001, NIST CSF, or CIS — understands what audit-ready evidence looks like\n\nBuilt Slack-driven workflows, bots, or self-service internal tooling\n\nPublic open-source contributions to IT/security tooling","company":"Tempo","rawCompany":"tempo","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-24T09:07:41.270Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1211.00","title":"Computer Systems Analysts","slug":"computer-systems-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"IT Systems Engineer","description":"Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe’s experience in global payments and Paradigm’s expertise in crypto tech.\n\nTempo’s payment-first design provides a scalable, low-cost predictable backbone that meets the needs of high-volume payment use cases. Our goal is to move money reliably, cheaply, and at scale. Our north star is simplicity for users: fintechs, traditional banks, merchants, platforms, and anyone else looking to move their payments into the 21st century.\n\nWe're building Tempo with design partners who are global leaders in AI, e-commerce, and financial services: Anthropic, Coupang, Deutsche Bank, DoorDash, Mercury, Nubank, OpenAI, Revolut, Shopify, Standard Chartered, Visa, and more.\n\nWe’re a team of crypto-optimists, building the infrastructure needed to bring real, substantial economic flows onchain. We like to move fast and swing for the fences — join us!\n\nThe Role\n\nYou'll own and build Tempo's corporate IT infrastructure — identity, device management, endpoint security, and the automation that ties it all together. This is a hands-on engineering role, not a help desk seat. You'll bring software-engineering rigor to IT systems and help secure a company operating at the frontier of crypto.\n\nResponsibilities\n\nArchitect and automate the full identity lifecycle — HRIS Okta SaaS apps — eliminating manual provisioning and off boarding gaps\n\nComplete and maintain SSO/SCIM integrations across the entire SaaS stack\n\nOwn Jamf Pro end to end: PreStage enrollment, configuration profiles, software updates, certificate distribution\n\nDeploy and tune endpoint security (SentinelOne) — policy management, MDM-driven deployment, alert triage\n\nExpand SIEM coverage and write detection/alerting rules with a detection-as-code approach\n\nBuild toward infrastructure-as-code management of all IT tooling (Terraform, GitHub Actions)\n\nResolve hard identity, device, and access escalations that get past first-line support\n\nDrive SOC 2 readiness — unified audit trails across identity, device, and security systems\n\nQualifications\n\n4+ years in IT engineering roles\n\nHands-on Okta administration: SSO, SCIM, SAML/OIDC integrations, lifecycle policies, Okta Workflows. Understands HRIS-as-source-of-truth (Rippling or similar)\n\nProduction Jamf Pro experience: PreStage enrollment, configuration profiles, software update management, certificate distribution. macOS-first\n\nDeployed and operated an EDR platform (SentinelOne or comparable) — policy tuning, MDM deployment, alert triage\n\nStrong scripting (Python/Bash/Go preferred), comfortable with REST APIs, webhooks, JSON, auth flows, and event-driven workflows\n\nGit-based config management, CI/CD pipelines (GitHub Actions), Terraform or equivalent\n\nSolid grasp of DNS, certificates/PKI, ZTNA (Tailscale or similar), and modern access control models\n\nNice-to-Haves\n\nCrypto/blockchain security exposure — multisig/hardware-wallet workflows (Fireblocks or similar), phishing/lookalike-domain campaigns, high-value signer threat models\n\nDetection-as-code: SIEM detections as version-controlled rules (Panther Python models, Sigma, or equivalent)\n\nApple platform depth beyond basic Jamf — DDM, MDM protocol internals, notarization/signing/packaging, macOS security frameworks (TCC, system extensions)\n\nMapped controls to SOC 2, ISO 27001, NIST CSF, or CIS — understands what audit-ready evidence looks like\n\nBuilt Slack-driven workflows, bots, or self-service internal tooling\n\nPublic open-source contributions to IT/security tooling","datePosted":"2026-08-24T09:07:41.270Z","dateModified":"2026-08-24T09:07:41.270Z","hiringOrganization":{"@type":"Organization","name":"Tempo","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"79a4adfb21932ce2d6ec415a"},"url":"https://jobsearcher.com/jobs/79a4adfb21932ce2d6ec415a"}}