IT Security Engineer
About UsRelay is a cross-chain payments protocol that provides instant, low-cost cross-chain bridging, swaps, and transactions. We're the fastest and cheapest way to bridge and transact across chains, serving over 5 million users who have completed 59+ million transactions with $6+ billion in volume across 85+ chains.Our company mission is to make transacting across chains as fast, cheap, and reliable as online payments. We are building the core infrastructure to abstract chains from end user payments, enabling the next billion users to experience the benefits of blockchain without the UX burdens.About The RoleRelay is scaling and we’re looking for someone who’ll be someone dedicated to the operational layer: device management, identity and access management, and the compliance infrastructure that makes us trustworthy at scale.In this role, you'll help to design and deploy our MDM strategy, manage access across our tool stack, and lead identity management initiatives. You will champion internal systems and help build the policies that govern how the whole company works.Right now, we are targeting candidates who work in UTC through UTC+ 5 time zones. Occasional on-call hours will be required.What you'll doBuild and operate our device fleetDesign and deploy our MDM solution, including platform selection, policy configuration, device enrollment, and secure configurationsEnforce device security standards: full-disk encryption, approved software lists, network access controls, and automatic lock policiesOwn device lifecycle and equipment policy for company-provided laptopsSupport new hire IT setup and workstation provisioning end to endOwn identity and access managementManage access provisioning and deprovisioning across Google Workspace, Slack, AWS, GitHub, and other internal toolsEnforce SSO and MFA policies across the stack; identify and close gaps where access bypasses SSOWork cross-functionally with HR, Finance, and Engineering to integrate SSO across their respective tool stacks (HRIS, payroll/finance systems, engineering tooling)Own contractor access lifecycle: identity verification, provisioning, and revocationMaintain a current inventory of who has access to whatDrive Security OperationsLead incident response during your time zone: triage, pull in the right people, and drive clear communication through to resolutionAggregate logging into a central solution, and use AI-assisted tooling to review logs and proactive threat huntingPartner with engineering to prioritize and track vulnerability findings, whether from internal tooling, third-party audits, or dependency scans, against defined severity-based SLAsCoordinate on policy documentation and own the operational controls including access reviews, device compliance, and onboarding and offboarding checklistsEstablish IT operations infrastructureBe the first point of contact for internal IT issues and security questions across the teamImplement and manage an Identity ProviderBuild runbooks and playbooks for common IT and access management workflowsCoordinate on policy documentation and own operational controls, including access reviews, device compliance, and onboarding/offboarding checklistsStay abreast of industry best practices and emerging technologiesAbout YouYou've built Security Operations at a startup before, ideally, you’ve also operated in a regulated industryYou operate under a breach mentality and implement zero trust systematically.You communicate clearly with non-technical stakeholders and can explain security tradeoffs without making people feel judgedYou're organized and process-oriented, and you rigorously build documentation and workflowsYou're excited about crypto and the unique security environment it creates: high-value systems, smart adversaries, and a global distributed teamSkills And AbilitiesMust-have5+ years in IT/Security operations, or a closely adjacent roleHands-on experience deploying and managing MDM platforms (Jamf, Kandji, Workspace ONE, or similar)Experience managing identity and access at scale: SSO configuration, MFA enforcement, directory management (Google Workspace, Okta, or similar)Working knowledge of compliance frameworks and what it takes to implement adequate security controlsCloud access and security fundamentals (AWS, Google Cloud, or equivalent)Experience building and maintaining contractor access policies and device compliance programsNice to haveExperience deploying remote desktop environments.Background in crypto/Web3 or fintech with similar compliance pressuresExperience at a company scaling from 50 to 100+ employeesFamiliarity with MacOS and Apple ProductsWhat we offerCompetitive base salaryEquity packageComprehensive health benefitsUnlimited PTO policy with encouraged minimumRemote-first culture with emphasis on collaboration, communication, and flexibility