Senior Security Engineer, Endpoint

Ramp

New York City, UShybrid$172k-$236k/yrPosted Jul 8, 2026
Posting intelligenceActively listedReposted 2×, possible evergreen/ghost posting

Skills

terraformcss

About the role

Location

New York, NY (HQ)

Employment Type

Full time

Location Type

Hybrid

Department

Security

Compensation

NYCTarget Base Salary $172K – $236K • Offers Equity

The final compensation will depend on the location and level at which the candidate is hired.

About Ramp

Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $200B in annualized spend flows in and out of 70,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books.

The problems are high-stakes, data-dense, and unforgiving.

We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome.

The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same.

If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it.

About the Role

You'll be the architect of our endpoint security posture across the full fleet - macOS, Windows, and BYOD mobile devices. You'll build secure-by-default controls with Terraform and GitOps, harden endpoints at scale, and automate the full device lifecycle so nothing depends on a human remembering to click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other engineers, and raise the bar on what "low-friction security" actually means. Everything you ship will be auditable, measurable, and built for the long run.

We're also thinking seriously about how corporate security evolves in an agentic world - where AI agents act on behalf of employees and traditional identity and endpoint assumptions break down. You'll help us shape that answer.

What You’ll Do

Write and ship MDM policy as code - configuration profiles, remediation scripts, and enforcement rules across macOS, Windows, and mobile - with staged rollouts and rollback from day one

Build patch automation that closes exposure windows fast without making employees' lives worse

Manage software distribution across the fleet

Mine fleet telemetry for signal - build dashboards, drift alerts, and AI-assisted automation that cuts toil before it compounds

Own managed browser and extension policy: enforce what's allowed, block what isn't, and keep the control plane auditable as the surface grows

Be the last line of defense on endpoint escalations that IT Operations can't crack

What You Need

Deep macOS security experience - Jamf Pro, FleetDM, or equivalent MDM at scale

Strong IaC fundamentals and a GitOps delivery model - Terraform modules, remote state, and CI pipelines shipped through MRs and code review, not tickets and manual steps

Solid working knowledge of Google Workspace in a managed enterprise environment, including Chrome Browser Cloud Management and extension policy enforcement

A point of view on how agentic AI changes the corporate security surface

Nice-to-Haves

Have shipped real work with open source endpoint and device management tooling

Have built automated, progressive rollout systems based on fleet telemetry.

Have managed a mixed fleet - macOS, Windows, and mobile - with real depth on at least one platform

Have put AI to work on real operational problems, not just prototyped

Benefits available to all full-time Ramp employees (Global)

Flexible PTO

Unlimited AI token usage

Centralized home-office equipment ordering

Health and wellness stipend

Budget for intra-office travel

Weekly coffee stipend

United States

100% medical, dental & vision insurance coverage for you, with partial coverage for dependents

One Medical annual membership

401(k), including employer match on contributions made while employed by Ramp

Fertility HRA (up to $10,000 per year)

Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay

Pet insurance

In-office perks: lunch, snacks, drinks, and more

Relocation support to NYC or SF (as needed)

Canada

Group medical, dental, and vision coverage through Sun Life

Life, AD&D, and disability coverage

Fertility drug coverage (up to $4,000 lifetime)

Group Retirement Plan with employer match (RRSP + DPSP)

Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay, with additional time available at reduced pay

Employee Assistance Program and virtual care through Lumino Health

United Kingdom

Private medical insurance through Freedom Elite

Virtual GP and at-home care via eMed x Livi

Workplace pension through Penfold, with salary sacrifice option

Parental leave: up to 16 weeks (birthing + bonding) or 8 weeks (bonding only) at 100% pay with additional time available at reduced pay

Referral Instructions

If you are being referred for the role, please contact that person to apply on your behalf.

Other notices

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Beware of recruiting scams: Ramp will only contact you through official @Ramp.com email addresses and will never ask for payment or sensitive personal information during the hiring process.

Compensation

This Security Engineer role pays $172k-$236k/yr. Within typical range for security engineer roles in United States.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.