Tempo logo

IT Systems Engineer

Tempo

United StatesRemoteJobNo compensation foundPosted 2mo agoVerified open 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
United StatesRemote
Work Authorization
Not specified

Job overview

Tempo is building a layer‑1 blockchain payment infrastructure and seeks an IT Systems Engineer to own and build corporate IT infrastructure, including identity, device management, endpoint security, and automation, applying software‑engineering rigor to secure a fast‑moving crypto company.

Skills & qualifications

RequiredNice to have

Skills

Mac OSScriptingWebhooksJSONISO/IEC 27001Okta AdministrationSSOSCIMSAML OIDC IntegrationsLifecycle PoliciesOkta WorkflowsHRISJamf PromacOSSentinelOnePythonBashGoREST APIsAuth FlowsEvent‑Driven WorkflowsGit‑Based Config ManagementCI CD PipelinesGitHub ActionsTerraformDNSCertificates PKIZTNAModern Access Control ModelsCrypto Blockchain SecurityMultisig Hardware Wallet WorkflowsPhishing Lookalike Domain CampaignsHigh Value Signer Threat ModelsDetection as CodePanther Python ModelsSigmaApple Platform DepthDDMMDM Protocol InternalsNotarization Signing PackagingmacOS Security FrameworksSOC 2 Mapping ControlsISO 27001

Qualifications

4+ Years IT Engineering Experience

Full job description

Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe’s experience in global payments and Paradigm’s expertise in crypto tech.

Tempo’s payment-first design provides a scalable, low-cost predictable backbone that meets the needs of high-volume payment use cases. Our goal is to move money reliably, cheaply, and at scale. Our north star is simplicity for users: fintechs, traditional banks, merchants, platforms, and anyone else looking to move their payments into the 21st century.

We're building Tempo with design partners who are global leaders in AI, e-commerce, and financial services: Anthropic, Coupang, Deutsche Bank, DoorDash, Mercury, Nubank, OpenAI, Revolut, Shopify, Standard Chartered, Visa, and more.

We’re a team of crypto-optimists, building the infrastructure needed to bring real, substantial economic flows onchain. We like to move fast and swing for the fences — join us!

The Role You'll own and build Tempo's corporate IT infrastructure — identity, device management, endpoint security, and the automation that ties it all together. This is a hands-on engineering role, not a help desk seat. You'll bring software-engineering rigor to IT systems and help secure a company operating at the frontier of crypto.

Responsibilities

  • Architect and automate the full identity lifecycle — HRIS → Okta → SaaS apps — eliminating manual provisioning and off boarding gaps

  • Complete and maintain SSO/SCIM integrations across the entire SaaS stack

  • Own Jamf Pro end to end: PreStage enrollment, configuration profiles, software updates, certificate distribution

  • Deploy and tune endpoint security (SentinelOne) — policy management, MDM-driven deployment, alert triage

  • Expand SIEM coverage and write detection/alerting rules with a detection-as-code approach

  • Build toward infrastructure-as-code management of all IT tooling (Terraform, GitHub Actions)

  • Resolve hard identity, device, and access escalations that get past first-line support

  • Drive SOC 2 readiness — unified audit trails across identity, device, and security systems

Qualifications

  • 4+ years in IT engineering roles

  • Hands-on Okta administration: SSO, SCIM, SAML/OIDC integrations, lifecycle policies, Okta Workflows. Understands HRIS-as-source-of-truth (Rippling or similar)

  • Production Jamf Pro experience: PreStage enrollment, configuration profiles, software update management, certificate distribution. macOS-first

  • Deployed and operated an EDR platform (SentinelOne or comparable) — policy tuning, MDM deployment, alert triage

  • Strong scripting (Python/Bash/Go preferred), comfortable with REST APIs, webhooks, JSON, auth flows, and event-driven workflows

  • Git-based config management, CI/CD pipelines (GitHub Actions), Terraform or equivalent

  • Solid grasp of DNS, certificates/PKI, ZTNA (Tailscale or similar), and modern access control models

Nice-to-Haves

  • Crypto/blockchain security exposure — multisig/hardware-wallet workflows (Fireblocks or similar), phishing/lookalike-domain campaigns, high-value signer threat models

  • Detection-as-code: SIEM detections as version-controlled rules (Panther Python models, Sigma, or equivalent)

  • Apple platform depth beyond basic Jamf — DDM, MDM protocol internals, notarization/signing/packaging, macOS security frameworks (TCC, system extensions)

  • Mapped controls to SOC 2, ISO 27001, NIST CSF, or CIS — understands what audit-ready evidence looks like

  • Built Slack-driven workflows, bots, or self-service internal tooling

  • Public open-source contributions to IT/security tooling

You've read the whole posting — now see how you match it.