About the Role
Tempo is building its corporate IT infrastructure, focusing on identity, device management, endpoint security, and automation. This is a hands-on engineering role requiring software engineering rigor to manage IT systems and enhance security for a crypto-focused company.
Responsibilities
- Architect and automate the full identity lifecycle, from HRIS to Okta to SaaS applications, eliminating manual provisioning and offboarding gaps.
- Complete and maintain SSO/SCIM integrations across the entire SaaS stack.
- Own Jamf Pro end-to-end, including PreStage enrollment, configuration profiles, software updates, and certificate distribution.
- Deploy and tune endpoint security (SentinelOne), managing policies, MDM-driven deployment, and alert triage.
- Expand SIEM coverage and write detection/alerting rules using a detection-as-code approach.
- Build towards infrastructure-as-code management of all IT tooling using Terraform and GitHub Actions.
- Resolve complex identity, device, and access escalations.
- Drive SOC 2 readiness by establishing unified audit trails across identity, device, and security systems.
Requirements
- 4+ years in IT engineering roles.
- Hands-on Okta administration experience, including SSO, SCIM, SAML/OIDC integrations, lifecycle policies, and Okta Workflows.
- Understanding of HRIS-as-source-of-truth (Rippling or similar).
- Production Jamf Pro experience, including PreStage enrollment, configuration profiles, software update management, and certificate distribution.
- Experience deploying and operating an EDR platform (SentinelOne or comparable), including policy tuning, MDM deployment, and alert triage.
- Strong scripting skills (Python/Bash/Go preferred) and comfort with REST APIs, webhooks, JSON, auth flows, and event-driven workflows.
- Experience with Git-based config management, CI/CD pipelines (GitHub Actions), and Terraform or equivalent.
- Solid understanding of DNS, certificates/PKI, ZTNA (Tailscale or similar), and modern access control models.
Skills
- Okta administration
- SSO
- SCIM
- SAML/OIDC integrations
- Lifecycle policies
- Okta Workflows
- HRIS integration
- Jamf Pro
- PreStage enrollment
- Configuration profiles
- Software update management
- Certificate distribution
- Endpoint security
- SentinelOne
- EDR platforms
- Policy management
- MDM deployment
- Alert triage
- SIEM
- Detection-as-code
- Infrastructure-as-code
- Terraform
- GitHub Actions
- Python scripting
- Bash scripting
- Go scripting
- REST APIs
- Webhooks
- JSON
- Auth flows
- Event-driven workflows
- Git
- CI/CD
- DNS
- Certificates/PKI
- ZTNA
- Tailscale
- Access control models
- Crypto/blockchain security
- Multisig/hardware-wallet workflows
- Fireblocks
- Phishing/lookalike-domain campaigns
- High-value signer threat models
- Panther Python models
- Sigma
- DDM
- MDM protocol internals
- Notarization/signing/packaging
- macOS security frameworks
- TCC
- System extensions
- SOC 2
- ISO 27001
- NIST CSF
- CIS
- Slack-driven workflows
- Bots
- Internal tooling
- Open-source contributions
Experience Level
- 4+ years in IT engineering roles
About the Company
- Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe’s experience in global payments and Paradigm’s expertise in crypto tech.
- Tempo’s payment-first design provides a scalable, low-cost predictable backbone that meets the needs of high-volume payment use cases.
- Our goal is to move money reliably, cheaply, and at scale.
- Our north star is simplicity for users: fintechs, traditional banks, merchants, platforms, and anyone else looking to move their payments into the 21st century.
- We're building Tempo with design partners who are global leaders in AI, e-commerce, and financial services: Anthropic, Coupang, Deutsche Bank, DoorDash, Mercury, Nubank, OpenAI, Revolut, Shopify, Standard Chartered, Visa, and more.
- We’re a team of crypto-optimists, building the infrastructure needed to bring real, substantial economic flows onchain.
- We like to move fast and swing for the fences — join us!
