Back to jobs
New

Security Automation Engineer

Seattle, WA
Stackline is the first full-funnel connected commerce platform for the world's most innovative brands. Business leaders, product innovators, performance marketers, and analysts trust Stackline as the single source of commerce truth. Fueled by our proprietary neural network, our market insights, revenue metrics, behavior analyses, and autonomous functionality create the actions that determine success or failure.
 
Founded in 2014 in Seattle, we now have offices in Minneapolis, New York, Cleveland, and London. Since November 2020, Stackline has raised $180 million in strategic investments from Goldman Sachs Growth Equity and TA Associates.
 
Stackline is on a mission to fuel the future of commerce by bringing brands and customers closer together.

About The Role

The Security Automation Engineer is a hands-on role responsible for Stackline's security posture, compliance program, and identity and endpoint platform. This covers a single Entra ID tenant, around a dozen federated applications, roughly 265 managed endpoints across macOS and Windows, and a SOC 2 Type II program tracked in Vanta with an external auditor.

For years, one generalist administrator ran this role — workable, but it revealed a limit: most of the week went to procedural work, running checklists and reconciling systems that disagree. That work has to be right but not done by hand. It needs a human to design it, and then to watch it run.

This role replaces that model with an engineer who automates the procedural half — evidence collection, offboarding, monitoring, and reconciliation — using scripts, services, and LLM agents. It builds on an existing internal repository of PowerShell and Python tooling, freeing capacity for the work that requires judgment: closing security gaps, hardening endpoints, driving vulnerability remediation, and carrying the compliance program.

The role splits roughly 40% security and compliance, 35% building automation, and 25% hands-on platform and deskside support. To support this on-site component, this position is based at our Seattle office 4 days per week.

What You Will Do

Security Posture and Compliance

  • Own the majority of Stackline's ~50 SOC 2 Type II controls in Vanta; route the rest to owners in Engineering, HR, Finance, and Legal.
  • Drive vulnerability remediation to SLA — critical in 15 days, high in 30, medium in 90 — across endpoint findings.
  • Run quarterly access reviews, the annual risk assessment, policy and vendor reassessment, and the leadership security council.
  • Coordinate the annual penetration test and track findings to closure.
  • Own incident response for identity and endpoint compromise: investigate, contain, document.

Automation and Agents

This is the part of the job that makes the rest of it possible. You will identify the operational work that repeats and replace it with software that runs unattended and tells someone when it fails.

  • Extend the nightly evidence-collection pipeline into a maintainable, company-owned system.
  • Automate employee offboarding to match the orchestration already in place for onboarding.
  • Build certificate and secret expiry monitoring across federated applications and app registrations.
  • Reconcile assets between the endpoint management platform and the ITSM system of record.
  • Automate ticket triage, first-response drafting, and knowledge retrieval against IT documentation.
  • Build with production rigor: scoped service identities, idempotent runs, structured logs, real failure alerts.

Identity and Endpoint Platform

  • Administer Microsoft Entra ID: conditional access, authentication methods, groups and role assignment, SAML/SCIM integrations, app registrations.
  • Administer Microsoft Intune across macOS and Windows: compliance policies, configuration profiles, application packaging and deployment, enrollment, Apple Business Manager.
  • Close endpoint-hardening gaps: EDR on macOS, local administrator privilege management, centralized endpoint logging.
  • Federate standalone-authenticating applications so disabling one account revokes everything.

What We Are Looking For

  • You write real code. Production-quality Python or PowerShell, and the ability to read the other — not glue scripts you'd be embarrassed to hand over.
  • Deep, hands-on identity experience. Entra ID or Azure AD at depth: conditional access, authentication methods, SAML/SCIM integrations, Graph API. Okta or Google Workspace depth works if you're ready to go deep on Entra quickly.
  • Endpoint management at fleet scale. Intune or Jamf — configuration profiles, compliance policy, application packaging, enrollment, and what happens when a device falls out of compliance.
  • You've carried a compliance framework, not just survived one. SOC 2, ISO 27001, or similar, from the inside — you know the difference between a control that's documented and one that's operating.
  • You've built automation other people depended on. Scheduled jobs, API integrations, least-privilege service identities, and alerting for when it breaks at 3am.
  • You're comfortable being the whole function. No tier one beneath you, no second administrator beside you. You decide, document, and say plainly when something is above your line.
  • You'll be in the Seattle office 4 days per week. Parts of this job are physical and can't be done remotely.
  • Bachelor's degree in information technology, computer science, cybersecurity, or a related technical field, or an equivalent combination of education, certifications, and relevant professional experience.

Bonus Points If You Have

  • Shipped something real with LLM agents and tool use — Claude Code, MCP servers, or an agent framework — and can talk about what broke in production, not just what demoed well.
  • macOS security depth: endpoint detection, privilege management, unified logging.
  • Networking you've configured yourself: VLANs, dual-WAN failover, Meraki or UniFi.
  • Automated against an ITSM platform's API and hit the credential-scope wall everyone hits.
  • Incident investigation: sign-in forensics, audit log analysis, mailbox rule and OAuth grant abuse.

Benefits and Perks

It's important that each and every employee feels they are supported and can complete their life's best work today and in the future. As part of that, we are committed to doing our part in addressing pay gaps and discrepancies by providing pay transparency for all of our roles. Actual salaries are just one component of the compensation package and may vary above or below the range based on job-related knowledge, skills, experience, geographical location, and performance. The pay range for this position is $140,000 - $160,000 per year. Other rewards may include annual bonuses, short- and long-term incentives, and other team-specific awards. In addition, we provide a robust benefits and perks package that includes:

  • Comprehensive medical, dental, and vision coverage that actually supports you — including HSA with company match and FSA options
  • Fertility benefits to support your path to parenthood
  • 401(k) with company match to help you plan ahead
  • Company-paid life insurance
  • 20 days of PTO + 9 company holidays to truly unplug
  • Paid parental leave for all parents — because family matters
  • Summer Fridays (log off at 3pm and enjoy it)
  • Regular in-office social events including happy hours and catered lunches
  • A thoughtfully stocked kitchen with healthy snacks and fresh fruit

 

Stackline is committed to creating a diverse environment and is proud to be an equal opportunity employer. We encourage applicants from all backgrounds to apply. All qualified applicants will receive consideration for employment without regard to race, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Create a Job Alert

Interested in building your career at Stackline? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Stackline’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.