Security IT Support Engineer
Role in brief
Crypto.com is hiring a Security IT Support Engineer to manage IT support, endpoint security, and vulnerability management. This role involves device lifecycle management, access control, and ensuring security controls are effective. Candidates with at least three years of IT support experience, familiarity with identity and access management, MDM, and endpoint security tools, and an understanding of AI tool security are encouraged to apply.
About the role
This role focuses on providing first-line IT support while maintaining a strong security posture. Key responsibilities include managing the full lifecycle of company devices, from deployment to troubleshooting, and ensuring all endpoints, workstations, and virtual environments are regularly patched and updated. The engineer will also conduct vulnerability scans, interpret results, and drive remediation efforts.
The position involves crucial identity and access management tasks, enforcing the principle of least privilege, and streamlining user provisioning and deprovisioning processes. Additionally, the engineer will help implement and monitor security controls such as endpoint protection, DLP, email security, and network controls. Accurate inventory management of IT assets is also a core duty.
A significant aspect of this role is supporting the secure adoption of AI tools within the organization. This includes identifying and mitigating risks like prompt injection, data leakage, and insecure integrations. The ideal candidate will be a self-directed professional capable of translating complex technical concepts for non-technical colleagues and maintaining project momentum independently.
The salary for this position ranges from $168,000 to $250,000 USD annually.
Skills that matter here
- identity and access management: This skill is used to manage user accounts, access rights, and enforce least privilege principles.
- MDM: This skill is applied to manage the full lifecycle of mobile devices and other endpoints.
- endpoint security: This skill is essential for implementing and monitoring security controls on devices and environments.
- patch management: This skill is used to keep endpoints, workstations, and cloud servers updated and secure.
- vulnerability scanning: This skill is applied to conduct regular scans, analyze results, and drive remediation of identified risks.
- AI tools: This skill involves helping teams adopt AI tools safely and identifying security risks associated with their use.
Who this role suits
- You have at least three years of experience in an IT support or operations role.
- You are proficient with identity and access management, MDM, and endpoint security tools.
- You are self-directed and can anticipate needs, ensuring project momentum without constant oversight.
- You can clearly explain complex technical concepts to non-technical individuals.
From the employer
- Be the first line of support for the organisation. Resolve issues, hit SLAs, and keep things moving.
- Own the full lifecycle of our devices — laptops, desktops, mobiles, and virtual desktops. Deployment, configuration, troubleshooting, all of it.
- Keep endpoints, workstations, cloud servers, and VDI environments up to date. Track what needs patching, get it done, and report on it.
- Run regular vulnerability scans across our environment. Understand what the results mean, prioritise by risk, and drive remediation to closure.
- Manage user accounts and access rights. Enforce least privilege. Make provisioning and deprovisioning slick and secure.
- Help implement and monitor our security controls — endpoint protection, DLP, email security, network controls. Keep an eye on what's happening.
- Know what we have, where it is, and who has it. Keep the inventory accurate.
- Set people up properly when they join and make sure access is cleanly revoked when they leave.
- Work with teams to help them adopt AI tools safely. Spot risks like prompt injection, data leakage, or insecure integrations.
- 3+ years in an IT support or IT operations role
- Solid experience with identity and access management, MDM, and endpoint security tools
- Some exposure to patch management — even if it's mostly been laptops, that's fine. We care that you understand the concept and are willing to grow into the broader scope.
- You've come across vulnerability scanning before and have a basic idea of what the results mean.
- You understand what AI tools are doing when people use them at work, and you can think about the security angle
- Skilled at translating complex technical concepts into clear, accessible language for non-technical stakeholders
- Highly self-directed professional who anticipates needs and ensures project momentum without requiring external follow-up.
Nice-to-Haves
- IT or security certifications (CISSP, CompTIA Security+, AWS, Microsoft Certified, etc.)
- Experience with physical office IT setup — networking gear, workstations, cabling
- Basic scripting ability (Python, Bash, PowerShell) to automate the repetitive stuff
- Exposure to LLM security concepts — prompt injection, data leakage, agentic risks — even from your own reading or research
- Worked in a fast-paced or high-security environment before
- Competitive salary
- Medical insurance package with extended coverage to dependents
- Attractive annual leave entitlement including: birthday, work anniversary
- Flexi-work hour and hybrid or remote set-up
- Aspire career alternatives through us. Our internal mobility program can offer employees a diverse scope.
- Work Perks: crypto.com visa card provided upon joining
- Our Crypto.com benefits packages vary depending on region requirements, you can learn more from our talent acquisition team.
Questions about this role
What is the remote work policy for this role?
This is a remote position with a flexi-work hour and remote setup.
What is the seniority level for this position?
This is a middle-seniority role.
What skills are required for this role?
Candidates need solid experience with identity and access management, MDM, endpoint security tools, some exposure to patch management, and basic understanding of vulnerability scanning and AI tool security.