Skip to content
FlexportFlexport

Security Engineer, Corporate Security

Build and operate corporate security controls across identity, endpoints, SaaS applications, and automation. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.

About the job

Responsibilities

Identity and Access

  • Improve SSO coverage, phishing-resistant MFA, SCIM lifecycle automation, and least-privilege access across SaaS and cloud environments.
  • Build detections and guardrails for account takeover, MFA fatigue attacks, and session token theft.

Endpoint and Device Lifecycle

  • Write and deploy device policy as code, including configuration profiles, remediation scripts, and enforcement rules for macOS and Windows.
  • Implement staged rollouts and rollback capabilities.
  • Maintain and improve EDR detection and response coverage across the device fleet.

SaaS Security

  • Reduce SaaS risk using SSPM tooling and automation, including detection of risky OAuth grants, shadow IT, and configuration drift.
  • Manage security configuration for tools such as Google Workspace and Slack.
  • Assess security implications of AI agents and MCP integrations.

Automation and Enablement

  • Automate device provisioning, access reviews, and vendor security questionnaires.
  • Write runbooks and documentation.
  • Partner with IT and People teams to implement practical security controls.

Requirements

  • Typically 2–5 years of experience in corporate, enterprise, or IT security engineering.
  • Hands-on experience with endpoint management and EDR tools such as Jamf, Kandji, Intune, CrowdStrike, or SentinelOne.
  • Working knowledge of SAML, OIDC, and SCIM, plus experience with an identity provider such as Okta, Entra, or Google Workspace.
  • Ability to write production code or scripts in Python, Go, or a similar language.
  • Clear, practical communication skills and the ability to explain security control tradeoffs to technical and non-technical stakeholders.

Nice to Have

  • Experience with SSPM tooling and OAuth grant governance.
  • Exposure to DLP or insider-risk tooling.
  • Familiarity with Terraform for infrastructure-as-code security configuration.
  • Understanding of how agentic AI tools and MCP integrations affect corporate security monitoring.
  • Interest in expanding into corporate security or detection engineering.

Compensation

  • Base salary range: $165,375–$202,125 USD.

Skills

SSO, MFA, SCIM, SAML, OIDC, Jamf, Kandji, Microsoft Intune, Crowdstrike, Sentinelone, Python, Go, Terraform, Sspm, OAuth

Sentry

Sentry

San Francisco, CA
Security Engineer, Detection & Response
CA$162k+/yrHybrid2+ YOESecurity Engineering

Security engineer responsible for detection engineering, investigations, incident response, identity and access management, and preventative security controls across corporate and production environments. Requires 2+ years of security engineering experience, programming ability, and familiarity with cloud and defensive security tooling.

Sentry

Sentry

San Francisco, CA
Security Engineer, Application Security
CA$162k+/yrHybrid2+ YOESecurity Engineering

Security Engineer focused on application and platform security, security reviews, threat modeling, vulnerability management, and secure development practices. The role requires at least two years of relevant experience, programming ability, and familiarity with cloud security technologies.

Harvey

Harvey

San Francisco, CA

Software Engineer, Security
$161k+/yrOn-site2+ YOESecurity Engineering

Build and operate foundational security services spanning identity, access, secrets, privileged access, and secure AI-agent infrastructure. The role requires at least two years of production software engineering experience, cloud expertise, and experience translating security requirements into reliable automated systems.

Greptile

Greptile

San Francisco, CA

Product Engineer, Security
$170k+/yrOn-site1+ YOESecurity Engineering

Build Greptile’s security product, including code scanning, vulnerability detection and reproduction, security-focused pull-request workflows, and agent infrastructure. The role requires a computer science degree, software or DevOps experience, JavaScript/TypeScript expertise, and hands-on security experience.

Hover

Hover

San Francisco, CA
Security Software Engineer
$148k+/yrHybrid1+ YOESecurity Engineering

Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.