Skip to content
CapeCape

Security Engineer, Corporate Security

Security Engineer responsible for designing and managing corporate security controls across identity, endpoint, network, and vendor risk. Requires 5+ years in information security, deep IAM/EDR/MDM expertise, and experience with compliance frameworks to reduce risk and build security culture.

About the job

Responsibilities

  • Design, implement, and manage security controls and policies across corporate IT systems, focusing on the confidentiality, integrity, and availability of employee, customer, and business data.
  • Own and mature identity and access management (IAM/SSO/MFA), endpoint security (EDR, MDM), and email/network security (phishing defense, DLP, firewalls, VPN) across the organization.
  • Perform comprehensive security assessments of corporate systems and vendors to identify vulnerabilities, assess risk, and recommend actionable mitigation strategies.
  • Establish governance, guardrails, and monitoring for emerging employee tooling, including the associated data-handling, access, and third-party risks.
  • Own the vulnerability management lifecycle across the corporate fleet: scanning, risk-based prioritization, remediation and patch SLAs, and closure tracking across endpoints and internal systems.
  • Lead security awareness and phishing simulation programs to build an organization-wide culture of security.
  • Contribute to compliance and audit efforts as needed, lending security context where it helps the business move faster.
  • Assess and manage third-party/vendor security risk, including security questionnaires, contract reviews, and ongoing vendor monitoring.
  • Assist in running and addressing findings from penetration tests, red team exercises, and internal audits, ensuring prompt and effective remediation.
  • Stay informed about the latest security threats, vulnerabilities, and compliance mandates affecting corporate environments; provide strategic guidance on technologies and best practices.
  • Investigate security incidents and insider-threat concerns in partnership with HR, Legal, and IT as needed.
  • Raise the security bar across the company by mentoring engineers and partners on secure practices, fostering a culture of security awareness and continuous improvement.
  • Collaborate with stakeholders to integrate security requirements effectively into IT projects and broader business initiatives.

Preferred Experience

  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience). Advanced degrees or certifications (e.g., CISSP, GIAC, Security+, CISM) are advantageous.
  • A minimum of 5 years of experience in information security, with meaningful experience across corporate/IT security domains (identity, endpoint, network, GRC).
  • Deep understanding of enterprise identity providers and SSO/MFA platforms, endpoint/EDR tooling, MDM platforms, and email security tooling.
  • Working knowledge of common compliance frameworks (e.g., SOC 2, ISO 27001).
  • Familiarity with government/public-sector security frameworks (FedRAMP, FISMA, NIST SP 800 series, CJIS) is a plus, given Cape's government-facing customer base.
  • Working knowledge of consumer privacy regulations (GDPR, CCPA, and other regional privacy laws) as they apply to handling customer data.
  • Exposure to secure software development lifecycle (SSDLC) practices and partnering with engineering on secure design reviews.
  • Proficiency in scripting or automation (Python, shell scripting, or similar) to streamline security operations and reporting.
  • Familiarity with vendor/third-party risk management processes and tooling.
  • Solid knowledge of network security, encryption technologies, and secure business-system configuration.
  • Excellent analytical skills for identifying and mitigating complex security vulnerabilities and risks.
  • Strong communication and leadership abilities, capable of working collaboratively across teams and effectively conveying technical information to non-technical stakeholders.
  • Organized and able to manage multiple priorities in a dynamic, fast-paced environment.

Competencies

  • Security Expertise – Experience identifying and resolving security issues across corporate systems (identity, endpoint, network, and data). Secure-by-design principles, and partnering with IT/engineering during design time.
  • Analytical – Collects data and information; uses critical thinking to solve problems and make sound decisions.
  • Collaboration & Teamwork – Builds partnerships with others to reach common goals. Able to share credit with coworkers, display enthusiasm and promote a friendly group-working environment. Works closely with other departments as necessary, supports group decisions and solicits opinions from coworkers.
  • Communication – Presents information through verbal and written communication; reads and interprets complex information; listens well. Develops and delivers multi-mode communications that convey clear understanding of unique audiences.
  • Decision-Making – Acts quickly to solve problems and exercises good judgment by making sound and well-informed decisions. Perceives the impact and implications of decisions; makes effective and timely decisions, even when data is limited.
  • Dependability/Self-Management – Possesses the personal discipline and diligence necessary to keep commitments and to complete tasks. Is accountable for actions and outcomes. Makes effort to improve situations without explicit instructions; a self-starter who consciously manages his/her own time and resources.
  • Customer Centric – Values the importance of delivering high quality, innovative service to employees; understands the needs of the client; responds promptly and is accessible to them; follows through on commitments in a timely manner; maintains positive, long-term working relationships.

Skills

IAM, SSO, MFA, Edr, MDM, Dlp, Vpn, SOC 2, ISO 27001, FedRAMP, Nist, Python, Security Awareness, Vulnerability Management, Third Party Risk Management

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.