Staff Corporate Security Engineer
Designs and implements Zero Trust, SASE, and identity-based security architectures to protect corporate networks, SaaS platforms, and AI systems. Requires 8+ years experience in SaaS security, IAM, DLP, and device trust.
About the job
Responsibilities
- Lead design and implementation of Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) architectures, replacing legacy VPNs.
- Architect preventative SaaS security for Google Workspace, Slack, Okta, including CASB controls.
- Implement Binary Authorization and device trust with hardware-backed identity (TPM, Secure Enclave).
- Design and tune Data Loss Prevention (DLP) across endpoints and SaaS.
- Strengthen email security with MFA and session controls.
- Architect AI-native security frameworks for agent-based systems (e.g., MCP).
- Scale identity and access management (SSO, SAML, OAuth, SCIM, JIT access).
- Define and execute “Crown Jewels” security methodology for high-risk vulnerabilities.
Requirements
- 8+ years designing Zero Trust, SASE, identity-based security architectures.
- Strong expertise in SaaS security (CASB, DLP, Google Workspace, Okta, Slack).
- Experience with device trust, endpoint security, hardware-backed identity.
- Strong IAM knowledge (SSO, SAML 2.0, OAuth, SCIM).
- Email security, phishing mitigation, session controls.
- Application vulnerabilities (IDOR, privilege escalation).
- AI security challenges, agent-based governance.
Nice-to-Haves
- CASB and enterprise DLP at scale.
- Model Context Protocol (MCP) or AI orchestration.
- “Secure by Default” in high-growth orgs.
- Cloud-native or AI infrastructure background.
Compensation
- $210,000 - $255,000 base + bonus + RSUs
Skills
Zero Trust, Sase, Ztna, Casb, Dlp, Okta, Google Workspace, Slack, SSO, SAML, OAuth, SCIM, Tpm, Secure Enclave, MFA
Similar jobs
Security Engineering jobsStaff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.