Security Engineer, Corporate
Owns corporate security across identities, endpoints, SaaS, email, and workplace AI tools. The role requires 5+ years of corporate, enterprise, or endpoint security experience, strong IAM and MDM expertise, coding ability, and practical risk-based security judgment.
About the job
Responsibilities
- Own the security of the corporate environment, including identity, endpoints, SaaS, email, and workplace AI tools.
- Roll out and maintain scalable controls such as passkeys, device trust, conditional access, data loss prevention (DLP), and SaaS security posture management (SSPM).
- Run phishing simulations, security awareness, and tabletop programs that improve employee behavior.
- Partner with IT and Detection & Response to prioritize detection of insider risk and account takeover.
- Make secure workflows the default while minimizing unnecessary friction.
Requirements
- 5+ years of experience in corporate, enterprise, or endpoint security at a fast-growing technology company.
- Deep expertise in identity and access management, including Google Workspace, Okta, Entra, SSO, SCIM, and conditional access.
- Experience with mobile device management (MDM) platforms such as Jamf, Kandji, or Intune.
- Ability to write code in Python, Bash, or Go and manage policies as versioned, tested, and deployed software.
- Strong understanding of phishing, social engineering, insider risk, and AI-enabled variants.
- Pragmatic approach to security UX and control implementation.
Nice to have
- Experience securing workplace AI tools and agents, including Claude, ChatGPT, Cursor, or internal copilots.
Technology
- React and TypeScript
- Golang and Rust
- Cloudflare, Google Cloud, and AWS
- GitHub Actions, Grafana, OpenTelemetry, and Terraform
- ClickHouse, Firestore, Spanner, and BigQuery
Skills
Identity And Access Management, Google Workspace, Okta, Microsoft Entra, SSO, SCIM, Conditional Access, Mobile Device Management, Jamf, Kandji, Intune, Python, Bash, Go, Terraform
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads detection engineering and incident response across corporate, production, and AI-agent environments. The role requires 8+ years of relevant experience, strong detections-as-code expertise, cloud and telemetry knowledge, and proven leadership of high-severity security incidents.