Skip to content

Sr. Security Engineer, Corporate Information Security

165k – 185kNew York, NYHybrid6+ YOE
Summary

Senior security engineer leading workforce IAM, endpoint security, and AI tool governance for a fintech company. Hands-on IC role focused on Okta, SaaS security, and Zero Trust architecture in a hybrid NYC environment.

About the role

Responsibilities

Identity & Access Architecture

  • Define and evolve the workforce IAM roadmap
  • Architect identity patterns across Okta and SaaS estate SSO at scale, RBAC design, and lifecycle automation from HRIS through joiner/mover/leaver
  • Build sustainable Identity Governance & Administration (IGA) practice including User Access Review campaigns

Security Design

  • Lead initiatives across authentication, authorization, federation, and privileged access
  • Design time-bound, just-in-time, and break-glass patterns (PIM-equivalent) for high-risk roles
  • Govern non-human identities, service accounts, API tokens, OAuth integrations, and AI agents
  • Embed Zero Trust and least-privilege principles

Securing & Monitoring Corporate Communications

  • Manage security of corporate communication platforms (email, Slack) through Abnormal Security and Proofpoint
  • DLP enforcement to protect PII
  • Conduct email investigations for spam, phishing, and other threats

Endpoint, Mobile & Browser Security

  • Define and enforce hardening standards aligned with CIS benchmarks
  • Own configuration baselines for macOS, Windows, and Linux Desktops
  • Architect enterprise browser security, extension governance, session protection, and DLP at the browser layer

Vulnerability & Posture Management

  • Lead workforce vulnerability management program for endpoints and corporate SaaS
  • Design remediation SLAs by severity and asset class
  • Run remediation campaigns to closure
  • Operate SaaS posture tooling (Wiz, Vanta, Drata, or peers)

AI Tool Security

  • Establish and enforce secure architecture for AI tool usage
  • Define data handling boundaries, connector security, identity-aware access controls
  • Implement detection for misuse with bias toward enabling business safely

Governance & Operations

  • Run UAR campaigns end-to-end
  • Drive remediation of audit findings (SOC 2, ISO 27001)
  • Partner with MDR MSP and internal teams to mature identity-related detection and incident response

Requirements

  • 6+ years in security engineering with deep experience in IAM and corporate security, ideally in a regulated environment
  • Strong command of authentication and authorization protocols (SAML, OIDC, OAuth, SCIM, LDAP)
  • Experience with enterprise IAM platforms (Okta, Entra ID), RBAC design, and lifecycle automation
  • Familiarity with endpoint management and EDR; operationalizing CIS benchmarks across macOS and Windows
  • Experience designing remediation SLAs, running remediation campaigns, and operating SaaS posture tooling (Wiz, Vanta, Drata)
  • Comfortable building tools and pipelines with Python, Go, or similar
  • Strong writing skills for RFCs, one-pagers, audit narratives
  • Experience operating in SOC 2 and ISO 27001/NIST environments
  • Experience with network monitoring & alerting, perimeter blocking, ZTNA, ACLs, firewall rules, cryptography, VPNs

Preferred Qualifications

  • Hands-on experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea)
  • Identity Governance & Administration (Saviynt, SailPoint, ConductorOne, Lumos)
  • Modern secrets management (HashiCorp Vault, Doppler)
  • Zero Trust implementation experience
  • Policy-as-code (OPA / Rego)
  • Experience partnering with MDR / managed SOC
  • Security certifications (CISSP or vendor IAM certifications)
Skills
OktaEntra IDSAMLOIDCOAuthSCIMLDAPPythonGoZero TrustCIS benchmarksWizVantaDrataSOC 2
Similar roles at this salary range
All Security Engineering jobs →
Shield AI

Senior Staff Cybersecurity Engineer, Platform Security

Senior technical owner building secure-by-default infrastructure, IaC modules, policy-as-code guardrails, and CI/CD security tooling for cloud and platform engineering teams.

160k – 240kSan Diego, CASecurity EngineeringOn-site7+ YOEGoOPA
Coinbase

Insider Threat Analyst

Insider Threat Analyst responsible for triaging alerts, conducting investigations, and mitigating insider risks using SIEM, UBA, and DLP tools. Requires 3+ years in security operations or investigations with strong cross-functional collaboration skills.

135k – 159kUnited StatesSecurity EngineeringRemote3+ YOEUBADLP
Upstart

Principal Security Engineer, Data Security

Principal-level security engineer defining infrastructure security strategy and leading cross-functional efforts to secure cloud, Kubernetes, and developer platforms at scale.

191k – 264kUnited StatesSecurity EngineeringRemote8+ YOEGoAWS
Brex

Senior Application Security Engineer

Senior Application Security Engineer focused on finding vulnerabilities, performing penetration testing, and building security tooling across Brex's platform. Requires 5+ years in application security with strong Python and AI workflow knowledge.

192k – 240kUnited StatesSecurity EngineeringRemote5+ YOEAWSgRPC
Apollo

Senior Application Security Engineer

Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.

190k – 273kUnited StatesSecurity EngineeringRemote5+ YOEGCPRuby