Enterprise Security Engineer
Pave · San Francisco Bay Area · 1 wk ago
On-siteInformation Technology$190/hrFull-time
About the role
Security at Pave protects the world's largest real-time compensation dataset and the company that runs on it. The team is small, senior, and AI pilled: everyone builds, everyone automates, and everyone flexes across domains. As Pave's Corporate Security Engineer, you'll own the corporate side of that mission: identity and access management, endpoint protection, SaaS security, and the corporate compliance operations behind our SOC 2 Type II and ISO 27001 programs, with an explicit charter to aggressively automate all the things.
Responsibilities
- Identity & Access Management
- Own Okta and Pave's access-management model: role/group architecture, lifecycle automation, SSO/SCIM, and the exception process
- Keep the RBAC model current and consistently enforced, with automation that prevents drift
- Compliance Operations
- Own the SOC 2 Type II and ISO 27001 controls that touch corporate IT, end to end
- Automate evidence collection and user access reviews
- Endpoint & SaaS Security
- Own endpoint protection (MDM/EDR) across a five-location, ~175-person company
- Run SaaS vendor security reviews and build shadow-IT visibility; feed IT-controlled data sources into our SIEM
- Automation & AI
- Engineer away manual IT toil — laptop setup, onboarding/offboarding provisioning, access requests — using APIs, workflow tooling, and AI agents
- Build governance for employee-built internal apps: publish detection, automated review checks, sane sharing models
- Partnership
- Design the systems that Pave's helpdesk (in G&A) operates day to day; be the design counterpart that makes that team stronger and more self-sufficient
Requirements
- 5+ years of hands-on corporate/enterprise security or IT security engineering experience at a multi-office company
- Okta (or equivalent IdP) administration at the design level — you've built an access model, not just operated one
- Experience operating within SOC 2 and/or ISO 27001: controls you owned passed audits
- Hands-on MDM/EDR and Google Workspace–class SaaS estate administration as a primary owner
- A track record of shipped automations with concrete before/after impact
- Demonstrated, specific use of AI tooling in your own workflows
- Networking fundamentals
Nice to have
- Previous management experience
- Came up through IT/helpdesk into security (or similar path), so you have empathy for the people you’re supporting and first hand experience with the toil you’re here to automate away
- Experience with Okta, GCP, Iru, Sentinel One, Claude code, and/or similar tools
- Vendor security review / third-party risk experience
- Background at a 150–500 person B2B SaaS company handling sensitive data
Pay
The targeted cash compensation for this position is $220,000+ (base) and equity included. Your level and compensation are determined by your experience and how you show up throughout the interview process.
Benefits
- Your Health, Fully Covered: Comprehensive medical, dental, and vision coverage for you and your family, with a range of options designed to meet you where you are.
- Time That's Actually Yours: Flexible PTO and the freedom to work from anywhere in the world for up to a month.
- Fuel for the Work: Lunch and dinner stipends plus fully stocked kitchens.
- Room to Keep Growing: A quarterly education stipend to invest in the skills and knowledge that matter most to you.
- Support When It Matters Most: Robust parental leave.
- Getting Here, Made Easier: A commuter stipend to support in-person collaboration.