Jobs · Information Technology

Enterprise Security Engineer

TRM Labs · NAMER · Yesterday
RemoteRemoteInformation Technology$220/hrFull-time

About the role

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. The Enterprise Security Team secures the identities, endpoints, and core SaaS infrastructure used by every employee and contractor, ensuring the company can move fast without taking unnecessary risk.

Responsibilities

  • Engine secure-by-default endpoint baselines for macOS and Windows, including encryption, firewall, application controls, device compliance, and configuration standards.
  • Automate and scale identity and access controls in Entra ID and Google Workspace (SSO, SCIM, conditional access, privileged access workflows, access reviews, joiner/mover/leaver).
  • Codify security controls as code (Terraform/configuration profiles/policy-as-code), with peer review, change history, testing/rollback, and measurable outcomes.
  • Build and maintain automations and integrations (e.g., n8n/SlackOps/APIs/scripts) that reduce manual access grants, speed up control changes, and eliminate repetitive workflows.
  • Apply AI tooling (Claude Code, agentic workflows, MCP integrations, LLM-backed automations) to accelerate your own engineering and triage work, and help secure how the rest of the company uses AI: sanctioned tooling, data handling guardrails, and visibility into shadow AI.
  • Harden SaaS and collaboration platforms by reducing unmanaged apps and enforcing strong authentication, least privilege, sharing controls, and data protection guardrails.
  • Ensure logging for endpoint, identity, and key SaaS applications (e.g., Defender/Sentinel and vendor logs where relevant).
  • Drive vulnerability and configuration drift reduction targets, remediation pipelines, and reporting that leadership can act on.
  • Partner with compliance and risk stakeholders to produce evidence, document controls, and operationalize requirements without creating brittle, manual processes.
  • Participate in an on-call rotation (every ~3 weeks) for identity, endpoint security, and critical enterprise systems.

Requirements

  • Demonstrated experience engineering and scaling endpoint security controls for macOS and Windows.
  • Strong IAM foundation: hands-on experience with Entra ID (conditional access, SSO, access governance) and Google Workspace and/or Microsoft 365 administration.
  • Proven ability to automate real operational workflow (Bash, PowerShell, Python, etc.).
  • Fluency with AI-assisted engineering: you already reach for coding agents and LLM tooling to build, review, and investigate faster, and you can judge where their output needs verification.
  • Strong troubleshooting and systems thinking: identity, endpoint, network controls, and SaaS integrations.
  • Comfort balancing security and usability using a risk-based approach, communicating tradeoffs clearly to technical and non-technical stakeholders.
  • Working knowledge of operating Infrastructure-as-Code / configuration-as-code (Terraform preferred; policy-as-code/config profiles acceptable).
  • Security Incident Response & Countermeasures experience.
  • Security Operation Center experience.
  • Experience securing or governing enterprise AI adoption (AI usage policy, DLP for AI tools, agent/MCP access scoping).

Qualifications

  • Strong plus: Working knowledge of operating Infrastructure-as-Code / configuration-as-code (Terraform preferred; policy-as-code/config profiles acceptable).
  • Security Incident Response & Countermeasures experience.
  • Security Operation Center experience.
  • Experience securing or governing enterprise AI adoption (AI usage policy, DLP for AI tools, agent/MCP access scoping).

Skills

  • AI Fluency: You are among the top 10% of operators in your function in how you apply AI to accelerate repeatable workflows, structure and solve problems, and improve output quality.

Benefits

  • No cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, or application instructions.

Pay

TBD

Schedule

TBD

Similar jobs