Security Engineer, Corporate Security
SG Home Office · San Francisco, CA · Yesterday
On-siteInformation Technology$200k–$220k/yrFull-time
About the role
Multifaceted security engineer position focusing on building scalable controls and automation across identity, endpoints, SaaS, and workforce infrastructure.
Responsibilities
- Harden our identity and access management stack, including Okta and Google Workspace, with phishing-resistant MFA, strong SSO and SCIM lifecycles, and least-privilege access across SaaS.
- Operate endpoint security program across a macOS-first fleet, including MDM, EDR, and configuration baselines, with working coverage for Windows and ChromeOS.
- Secure AI tool usage at the endpoint, including governance of large language models, AI agents, and model context protocol (MCP) integrations; detect and prevent unauthorized or risky AI service access and data exfiltration through AI-enabled tools.
- Reduce SaaS risk at scale through SSPM tooling and custom automation, including detection of risky OAuth grants, excessive permissions, shadow IT, and configuration drift.
- Write code (Python, Terraform) to automate access reviews, onboarding and offboarding, configuration drift detection, and audit evidence collection.
- Partner with Detection & Response to ensure corporate systems produce the telemetry needed to detect identity, endpoint, and SaaS abuse.
- Support SOC 2, ISO 27001, and customer audits as a byproduct of good engineering, not a separate workstream.
- Partner with Detection & Response on investigation and response for corporate security incidents, including phishing, account compromise, lost devices, and BEC.
Requirements
- 5+ years of hands-on experience in corporate security, enterprise security, or IT security engineering at a cloud-native company.
- Working knowledge of a major identity provider (Okta, Entra, or Google Workspace) and the underlying protocols (SAML, OIDC, OAuth 2.0, SCIM).
- Hands-on experience operating endpoint management and detection tooling across macOS and enterprise environments.
- Write production-quality scripts and automation in Python or Bash, and have shipped Terraform or other infrastructure-as-code for security configuration.
- Familiarity with SaaS security risks (OAuth governance, audit logging, SSPM) and the realities of integrating a long tail of vendors.
- Experience at a fast-growing tech or AI company where the security program had to outpace headcount.
- A background in IT engineering, SRE, or production engineering that transitioned into security engineering.
- Experience building internal security tooling or workflows that improved employee or developer experience.
- Contributions to the security community through open-source tools, blog posts, or conference talks.
Skills
- Have 5+ years of hands-on experience in corporate security, enterprise security, or IT security engineering at a cloud-native company.
- Have working knowledge of a major identity provider (Okta, Entra, or Google Workspace) and the underlying protocols (SAML, OIDC, OAuth 2.0, SCIM).
- Have hands-on experience operating endpoint management and detection tooling across macOS and enterprise environments.
- Write production-quality scripts and automation in Python or Bash, and have shipped Terraform or other infrastructure-as-code for security configuration.
- Be familiar with SaaS security risks (OAuth governance, audit logging, SSPM) and the realities of integrating a long tail of vendors.
- Have experience at a fast-growing tech or AI company where the security program had to outpace headcount.
- Have a background in IT engineering, SRE, or production engineering that transitioned into security engineering.
- Have experience building internal security tooling or workflows that improved employee or developer experience.
- Have contributions to the security community through open-source tools, blog posts, or conference talks.