Jobs · Information Technology · California

Security Engineer, Corporate Security

SG Home Office · San Francisco, CA · Yesterday
On-siteInformation Technology$200k–$220k/yrFull-time

About the role

Multifaceted security engineer position focusing on building scalable controls and automation across identity, endpoints, SaaS, and workforce infrastructure.

Responsibilities

  • Harden our identity and access management stack, including Okta and Google Workspace, with phishing-resistant MFA, strong SSO and SCIM lifecycles, and least-privilege access across SaaS.
  • Operate endpoint security program across a macOS-first fleet, including MDM, EDR, and configuration baselines, with working coverage for Windows and ChromeOS.
  • Secure AI tool usage at the endpoint, including governance of large language models, AI agents, and model context protocol (MCP) integrations; detect and prevent unauthorized or risky AI service access and data exfiltration through AI-enabled tools.
  • Reduce SaaS risk at scale through SSPM tooling and custom automation, including detection of risky OAuth grants, excessive permissions, shadow IT, and configuration drift.
  • Write code (Python, Terraform) to automate access reviews, onboarding and offboarding, configuration drift detection, and audit evidence collection.
  • Partner with Detection & Response to ensure corporate systems produce the telemetry needed to detect identity, endpoint, and SaaS abuse.
  • Support SOC 2, ISO 27001, and customer audits as a byproduct of good engineering, not a separate workstream.
  • Partner with Detection & Response on investigation and response for corporate security incidents, including phishing, account compromise, lost devices, and BEC.

Requirements

  • 5+ years of hands-on experience in corporate security, enterprise security, or IT security engineering at a cloud-native company.
  • Working knowledge of a major identity provider (Okta, Entra, or Google Workspace) and the underlying protocols (SAML, OIDC, OAuth 2.0, SCIM).
  • Hands-on experience operating endpoint management and detection tooling across macOS and enterprise environments.
  • Write production-quality scripts and automation in Python or Bash, and have shipped Terraform or other infrastructure-as-code for security configuration.
  • Familiarity with SaaS security risks (OAuth governance, audit logging, SSPM) and the realities of integrating a long tail of vendors.
  • Experience at a fast-growing tech or AI company where the security program had to outpace headcount.
  • A background in IT engineering, SRE, or production engineering that transitioned into security engineering.
  • Experience building internal security tooling or workflows that improved employee or developer experience.
  • Contributions to the security community through open-source tools, blog posts, or conference talks.

Skills

  • Have 5+ years of hands-on experience in corporate security, enterprise security, or IT security engineering at a cloud-native company.
  • Have working knowledge of a major identity provider (Okta, Entra, or Google Workspace) and the underlying protocols (SAML, OIDC, OAuth 2.0, SCIM).
  • Have hands-on experience operating endpoint management and detection tooling across macOS and enterprise environments.
  • Write production-quality scripts and automation in Python or Bash, and have shipped Terraform or other infrastructure-as-code for security configuration.
  • Be familiar with SaaS security risks (OAuth governance, audit logging, SSPM) and the realities of integrating a long tail of vendors.
  • Have experience at a fast-growing tech or AI company where the security program had to outpace headcount.
  • Have a background in IT engineering, SRE, or production engineering that transitioned into security engineering.
  • Have experience building internal security tooling or workflows that improved employee or developer experience.
  • Have contributions to the security community through open-source tools, blog posts, or conference talks.

Similar jobs