Sr. Security Engineer, Corporate Information Security
About the Role
Betterment is hiring a Sr. Security Engineer, Corporate Information Security to be a principal member of the Workforce Security team. We're responsible for managing identity and logical access across the company, owning change management for the systems employees and contractors rely on every day, and operating the technologies that secure them: Okta, Google Workspace, Slack, Atlassian, Glean, Jamf, and the SaaS portfolio that surrounds them.
This is a hands-on senior IC role focused on designing, implementing, and continuously improving identity architecture, privileged access controls, endpoint hardening standards, and our overall workforce security posture. You'll embed secure access patterns across SaaS, managed browser, mobile, and workstation environments partnering closely with other Security teams, IT, Legal, Compliance, and the business units we serve.
Responsibilities
- Define and evolve the workforce IAM roadmap
- Architect identity patterns across Okta and our SaaS estate SSO at scale, RBAC that holds up under growth, and lifecycle automation that reaches every downstream system from HRIS through joiner/mover/leaver
- Build a sustainable Identity Governance & Administration (IGA) practice, including User Access Review campaigns that produce real evidence rather than rubber stamps
- Lead initiatives across authentication, authorization, federation, and privileged access
- Design time-bound, just-in-time, and break-glass patterns (PIM-equivalent) for high-risk roles so standing privilege trends toward zero
- Govern non-human identities, service accounts, API tokens, OAuth integrations, and the AI agents that increasingly act on users' behalf
- Embed Zero Trust and least-privilege principles into every workforce system you touch
- Manage the security of corporate communication platforms, including email and Slack, through tools such as Abnormal Security and Proofpoint
- Define and enforce hardening standards aligned with CIS benchmarks
- Own configuration baselines for macOS, Windows, and Linux Desktops, with mobile and managed browser controls layered on top
- Architect enterprise browser security, extension governance, session protection, and DLP at the browser layer
- Lead the workforce vulnerability management program for endpoints and corporate SaaS
- Design remediation SLAs by severity and asset class, run remediation campaigns that actually close findings, and partner with IT Systems to surface and fix identity and configuration misconfigurations
- Operate SaaS posture tooling (e.g., Wiz, Vanta, Drata, or peers) as the connective tissue across our SaaS estate
- Establish and enforce a secure architecture for AI tool usage, data handling boundaries, connector security, identity-aware access controls, and detection for misuse with a bias toward enabling the business safely rather than gating it
- Run UAR campaigns end-to-end, drive remediation of audit findings (SOC 2, ISO 27001), and partner with our MDR MSP and internal teams to mature identity-related detection and incident response
Requirements
- 6+ years in security engineering with deep experience in IAM and corporate security, ideally with time in a regulated environment
- Strong command of authentication and authorization protocols (SAML, OIDC, OAuth, SCIM, LDAP), enterprise IAM platforms (Okta and Entra ID), RBAC design, and lifecycle automation
- Comfortable with Identity Center / SSO patterns at scale and PIM-equivalent / break-glass models for privileged access
- Familiarity with endpoint management and EDR; an opinion on operationalizing CIS benchmarks across macOS and Windows without crushing the user experience; comfort extending security to mobile and managed browser surfaces
- Experience designing remediation SLAs, running remediation campaigns to actual closure, and operating SaaS posture tooling (Wiz, Vanta, Drata, or peers)
- Comfortable building tools and pipelines, not just configuring them; Python, Go, or similar with a track record of automation that survives the person who built it
- Curiosity for AI tools and workflows; an instinct for enabling responsibly rather than reflexively blocking
- Strong writing — RFCs, one-pagers, audit narratives — and the cross-functional patience to bring stakeholders along
- Comfort operating in SOC 2 and ISO 27001/NIST environments, balancing risk reduction with business enablement
Preferred Qualifications
- Hands-on experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea), Identity Governance & Administration (Saviynt, SailPoint, ConductorOne, Lumos), or modern secrets management (HashiCorp Vault, Doppler)
- Real-world Zero Trust implementation experience, not as a slide
- Working knowledge of policy-as-code (OPA / Rego) or similar
- Experience partnering with an MDR / managed SOC and shaping their detection content
- Security certifications such as CISSP or vendor IAM certifications
Benefits
We offer a competitive suite of benefits, including medical, dental, and vision coverage; life and AD&D insurance; short- and long-term disability; infertility support and WPATH-aligned transgender health benefits; an Employee Assistance Program (EAP); transit benefits and FSA and HSA options
- Equity for all employees, including new hire and refresher grants
- Flexible paid time off, paid parental leave, and a fully paid four-week sabbatical in your sixth year
- Company-paid professional coaching for all employees
- Day-one 401(k) match plus matching on qualified student loan payments
Pay
The base salary range for this position is $165,000-185,000, and this job may also be eligible for variable compensation in the form of a company incentive bonus