
Enterprise Security Engineer
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in United States.
• Develop secure-by-default endpoint baselines for macOS and Windows, encompassing encryption, firewall, application controls, device compliance, and configuration standards.
• Automate and expand identity and access controls in Entra ID and Google Workspace (SSO, SCIM, conditional access, privileged access workflows, access reviews, joiner/mover/leaver).
• Codify security controls as code (Terraform/configuration profiles/policy-as-code), ensuring peer review, change history, testing/rollback, and measurable outcomes.
• Create and manage automations and integrations (e.g., n8n/SlackOps/APIs/scripts) that minimize manual access grants, expedite control changes, and eradicate repetitive workflows.
• Utilize AI tools to enhance your engineering and triage efforts, while also securing how the organization employs AI: sanctioned tools, data handling guidelines, and oversight of shadow AI.
• Strengthen SaaS and collaboration platforms by minimizing unmanaged applications and enforcing robust authentication, least privilege, sharing controls, and data protection guidelines.
• Enhance visibility and detection by ensuring logging of endpoints, identities, and key SaaS applications.
• Lead initiatives to reduce vulnerability and configuration drift targets, develop remediation pipelines, and generate actionable reports for leadership.
• Collaborate with compliance and risk stakeholders to produce evidence, document controls, and operationalize requirements while avoiding the creation of fragile, manual processes.
• Take part in an on-call rotation (approximately every 3 weeks) for identity, endpoint security, and critical enterprise systems.
• Proven experience in engineering and scaling endpoint security controls for macOS and Windows.
• Solid foundation in IAM: practical experience with Entra ID and Google Workspace and/or Microsoft 365 administration.
• Demonstrated ability to automate real operational workflows (Bash, PowerShell, Python, etc.).
• Proficiency with AI-assisted engineering: you regularly utilize coding agents and LLM tools to build, review, and investigate more efficiently, and you can assess where their outputs require verification.
• Strong troubleshooting skills and systems thinking: encompassing identity, endpoint, network controls, and SaaS integrations.
• Ability to balance security and usability using a risk-based approach, effectively communicating trade-offs to both technical and non-technical stakeholders.
• Health insurance
• 401(k) matching
• Flexible working hours
• Paid time off
• Remote work options
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.