
Staff Security Engineer
Posted 9 hours ago

Posted 9 hours ago
This is a fully remote position, open to applicants in United States.
• Take charge of developing security controls for OpenLoop’s macOS and Windows devices, which includes MDM, disk encryption, patch compliance, and local admin controls.
• Design MDM and MAM policies to safeguard company and PHI data on managed devices as well as BYOD.
• Implement and oversee an enterprise browser that secures SaaS and web access through data controls, session policies, and extension management.
• Create, apply, and consistently assess CIS Benchmark baselines throughout the fleet.
• Monitor configuration drift, manage documented exceptions, and generate fleet-level evidence for HITRUST and SOC 2 audits.
• Promote application control and enforce least privilege principles on endpoints.
• Manage Google Workspace email security, encompassing SPF, DKIM, DMARC, phishing and BEC defenses, attachment and link protection, as well as PHI data loss prevention.
• Adjust security controls to mitigate risks and reduce false positives, collaborating with SecOps on phishing triage workflows.
• Develop security standards, configuration baselines, and runbooks.
• Execute and validate controls identified through threat modeling and security assessments.
• Align controls with HITRUST and SOC 2 requirements and manage audit evidence.
• Automate repetitive tasks through scripting.
• Mentor SAE and engineers from adjacent teams, serving as an incident escalation point.
• Collaborate with IT, Engineering, Compliance, and SecOps to translate security risks into business and operational language.
• Perform additional duties as assigned.
• Over 8 years of experience in security engineering, demonstrating a history of owning outcomes from start to finish.
• In-depth, hands-on knowledge of endpoint security and email security.
• Experience in deploying and managing MDM/MAM platforms (such as Kandji, Jamf, Intune, or similar) and email security platforms.
• Experience in deploying and managing an enterprise browser platform.
• Practical experience in implementing CIS Benchmarks and assessing compliance against them at a fleet scale.
• Familiarity with network security, including secure remote access (ZTNA/VPN), DNS filtering, segmentation, or firewall policy.
• Understanding of cloud security fundamentals, such as IAM, network controls, logging, and workforce access to cloud environments.
• Familiarity with DevSecOps practices, including infrastructure as code, CI/CD security, secrets management, or security tools in pipelines.
• Proficiency in scripting languages like Python, Bash, PowerShell, or similar.
• Experience in a regulated environment (such as HIPAA, HITRUST, SOC 2, PCI, or similar) and producing audit evidence.
• Excellent written communication skills; ability to articulate standards, defend decisions, and communicate risks to non-security executives.
• Relevant certifications such as GIAC, CISSP, OSCP, or cloud security certifications are preferred, but not mandatory.
• Must indicate whether visa sponsorship is required now or in the future.
• Medical, Dental & Vision coverage.
• Flexible Spending / Health Savings Accounts.
• Generous Paid Time Off (PTO).
• Flexible hybrid work arrangements.
• 401(k) plan with Company Match.
• Life Insurance benefits.
• Pet Insurance options.
• Competitive salary and compensation package.
Funcional Health Tech
Salesforce
CNO Financial Group
GuidePoint Security
Get handpicked remote jobs straight to your inbox weekly.