Remote job
Security Engineer
Job details
About this role
Role overview A senior, high-ownership security engineering position on a small team that protects the perimeter of an internet intelligence platform serving major enterprises and government customers. The role blends program ownership (identity, cloud, vulnerability management) with hands-on incident response and the development of agentic automation that lets a small team operate at scale.
Responsibilities - Treat identity as a program: drive down standing access, automate joiner-mover-leaver lifecycle work, and govern non-human and agent identities. - Harden a GCP-first cloud estate through org policy, least-privilege IAM, workload identity hygiene, network segmentation, secrets management, and posture monitoring, partnering with infrastructure teams on IaC guardrails. - Own vulnerability management end to end: coverage, risk-based prioritization grounded in real exploitability, defensible SLAs, remediation partnership, and leadership-ready reporting. - Build detection coverage for identity, cloud, and SaaS environments; share an escalation rotation; lead or co-lead high-seeverity incidents; run blameless post-incident reviews and convert findings into durable fixes. - Secure the company's AI footprint (agent identity, MCP server and tool-permission scoping, secrets for autonomous workflows, prompt-injection boundaries) and design agentic security workflows that reduce manual toil. - Operate as a Slack-native, ChatOps-first team, replacing documentation with automation where possible.
Requirements - 5+ years in security engineering with real depth in at least two of: identity and access management, cloud security, vulnerability management, detection and response. - Hands-on identity operations experience with SSO/SAML/OIDC, MFA, conditional access, device trust, and lifecycle automation; experience with Duo and Google Workspace is a notable plus. - Background securing cloud-first environments; GCP preferred, strong AWS or Azure with willingness to go deep on GCP also fits. - Scripting ability in Python, Go, or similar, sufficient to build internal tooling. - Comfort making prioritization calls when multiple issues look urgent at once.
Nice to have - Excitement about building with AI and shipping agentic workflows. - Experience pairing with SRE or platform teams on shared cloud guardrails (application and product security are owned elsewhere).
Benefits and work setup - Reasonable accommodations available for candidates and employees with disabilities. Identity verification is part of the offer process, and US-based new hires are invited to an in-person onboarding week in Ann Arbor, Michigan.