Remote job
Staff CorpSec Engineer
Job details
About this role
Role overview
A senior, hands-on Staff Corporate Security Engineer role focused on protecting the internal attack surface across devices, identity, SaaS applications, and the corporate network. The position sets the technical direction for corporate security, builds automation that makes secure-by-default the norm, and balances strong protection with a smooth employee experience.
Responsibilities
- Own endpoint security across macOS, Windows, and Linux fleets, including hardening, EDR, patching, and device compliance via MDM. - Design and operate the identity and access architecture: SSO, MFA, conditional access, and least-privilege access to corporate systems and SaaS. - Drive the zero-trust strategy for corporate access, reducing reliance on the traditional network perimeter. - Secure the SaaS estate through configuration hardening, monitoring, and automated detection of risky changes and access. - Build automation and tooling for provisioning, deprovisioning, access reviews, and self-service guardrails. - Partner with IT and Detection & Response to instrument corporate telemetry and surface high-signal detections for phishing, account compromise, and endpoint threats. - Lead response to phishing, account takeover, and endpoint incidents, then build the systems that prevent recurrence.
Requirements
- Typically 8+ years of experience in security engineering with deep focus on corporate or enterprise security. - Strong hands-on experience with endpoint security and management (EDR, MDM) across macOS and Windows. - Deep expertise in identity and access management: SSO, MFA, SAML/OIDC, and modern IdPs such as Okta, Entra ID, or Google Workspace. - Experience securing SaaS environments and driving zero-trust access models. - Strong software or scripting skills (e.g., Python, Go) to automate security at scale. - Ability to balance strong security with a good employee experience and lead cross-team initiatives.
Nice to have
- Experience with detection engineering for corporate telemetry. - Familiarity with device management tooling and osquery-style fleet visibility. - Background responding to phishing and account compromise at scale. - Experience securing a fast-growing, remote-friendly workforce.
Benefits and work setup
- Posted base salary of $220,000.