Corporate Security Engineer

Harvey Harvey · AI Frontier · San Francisco, CA · Engineering

This role is part of the corporate security function, focusing on ensuring IT and business systems are secure, compliant, and user-friendly. The team is scaling rapidly and is driven by a commitment to securing customer data and corporate IP. The role involves implementing and evolving systems like Identity Governance and Administration (IGA) and device trust programs, supporting endpoint security, partnering with IT/Business Systems teams, and ensuring visibility into corporate systems for security detection and response, as well as streamlining evidence collection for audits.

What you'd actually do

  1. Support implementation of our Identity Governance and Administration (IGA) application to ensure that employees can seamlessly gain the appropriate level of access for their role and we can efficiently meet compliance objectives for access approvals and revocation of access upon separation.
  2. Evolve our corporate device trust program to ensure only compliant devices can access corporate and production systems.
  3. Support endpoint security efforts including security policies, controls, and vulnerability management
  4. Partner with our IT & Business Systems team and provide security expertise and oversight over the implementation and operations of SaaS applications and business systems
  5. Partner with the Security Detection & Response team to ensure visibility into corporate systems including development of scripts and integrations as needed

Skills

Required

  • Demonstrated experience deploying new IT systems and processes across the organization with high user satisfaction.
  • Demonstrated ability to identify risks and vulnerabilities in IT and business systems and to work cross-functionally throughout the company to balance risk with company priorities and effectively communicate risk to stakeholders.
  • Understanding of and ability to debug IT systems, including X.509, SAML, SCIM.
  • Familiarity with endpoint engineering for macOS and Windows
  • Software Engineering and DevOps experience with proficiency in python and/or golang as well as familiarity with Terraform and/or Pulumi
  • 4+ years of experience in security-focused software engineering, corporate engineering, IT, and/or program management.

Nice to have

  • Experience with Okta, Salesforce, NetSuite, Workday, Microsoft Entra/Azure/InTune, JAMF, and/or ConductorOne is a plus

What the JD emphasized

  • secure, trustworthy, and compliant platform
  • securing the data entrusted to us by our customers as well as our corporate intellectual property
  • validate every assumption through threat modelling, real-world testing, and by incorporating lessons learned from breaches and attacks at other companies
  • 4+ years of experience in security-focused software engineering, corporate engineering, IT, and/or program management