Sr. Security Engineer, Corporate Information Security

Betterment Betterment · Fintech · New York, NY · Internal Engineering

This role is for a Sr. Security Engineer focused on Corporate Information Security at Betterment, a fintech company. The primary responsibility is to manage and secure identity and access across the company's systems, including SaaS applications, endpoints, and mobile devices. A key aspect of the role involves partnering with the AI Governance team to evaluate, enable, and secure the use of AI tools, establishing guardrails and ensuring secure architecture for AI tool usage, data handling, and access controls, particularly for AI agents acting on behalf of users. The role requires hands-on implementation, architectural design, and operational support for identity and access management, privileged access controls, and endpoint hardening, with a focus on secure AI tool integration and monitoring.

What you'd actually do

  1. Define and evolve the workforce IAM roadmap.
  2. Lead initiatives across authentication, authorization, federation, and privileged access.
  3. Manage the security of corporate communication platforms, including email and Slack, through tools such as Abnormal Security and Proofpoint.
  4. Define and enforce hardening standards aligned with CIS benchmarks.
  5. Establish and enforce a secure architecture for AI tool usage, data handling boundaries, connector security, identity-aware access controls, and detection for misuse with a bias toward enabling the business safely rather than gating it.

Skills

Required

  • IAM and corporate security
  • identity and logical access management
  • change management
  • Okta
  • Google Workspace
  • Slack
  • Atlassian
  • Glean
  • Jamf
  • SaaS security
  • Windows
  • Linux
  • identity architecture
  • privileged access controls
  • endpoint hardening
  • workforce security posture
  • SaaS
  • managed browser
  • mobile
  • workstation environments
  • authentication
  • authorization
  • federation
  • SAML
  • OIDC
  • OAuth
  • SCIM
  • LDAP
  • enterprise IAM platforms
  • Entra ID
  • RBAC design
  • lifecycle automation
  • Identity Center
  • SSO
  • PIM-equivalent
  • break-glass models
  • non-human identities
  • service accounts
  • API tokens
  • AI agents
  • Zero Trust
  • least-privilege principles
  • DLP enforcement
  • email investigations
  • spam
  • phishing
  • endpoint management
  • EDR
  • CIS benchmarks
  • macOS
  • mobile
  • managed browser
  • enterprise browser security
  • extension governance
  • session protection
  • vulnerability management
  • remediation SLAs
  • SaaS posture tooling
  • Wiz
  • Vanta
  • Drata
  • automation
  • tools and pipelines
  • regulated environment experience

Nice to have

  • AI Governance & enablement
  • AI tools (ChatGPT, Claude, Glean Assistant)
  • agentic tooling
  • Abnormal Security
  • Proofpoint
  • user access review campaigns
  • SOC 2
  • ISO 27001
  • MDR MSP
  • identity-related detection and incident response
  • GRC capabilities

What the JD emphasized

  • AI agents that increasingly act on users' behalf
  • AI Tool Security
  • secure architecture for AI tool usage