Staff Corporate Security Engineer

Crusoe · Data AI · San Francisco, CA - US · IT, Compliance, and Security

Staff Corporate Security Engineer to architect and implement corporate security posture, focusing on Zero Trust, SASE, SaaS security, and AI-native security frameworks.

What you'd actually do

  1. Leading the design and implementation of Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) architectures, replacing legacy VPNs with identity-aware, perimeter-less access models
  2. Architecting preventative SaaS security across platforms such as Google Workspace, Slack, and Okta, including CASB controls to enforce data protection and monitor unauthorized applications or extensions
  3. Implementing Binary Authorization and device trust mechanisms, leveraging hardware-backed identity (e.g., TPM, Secure Enclave) to ensure only compliant devices can access corporate systems
  4. Designing and tuning Data Loss Prevention (DLP) controls across endpoints and SaaS platforms to protect intellectual property
  5. Architecting AI-native security frameworks, including governance and secure gateways for agent-based systems (e.g., MCP), ensuring all AI-driven actions are auditable and aligned with zero-trust principles

Skills

Required

  • 8+ years of experience designing and implementing Zero Trust, SASE, and modern identity-based security architectures
  • Strong expertise in SaaS security, including CASB, DLP, and governance across platforms like Google Workspace, Okta, and Slack
  • Experience implementing device trust, endpoint security, and hardware-backed identity solutions
  • Strong understanding of identity and access management systems (SSO, SAML 2.0, OAuth, SCIM) and secure access patterns
  • Knowledge of email security, phishing mitigation, and session security controls
  • Experience identifying and mitigating application-layer vulnerabilities such as IDOR and privilege escalation risks
  • Familiarity with emerging AI security challenges, including governance of agent-based systems and secure orchestration patterns
  • Strong architectural mindset with the ability to design preventative, scalable security systems
  • Excellent communication skills and ability to influence security decisions across engineering and business teams

Nice to have

  • Experience implementing CASB platforms and enterprise DLP solutions at scale
  • Familiarity with Model Context Protocol (MCP) or similar AI orchestration frameworks
  • Experience building “Secure by Default” environments in high-growth organizations
  • Background in cloud-native or AI infrastructure environment.

What the JD emphasized

  • AI-native security frameworks
  • agent-based systems