11 дней назад
Enterprise Engineer (Identity & Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Enterprise Engineer (Identity & Security) (AI engineering software): Building and operating enterprise identity, device management, and secure access infrastructure for an AI-driven simulation software stack with an accent on Entra ID, zero trust, SASE, and infrastructure as code. Focus on designing conditional access and least-privilege controls, automating identity and device workflows, and aligning enterprise IT with AWS, GCP, and Azure security requirements.
Location: New York, United States; hybrid work with time in the New York office and work-from-home days
Company
is a deep-tech company building AI-driven simulation software for engineering and manufacturing across aerospace, defense, materials, energy, semiconductors, and automotive industries.
What you will do
- Own and evolve the Microsoft Entra ID environment, including identity architecture, Conditional Access, MFA, PIM, SSO, SCIM, and hybrid identity.
- Manage identity, networking, and security infrastructure as code with Terraform.
- Design and implement zero-trust network access and SASE-based access controls to replace legacy VPN patterns.
- Own MDM strategy across macOS, Windows, Linux, and mobile devices, including enrollment, compliance, patching, and endpoint security posture.
- Partner with platform and DevOps teams to align enterprise IT and AWS, GCP, and Azure security postures.
- Lead access reviews, least-privilege enforcement, identity governance, and audit-readiness work for SOC 2 and ISO 27001.
Requirements
- 5–10 years of experience in enterprise IT, security engineering, identity, or infrastructure roles.
- Deep hands-on production ownership of Microsoft Entra ID/Azure AD and Conditional Access policy design.
- Experience with Entra ID Governance, Access Reviews, Identity Protection, PIM, SSO/SAML/OIDC federation, and SCIM provisioning.
- Experience with endpoint security and EDR platforms such as CrowdStrike or Defender for Endpoint.
- Ability to automate identity and device workflows with PowerShell, Python, or Microsoft Graph API.
- Experience with hybrid identity and compliance frameworks including SOC 2, ISO 27001, and FedRAMP.
Nice to have
- Cloud IAM and security architecture experience across AWS and Google Cloud.
- Experience with Cloudflare Zero Trust, compliance automation tools such as Vanta or Drata, and SIEM/EDR/XDR tooling.
- Background in an AI or high-growth SaaS company.
- Experience supporting UK/EU data protection requirements such as GDPR.
- Relevant certifications including SC-300, SC-100, MD-102, Security+, CCNA, or SASE vendor certifications.
Culture & Benefits
- Hybrid work model combining collaboration in the New York office with work-from-home days.
- Flat structure with emphasis on impact, collaboration, and challenging assumptions.
- Equity options and a 5% 401(k) contribution.
- Private health insurance, FSA, enhanced parental leave, and 20 days of annual leave plus public holidays.
- Weekly team lunch, personal development support, and subsidized Gympass/Wellhub for employees and up to three family members.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Senior Infrastructure Engineer
14 дней назад
Senior Systems Administrator (Microsoft 365 GCC High)
133 500 - 190 050$
11 дней назад
Systems Engineer I (Azure/AWS)
13 дней назад
Senior End User Platform Engineer (Microsoft 365)
14 дней назад
IT Engineer (Fintech)
90 000 - 180 000$
14 дней назад
Senior IT Systems Engineer
121 000 - 140 000$