Назад
2 дня назад

Lead Corporate Security Engineer

276 960 - 363 510$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Corporate Security Engineer (Corporate Security): Owning and maturing Suno’s corporate security domain across identity governance, endpoint security, detection and response, third-party risk, and SaaS posture with an accent on building security standards, roadmaps, and automation. Focus on designing RBAC and access lifecycle controls, reducing vulnerability exposure, leading incident response, and holding managed security providers to defined outcomes.

Location: Boston, United States

Salary: $276,960–$363,510 per year, plus equity

Company

Suno is a consumer entertainment company building an AI-powered music creation platform used by people ranging from casual creators to Grammy-winning artists.

What you will do

  • Own the corporate security roadmap, standards, risk appetite, sequencing, and outcomes in partnership with IT leadership and the CISO.
  • Design identity and access governance, including RBAC, least-privilege defaults, access reviews, lifecycle automation, and non-human identity controls.
  • Set endpoint security and vulnerability management standards for a macOS-primary fleet, including hardening, device trust, compliance, and remediation programs.
  • Lead detection and response through CrowdStrike Falcon Complete and the outsourced SOC, including tuning, vendor performance, and incident closure.
  • Own third-party integration risk, OAuth reviews, vendor assessments, SaaS security posture, and tenant-level configuration improvements.
  • Partner with IT, Security, Engineering, AI Enablement, and Legal while mentoring engineers and shaping future GRC and automation investments.

Requirements

  • 8+ years of experience in corporate, enterprise, or security engineering, including ownership of identity, endpoint, or SaaS security as a domain.
  • Hands-on expertise with a modern identity provider, preferably Okta, and access-governance tools such as Lumos, Veza, ConductorOne, or Opal.
  • Experience designing entitlement or RBAC models across large SaaS portfolios and managing macOS endpoint security at scale.
  • Strong EDR experience, preferably with CrowdStrike, and experience managing an outsourced SOC or managed detection provider against defined standards.
  • Strong knowledge of OAuth, SAML, OIDC, SCIM, REST APIs, and automation with Python or TypeScript.
  • Role location: Boston, United States. Strong writing, judgment under ambiguity, risk calibration, and cross-functional influence are required.

Nice to have

  • Detection engineering, insider risk, DLP, zero-trust network access, SOC 2, or ISO program ownership.
  • Just-in-time access, identity-as-code, AI agent and non-human identity security experience.
  • Experience as the first or second security hire at a fast-growing company.

Culture & Benefits

  • Work with a small, quality-focused engineering organization building a new entertainment medium.
  • High-ownership environment with fast pace, complex security challenges, and hands-on technical work.
  • Opportunity to build corporate security capabilities from 0 to 1 and mature existing systems from 1 to 10.
  • Equity is included in the compensation package.
  • Equal opportunity employment practices apply, including fair-chance hiring considerations under applicable laws.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →