Назад
Company hidden
1 день назад

Security Engineer, Corporate Security (Cybersecurity)

130 950 - 202 125$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer, Corporate Security (Cybersecurity): Building identity, endpoint, SaaS security, and corporate security automation across Flexport’s workforce environment with an accent on phishing-resistant authentication, device policy as code, EDR coverage, and SaaS posture management. Focus on detecting account takeover and session theft, automating access and device lifecycle controls, and securing AI agent and MCP integrations.

Location: United States; regular in-person work in the San Francisco office

Salary: $130,950–$202,125 USD annually, depending on location, level, experience, and other factors. Additional compensation may include bonus, equity, and benefits.

Company

hirify.global provides technology for global commerce and supply chain operations, moving merchandise across more than 112 countries.

What you will do

  • Advance identity security through SSO coverage, phishing-resistant MFA, SCIM lifecycle automation, and least-privilege access across SaaS and cloud environments.
  • Build detections and guardrails for account takeover, MFA fatigue attacks, and session token theft.
  • Write and deploy device policies as code, configuration profiles, remediation scripts, and enforcement rules for macOS and Windows with staged rollouts and rollback support.
  • Maintain and improve EDR detection and response coverage across the device fleet.
  • Reduce SaaS risk using SSPM tooling and automation, including OAuth grant monitoring, shadow IT detection, and configuration drift management.
  • Automate device provisioning, access reviews, and vendor security questionnaires while documenting controls and partnering with IT and People teams.

Requirements

  • 2–5 years of experience in corporate, enterprise, or IT security engineering.
  • Hands-on experience with endpoint management and EDR tools such as Jamf, Kandji, Intune, CrowdStrike, or SentinelOne.
  • Working knowledge of SAML, OIDC, SCIM, and a major identity provider such as Okta, Entra, or Google Workspace.
  • Ability to write production code or scripts in Python, Go, or a similar language.
  • Clear, practical communication skills for explaining security control tradeoffs to technical and business stakeholders.

Nice to have

  • Experience with SSPM tooling and OAuth grant governance.
  • Exposure to DLP or insider-risk tooling.
  • Familiarity with Terraform for managing security configuration.
  • Understanding of how agentic AI tools and MCP integrations affect corporate security monitoring.
  • Interest in expanding into broader corporate security or detection engineering.

Culture & Benefits

  • Work closely with teammates across continents through Slack, video, and asynchronous documentation.
  • Use current hardware and software, including frontier AI models.
  • Teams choose practical working methods without rigid adherence to a single process.
  • Own defined security projects end to end, from design through rollout.
  • Comprehensive benefits include medical and dental coverage, flexible time off, bonus, and equity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →