Staff CorpSec Engineer
Staff Corporate Security Engineer
About the role
We're looking for a Staff Corporate Security (CorpSec) Engineer to secure the environment our employees work in every day — devices, identity, SaaS applications, and the corporate network. This is a senior, hands-on role focused on protecting the internal attack surface: the laptops, logins, and tools that, if compromised, give attackers a foothold into everything else.
As a Staff engineer, you'll set the technical direction for corporate security, build the systems and automation that make secure the default for every employee, and raise the bar for how we protect our workforce — all while keeping the experience smooth enough that people don't route around it.
What you'll do
Own the security of our endpoint fleet (macOS, Windows, Linux): hardening, EDR, patching, and device compliance via MDM.
Design and operate our identity and access architecture: SSO, MFA, conditional access, and least-privilege access to corporate systems and SaaS.
Drive our zero-trust strategy for corporate access, reducing reliance on the network perimeter.
Secure our SaaS estate: configuration hardening, monitoring, and automated detection of risky changes and access.
Build automation and tooling that scale corporate security — provisioning/deprovisioning, access reviews, and self-service guardrails.
Partner with IT and Detection & Response to instrument corporate telemetry and surface high-signal detections for phishing, account compromise, and device threats.
Lead the corporate security response to phishing, account takeover, and endpoint incidents, then build the systems that prevent recurrence.
Set standards and mentor engineers across IT and security.
What we're looking for
Significant experience (typically 8+ years) in security engineering, with real depth in corporate/enterprise security.
Strong hands-on experience with endpoint security and management (EDR, MDM) across macOS and Windows.
Deep expertise in identity and access management: SSO, MFA, SAML/OIDC, and modern IdPs (e.g., Okta, Entra ID, Google Workspace).
Experience securing SaaS environments and driving zero-trust access.
Strong software/scripting skills (Python, Go, or similar) to automate security at scale.
Ability to balance strong security with a good employee experience, and to lead cross-team initiatives.
Nice to have
Experience with detection engineering for corporate telemetry.
Familiarity with device management tooling and osquery-style fleet visibility.
Background responding to phishing and account compromise at scale.
Experience securing a fast-growing, remote-friendly workforce.
How we define Staff level
At the Staff level, your impact extends beyond the systems you personally build. You'll set corporate security strategy, identify the highest-leverage risks to our workforce, elevate the engineers around you, and leave our internal attack surface materially harder to exploit.
Salary: 220k base
Values