Security & Policy Engineer
Core
Build the security and policy layer for a regulated enterprise platform, implementing fail-closed controls, least privilege access, audit evidence, and defensible compliance posture.
Role type
Senior IC Security & Policy Engineer
Builds
Security controls, policy enforcement mechanisms, audit trails, and secure integrations for enterprise buyers
Domain
Cybersecurity, Identity & Access Management (IAM), Compliance Engineering
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
policy decision points, policy enforcement points, RBAC/ABAC workflows, threat modeling, secure design reviews, tenant isolation, mTLS, certificate lifecycle, key management, secure APIs, encryption, secrets management, audit logging, identity federation
Preferred skills
OPA, Rego, Keycloak, SPIFFE/SPIRE, service mesh security, SIEM integrations, cloud KMS/HSM patterns, SOC 2, ISO 27001, financial services security reviews, AI governance, model risk management, data loss prevention, privacy engineering
Technologies
OPA, Rego, Keycloak, SPIFFE, SPIRE, mTLS, SIEM, KMS, HSM
Responsibilities
Implement policy decision points, policy enforcement points, audit trails, and RBAC/ABAC workflows; Integrate external IAM and policy systems through provider abstractions; Own threat models, secure design reviews, abuse cases, data-flow analysis, and security test requirements; Build controls for tenant isolation, service authentication, mTLS, certificate lifecycle, and key management; Create secure-by-default engineering patterns and partner with QA on negative tests and regression suites; Support enterprise due diligence, security questionnaires, audit requests, and compliance evidence collection
Seniority
Senior, hands-on IC