Sr. Security Engineer, Corporate Information Security
Core
Designing, implementing, and continuously improving identity architecture, privileged access controls, endpoint hardening standards, and overall workforce security posture for a financial services company.
Role type
Senior IC Security Engineer (Workforce Security & IAM)
Builds
Identity and access management systems, secure access patterns across SaaS and endpoints, AI tool security guardrails, and vulnerability management programs.
Domain
Financial Services / Cybersecurity (Identity & Access Management)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IAM architecture (SAML, OIDC, OAuth, SCIM, LDAP), Enterprise IAM platforms (Okta, Entra ID), RBAC design, Lifecycle automation, Endpoint hardening (CIS benchmarks), Vulnerability management, Python/Go automation, AI tool security governance, Compliance frameworks (SOC 2, ISO 27001, NIST)
Preferred skills
Privileged Access Management (CyberArk, BeyondTrust), Identity Governance & Administration (Saviynt, SailPoint), Policy-as-code (OPA/Rego), MDR/SOC partnership, Security certifications (CISSP)
Technologies
Okta, Google Workspace, Slack, Atlassian, Glean, Jamf, Wiz, Vanta, Drata, Abnormal Security, Proofpoint, HashiCorp Vault, Doppler
Responsibilities
Define and evolve the workforce IAM roadmap and SSO architecture; Lead initiatives for authentication, authorization, federation, and privileged access (PIM); Manage security of corporate communication platforms (email, Slack) including DLP and threat investigation; Define and enforce endpoint, mobile, and browser hardening standards; Lead the workforce vulnerability management program for endpoints and SaaS; Establish secure architecture for AI tool usage; Run UAR campaigns and drive remediation of audit findings.
Seniority
Senior, hands-on IC