Workforce Security Engineer

Future plc
Austin, TX, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Artificial Intelligence Apple Mac Systems Software as a Service Cloud Computing Security Human Resources Information System (HRIS) Identity and Access Management Python (Programming Language) OAuth OpenID Windows PowerShell Azure Active Directory
+9 more
Phishing Zero Trust Network Access Security Assertion Markup Language (SAML) Scripting Large Language Models Microsoft InTune Patch Management Cloudflare Casper Suite

Job description

We are hiring a Workforce Security Engineer to secure how our people work: their identities, their devices, and the SaaS and collaboration stack they use every day. Identity is the active front line. You’ll design and build phishing-resistant authentication, tighten admin access, automate the joiner/mover/leaver lifecycle, and harden the endpoint and workplace estate. If you’d rather automate an identity problem out of existence than click through an admin console forever, you’ll fit here. Security is core to the product and the company, and we are engineering-led: we buy managed protection where it makes sense and spend headcount on engineers who automate and extend the stack. You’ll be one of the first hires on this team, owning a domain rather than a slice of someone else’s.

Responsibilities

  • Harden our IdP (Microsoft Entra) with phishing-resistant authentication, Conditional Access, privileged-access tiering (PIM), and admin-account protections
  • Drive SSO enforcement across SaaS and automate the joiner/mover/leaver lifecycle (HRIS-to-IdP)
  • Manage workforce secrets (e.g., 1Password) and build contingent-worker and non-human identity models
  • Own MDM (e.g., Intune), EDR (e.g., CrowdStrike Falcon), device posture (e.g., Fleet), endpoint hardening, vulnerability and patch management, and reliable device lock/recovery at offboarding
  • Harden the workplace stack (e.g., M365) and email security (e.g., Microsoft Defender), data-loss prevention, and SaaS posture/CASB and connectivity (e.g., Cloudflare One)
  • Govern AI tooling access for the workforce
  • Build the controls and automation that govern workforce access into customer environments
  • Participate in the shared incident-response and on-call rotation

Requirements

  • 5+ years in identity/IAM, corporate/workforce security, or security engineering
  • Hands-on IAM depth: an enterprise IdP (Entra/Azure AD or equivalent) and the auth protocols (SAML, OIDC, OAuth), including MFA and Conditional Access
  • Endpoint management experience (Intune, Jamf, or equivalent) across macOS and Windows
  • Scripting/automation skills (e.g., Python, PowerShell) to replace manual identity and endpoint toil
  • Working knowledge of M365 / workplace SaaS security

Preferred Qualifications

  • Identity-lifecycle/IGA automation and SCIM provisioning
  • DLP, CASB, and SaaS posture management
  • Zero-trust / device-trust-at-authentication models
  • Experience securing AI tool usage and LLM gateways for a workforce

Benefits & conditions

  • A high-performance culture
  • State-of-the-art technology
  • Experience world-class leadership
  • Scale of impact and purpose
  • A competitive salary and a huge growth trajectory
  • Work with the best in the industry
  • Flexible work environment
  • Diversity and creativity

About the company

At Future Secure AI, we’re building something genuinely new - and we’re looking for people bold enough to build it with us. We work at the frontier of AI, tackling big, real-world problems for global enterprises across multiple industries, armed with state-of-the-art technology and a culture that prizes courage, rigor, and relentless curiosity. Our BRAVER values aren’t just words on a wall - they describe the kind of people we are and the standard we hold ourselves to every day. Our leadership team is entrepreneurial, experienced, and accessible, with an open-door policy that means you’ll never be just a number here. We invest seriously in your growth because we know our success depends on yours. If you’re ready to work alongside some of the brightest minds in the industry, push into uncharted territory, and do work that genuinely matters, Future Secure AI is the place for you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all