> Markdown version of [/jobs/ext/1178747-workforce-security-engineer](https://www.wearedevelopers.com/jobs/ext/1178747-workforce-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Workforce Security Engineer - **Company:** Future plc - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Apple Mac Systems, Software as a Service, Cloud Computing Security, Human Resources Information System (HRIS), Identity and Access Management, Python (Programming Language), OAuth, OpenID, Windows PowerShell, Azure Active Directory, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Scripting, Large Language Models, Microsoft InTune, Patch Management, Cloudflare, Casper Suite - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c8a3e63bbfa84f07 ## About the Role * 5+ years in identity/IAM, corporate/workforce security, or security engineering * Hands-on IAM depth: an enterprise IdP (Entra/Azure AD or equivalent) and the auth protocols (SAML, OIDC, OAuth), including MFA and Conditional Access * Endpoint management experience (Intune, Jamf, or equivalent) across macOS and Windows * Scripting/automation skills (e.g., Python, PowerShell) to replace manual identity and endpoint toil * Working knowledge of M365 / workplace SaaS security Preferred Qualifications * Identity-lifecycle/IGA automation and SCIM provisioning * DLP, CASB, and SaaS posture management * Zero-trust / device-trust-at-authentication models * Experience securing AI tool usage and LLM gateways for a workforce ## Description We are hiring a Workforce Security Engineer to secure how our people work: their identities, their devices, and the SaaS and collaboration stack they use every day. Identity is the active front line. You'll design and build phishing-resistant authentication, tighten admin access, automate the joiner/mover/leaver lifecycle, and harden the endpoint and workplace estate. If you'd rather automate an identity problem out of existence than click through an admin console forever, you'll fit here. Security is core to the product and the company, and we are engineering-led: we buy managed protection where it makes sense and spend headcount on engineers who automate and extend the stack. You'll be one of the first hires on this team, owning a domain rather than a slice of someone else's. Responsibilities * Harden our IdP (Microsoft Entra) with phishing-resistant authentication, Conditional Access, privileged-access tiering (PIM), and admin-account protections * Drive SSO enforcement across SaaS and automate the joiner/mover/leaver lifecycle (HRIS-to-IdP) * Manage workforce secrets (e.g., 1Password) and build contingent-worker and non-human identity models * Own MDM (e.g., Intune), EDR (e.g., CrowdStrike Falcon), device posture (e.g., Fleet), endpoint hardening, vulnerability and patch management, and reliable device lock/recovery at offboarding * Harden the workplace stack (e.g., M365) and email security (e.g., Microsoft Defender), data-loss prevention, and SaaS posture/CASB and connectivity (e.g., Cloudflare One) * Govern AI tooling access for the workforce * Build the controls and automation that govern workforce access into customer environments * Participate in the shared incident-response and on-call rotation ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)