> Markdown version of [/jobs/ext/1799307-enterprise-security-engineer](https://www.wearedevelopers.com/jobs/ext/1799307-enterprise-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise Security Engineer - **Company:** TRM Labs - **Location:** United States (Remote available) - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Apple Mac Systems, Bash Shell, Software as a Service, Cloud Computing Security, Identity and Access Management, Python (Programming Language), Windows PowerShell, Single Sign-On, Systems Integration, Policy as Code, Data Processing, Large Language Models, Software Troubleshooting, Firewalls (Computer Science), Microsoft InTune, Gsuite, Terraform - **Published:** July 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=af05e52ef83c0323 ## About the Role * Demonstrated experience engineering and scaling endpor Intune) and endpoint security controls for macOS and Windows. * Strong IAM foundation: hands-on experience with Entra ID (conditional access, SSO, access governance) and Google Workspace and/or Microsoft 365 administration. * Proven ability to automate real operational workflow (Bash, PowerShell, Python, etc.). * Fluency with AI-assisted engineering: you already reach for coding agents and LLM tooling to build, review, and investigate faster, and you can judge where their output needs verification * Strong troubleshooting and systems thinking: identity, endpoint, network controls, and SaaS integrations. * Comfort balancing security and usability using a risk-based approach, communicating tradeoffs clearly to technical and non-technical stakeholders. Strong Plus: * Working knowledge of operating Infrastructure-as-Code / configuration-as-code (Terraform preferred; policy-as-code/config profiles acceptable) * Security Incident Response & Countermeasures experie * Security Operation Center experience * Experience securing or governing enterprise AI adoption (AI usage policy, DLP for AI tools, agent/MCP access scoping), * Priorities and targets to change quickly as we experiment and iterate * Work that often requires operating with a high degree of ambiguity * A high level of personal ownership and accountability * Close collaboration across teams and functions * Frequent, high-touch communication * Creative problem solving and out-of-the-box thinking * A pace that rewards urgency, adaptability, and outcomes This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment. We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here. At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more: Interviewing at TRM: How We Hire and What Success Looks Like ## Description * TRM's Enterprise Security Team secures the identities, endpoints, and core SaaS infrastructure used by every employee and contractor, so the company can move fast without taking unnecessary risk. We operate at the intersection of IT and Security: building secure-by-default systems, automating controls, and reducing operational toil through engineering. We use AI tooling heavily as part of how we work, and we expect the same of the engineers who join us. * We're looking for an Enterprise Security Engineer to help harden and scale our corporate environment. You'll design and ship identity, endpoint, and SaaS security improvements; codify controls using automation and infrastructure-as-code; and partner closely with Security, Compliance, and engineering teams to continuously raise the security baseline while preserving a great employee experience. The impact you will have here: * Engineer secure-by-default endpoint baselines for macOS and Windows, including encryption, firewall, application controls, device compliance, and configuration standards. * Automate and scale identity and access controls in Entra ID and Google Workspace (SSO, SCIM, conditional access, privileged access workflows, access reviews, joiner/mover/leaver). * Codify security controls as code (Terraform/configuration profiles/policy-as-code), with peer review, change history, testing/rollback, and measurable outcomes. * Build and maintain automations and integrations (e.g., n8n/SlackOps/APIs/scripts) that reduce manual access grants, speed up control changes, and eliminate repetitive workflows. * Apply AI tooling (Claude Code, agentic workflows, MCP integrations, LLM-backed automations) to accelerate your own engineering and triage work, and help secure how the rest of the company uses AI: sanctioned tooling, data handling guardrails, and visibility into shadow AI. * Harden SaaS and collaboration platforms by reducing unmanaged apps and enforcing strong authentication, least privilege, sharing controls, and data protection guardrails. * Improve visibility and detection by ensuring loggingr endpoint, identity, and key SaaS applications (e.g.,Defender/Sentinel and vendor logs where relevant). * Drive vulnerability and configuration drift reductio targets, remediation pipelines, and reporting that leadership can act on. * Partner with compliance and risk stakeholders to produce evidence, document controls, and operationalize requirements without creating brittle, manual processes. * Participate in an on-call rotation (every ~3 weeks) identity, endpoint security, and critical enterprise systems., We hire and grow against three leadership principles. They're the standards for how we operate, treat each other, and make decisions. * Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment - test, ship, measure, and iterate quickly. * Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end-to-end, and invest in getting better everyday. * Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one-team mindset - giving and receiving feedback to make the team stronger., By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy. We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM. Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at privacy@trmlabs.com. To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance. The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form. ## Related Videos - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How to Answer the Interview Question: “Why Do You Want to Be a Software Engineer?”](https://www.wearedevelopers.com/magazine/392-how-to-answer-the-interview-question-why-do-you-want-to-be-a-software-engineer) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)