> Markdown version of [/jobs/ext/1988567-staff-corporate-security-engineer-in-san-francisco](https://www.wearedevelopers.com/jobs/ext/1988567-staff-corporate-security-engineer-in-san-francisco). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Corporate Security Engineer in San Francisco - **Company:** Energy Jobline - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $210,000.0 - $255,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Information Leak Prevention, Identity and Access Management, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, OAuth, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, AI Infrastructure, Okta, Multi-Agent Systems, Slack, Gsuite - **Published:** August 8, 2026 - **Apply:** https://www.energyjobline.com/job/staff-corporate-security-engineer-san-francisco-31405130 ## About the Role * 8+ years of experience designing and implementing Zero Trust, SASE, and modern -based security architectures * Strong expertise in SaaS security, including CASB, DLP, and governance across platforms like Google Workspace, Okta, and Slack * Experience implementing device trust, endpoint security, and hardware-backed solutions * Strong understanding of and access management systems (SSO, SAML 2.0, OAuth, SCIM) and secure access patterns * Knowledge of email security, phishing mitigation, and session security controls * Experience identifying and mitigating application-layer vulnerabilities such as IDOR and privilege escalation risks * Familiarity with emerging AI security challenges, including governance of agent-based systems and secure orchestration patterns * Strong architectural mindset with the ability to design preventative, scalable security systems * Excellent communication skills and ability to influence security decisions across engineering and business teams Bonus Points * Experience implementing CASB platforms and enterprise DLP solutions at scale * Familiarity with Model Context Protocol (MCP) or similar AI orchestration frameworks * Experience building "Secure by Default" environments in high-growth organizations * Background in cloud- or AI infrastructure environment. ## Description * Leading the design and implementation of Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) architectures, replacing legacy VPNs with -aware, perimeter-less access models * Architecting preventative SaaS security across platforms such as Google Workspace, Slack, and Okta, including CASB controls to enforce data protection and monitor unauthorized applications or extensions * Implementing Binary Authorization and device trust mechanisms, leveraging hardware-backed (e.g., TPM, Secure Enclave) to ensure only compliant devices can access corporate systems * Designing and tuning Data Loss Prevention (DLP) controls across endpoints and SaaS platforms to protect intellectual property * Strengthening email security posture, including MFA enforcement and session controls to mitigate phishing and session hijacking risks * Architecting AI- security frameworks, including governance and secure gateways for agent-based systems (e.g., MCP), ensuring all AI-driven actions are auditable and aligned with zero-trust principles * Scaling and access management systems, including SSO, SAML, OAuth, SCIM, and designing Just-In-Time (JIT) access workflows to eliminate standing privileges * Defining and executing a "Crown Jewels" security methodology, identifying and remediating high-risk vulnerabilities (e.g., IDOR, role-bypass) across critical systems ## Related Videos - [Stack Overflow: Community and AI](https://www.wearedevelopers.com/videos/600-stack-overflow-community-and-ai) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Cloud as the new mainframe: why the cloud hype does not reflect the dev reality](https://www.wearedevelopers.com/videos/797-cloud-as-the-new-mainframe-why-the-cloud-hype-does-not-reflect-the-dev-reality) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)