> Markdown version of [/jobs/ext/2006761-security-engineer-l5-workforce-security](https://www.wearedevelopers.com/jobs/ext/2006761-security-engineer-l5-workforce-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (L5) - Workforce Security - **Company:** Netflix, Inc. - **Location:** East Coast of the United States, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Macintosh Computers, Linux, Software Vulnerability Management, Scripting, Cyber Threat Analysis, Microsoft InTune, Patch Management, Casper Suite, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.workingnomads.com/job/go/1777890/ ## About the Role * Knowledge of commercially available endpoint MDM solutions such as Jamf, Kandji, or Intune * Working experience with commercially available endpoint vulnerability scanning tools such as CrowdStrike, Tenable * Experience designing and testing host hardening configuration for at least two of the major operating systems (Mac, Windows, Linux). * Understanding of Vulnerability Management practices * Threat Modeling competency to influence control right-sizing and other prioritization efforts * Ability to validate publicly disclosed exploits and perform variant analysis * Scripting (must be able to script, not to production level, and use of GenAI is sufficient) * Autonomously drives work delivery (bias to action) * Cross-functional collaboration skills * High-level familiarity with the functionality of commercially available corporate security tooling in the areas of endpoint, identity, data, and vendor security. * Ability to navigate ambiguity by taking strategic goals and decomposing them into actionable project plans * Using measurement and metrics to drive decision-making and outcomes ## Description We are seeking a talented L5 Security Engineer specializing in Endpoint Security to join our team. In this role, you will be critical to identifying and managing risks across all software on Netflix endpoints. You will drive the development of scalable technical security controls that enhance business agility and reduce risk for workforce-related business scenarios. The Workforce Security Engineer role focuses heavily on designing, implementing, and validating protective endpoint security controls. This includes developing and rolling out solutions for host hardening, vulnerability identification, and effective patch management to maintain defined security standards and prevent configuration drift across devices. Rapid genAI adoption and evolving genAI threats are changing our endpoint posture needs. A critical component of the role is designing and testing host hardening configurations for Mac, Windows, and Linux systems. You will also be responsible for designing and executing a comprehensive Patch and Vulnerability Management Strategy, enforcement, and applying Threat Intelligence to prioritize the remediation of endpoint vulnerabilities at the OS, App, and App Configuration levels. Where necessary, you will also evaluate build vs. buy security capabilities through requirement gathering, cost-benefit analysis, and accurate estimation of development effort. Beyond the technical implementation, this position requires strong communication and risk translation skills, specifically the ability to translate complex technical risks into clear business risks for stakeholders to inform trade-off decisions. Finally, the role includes providing standard business-hours operational support for Workforce Security and participating in infrequent 24/7 Incident Response as needed. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)