> Markdown version of [/jobs/ext/2708191-it-security-engineer](https://www.wearedevelopers.com/jobs/ext/2708191-it-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Engineer - **Company:** Higgsfield Inc. - **Location:** United States - **Salary:** $165,000.0 - $250,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Authentication Protocols, Software as a Service, Cloud Computing Security, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Networking Basics, Network Segmentation, Role-Based Access Control, Remote Access Technology, Azure Active Directory, Zero Trust Network Access, Reverse Engineering, Security Assertion Markup Language (SAML), Security Information and Event Management, Systems Integration, Scripting, Software Security, Microsoft InTune, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/it-security-engineer-higgsfield-8795754 ## About the Role * Strong hands-on experience with identity and access management, ideally within Microsoft Entra ID. * Experience implementing or managing SSO/SAML, SCIM, MFA, Conditional Access, RBAC, and JML workflows. * Experience with MDM and endpoint security, ideally Microsoft Intune and modern EDR tooling. * Understanding of SaaS and corporate application security. * Experience implementing or operating within a Zero Trust security model. * Ability to automate workflows using scripts and APIs, with experience in a language such as Python or JavaScript. * Working knowledge of security detection, investigation, and incident response. * Strong security judgment - you can distinguish theoretical risk from meaningful business risk and prioritize accordingly. * Comfortable operating independently in a fast-moving startup environment where priorities can change quickly. * Builder mindset: you look for ways to automate, simplify, and improve systems rather than relying on manual processes. Nice to Have * Experience with reverse engineering, CTFs, security competitions, or similar hands-on security challenges. * Strong understanding of networking fundamentals, including VPNs, network segmentation, authentication protocols, and common lateral-movement techniques. * Experience securing rapidly scaling or highly technical organizations. * Experience working closely with engineering or product security teams. * Familiarity with cloud security concepts and modern security monitoring tools. ## Description We're looking for an IT Security Engineer to own and strengthen the security of our corporate technology environment. This is a hands-on role spanning identity and access management, endpoint security, SaaS security, Zero Trust, security automation, and incident response. You'll work closely with Security, IT, Engineering, and business teams to build secure, scalable systems and automate the controls that protect our people, devices, applications, and data., * Own and strengthen identity and access controls across our corporate environment, with a focus on Microsoft Entra ID. * Implement and maintain SSO/SAML, SCIM provisioning, MFA, Conditional Access, and RBAC. * Build and improve automated joiner, mover, and leaver (JML) workflows. * Regularly review permissions, privileged access, and authentication policies to reduce unnecessary access and security risk. * Help establish identity as the foundation of our Zero Trust security model., * Manage and improve endpoint security through Microsoft Intune/MDM, device compliance policies, and endpoint protection tooling. * Deploy and maintain EDR capabilities across the corporate fleet. * Establish and enforce security baselines for employee devices. * Investigate endpoint security events and remediate compromised or non-compliant devices., * Assess and improve the security posture of corporate SaaS applications. * Partner with application owners to implement appropriate authentication, authorization, provisioning, and data-access controls. * Identify shadow IT, excessive permissions, insecure configurations, and other SaaS-related risks. * Help establish scalable security standards for onboarding and managing new corporate applications. Zero Trust & Corporate Access * Design and implement Zero Trust principles across identity, endpoints, applications, and corporate access. * Strengthen controls around privileged access, remote access, and access to sensitive systems. * Apply practical security controls that balance strong protection with employee productivity., * Automate repetitive security and IT workflows using scripts, APIs, and integrations. * Build tooling to automate access reviews, provisioning, compliance checks, alert enrichment, remediation, and other security processes. * Use scripting languages such as Python or JavaScript to improve security operations and reduce manual work. * Look for opportunities to turn manual security processes into scalable, reliable systems. Detection & Incident Response * Monitor and investigate security alerts across identity, endpoint, and corporate systems. * Perform initial investigation and triage of suspicious activity and potential security incidents. * Support incident containment, remediation, and post-incident improvements. * Build lightweight detections and alerts for meaningful risks within the corporate environment. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)