Security Engineer, Enterprise Security

Turo Hospital
San Francisco, CA, United States
5 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$124,000.0 - $155,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software as a Service Cloud Computing Security Information Leak Prevention Identity and Access Management Python (Programming Language) Windows PowerShell Phishing Zero Trust Network Access EndPointSecurity Scripting Okta
+2 more
Containerization Terraform

Job description

Turo is searching for a highly motivated and versatile Security Engineer to support and execute our efforts in securing enterprise systems and data through the daily operation, administration, and implementation of our security framework. This role will focus heavily on building out and maintaining Zero Trust principles across the organization under the strategic direction of the Senior Engineer and Manager.

The successful candidate will have strong execution capabilities across enterprise domains, have a proactive technical mindset, and be eager to build automated security solutions from the ground up., * Support the implementation of Zero Trust security frameworks across the enterprise, focusing on daily enforcement of least privilege models.

  • Administer and maintain Advanced Email Security solutions to protect against phishing, spoofing, and email threats.
  • Deploy, operate, and triage alerts for Data Loss Prevention (DLP) and Insider Threat prevention technologies.
  • Manage and optimize Endpoint Security configurations (e.g., CrowdStrike, Kandji) to safeguard corporate devices.
  • Collaborate with Identity Governance teams to administer and enforce secure user access control policies (e.g., Okta lifecycle workflows).
  • Support evidence gathering and control verification to ensure ongoing compliance with SOX and SOC 2 standards.
  • Deliver and manage regular Security Awareness Training programs and corporate phishing simulations.
  • Utilize Infrastructure as Code (specifically Terraform templates) to maintain automated security configurations.
  • Actively participate in the Incident Response on-call rotation, triaging security alerts, executing defined automation playbooks, and mitigating security incidents swiftly.
  • Evaluate and maintain the baseline security posture of integrated third-party SaaS applications

Requirements

  • 3+ years of experience in enterprise security, focusing on core administration of email security, DLP, or endpoint detection tools.
  • Solid knowledge of identity governance, SaaS security baselines, and standard compliance frameworks (SOX/SOC 2).
  • Proficiency in scripting basic security automations using Python or PowerShell.
  • Familiarity or baseline experience working with containerized environments, GitOps workflows, and AWS security suites.
  • Industry certifications like Security+, GSEC, or CEH are a plus.

For this role, the target base salary range in San Francisco is $124,000-$155,000 annually. This role is also eligible for equity and benefits. In general, our ranges reflect the market-based target for new hire salaries based on the level and location of the role. Within the range, individual pay is determined by objective factors assessed during the application and interview process, such as job-related skills, experience, and relevant education or training. We encourage you to talk with your recruiter to learn more about the total compensation and benefits available for this role.

Benefits & conditions

  • Competitive salary, equity, benefits, and perks for all full-time employees
  • Employer-paid medical, dental, and vision insurance (Country specific)
  • Retirement employer match
  • Learning & Development stipend to invest in your professional development
  • Turo host matching program
  • Turo travel credit
  • Cell phone and internet stipend
  • Paid time off to relax and recharge
  • Paid holidays, volunteer time off, and parental leave
  • For those who are in the office full-time or hybrid we have in-office lunch, office snacks, and fun activities

We are committed to building a diverse team. If you are from a background that’s underrepresented in tech, we’d love to meet you.

Aside from an award winning work environment and the opportunity to be part of the world’s largest car sharing marketplace, we are also growing the team quickly - join us! Even if you don’t meet every qualification, we are looking for people with enthusiasm for what we do and we will consider you for this and other possibilities.

About the company

Turo is the world’s largest car sharing marketplace where you can book the perfect car for wherever you’re going from a vibrant community of trusted hosts across the US, UK, Canada, Australia, and France. Whether you’re flying in from afar or looking for a car down the street, searching for a rugged truck or something smooth and swanky, Turo puts you in the driver’s seat of an extraordinary selection of cars shared by local hosts.

Discover Turo at https://turo.com, the App Store, and Google Play, and check out our blog, Field Notes.

Read more about the Turo culture according to Turo CEO, Andre Haddad.

Turo is an Equal Opportunity Employer and a participant in the U.S. Federal E-Verify program. Women, minorities, individuals with disabilities and protected veterans are encouraged to apply. We welcome people of different backgrounds, experiences, abilities and perspectives.

Turo will consider qualified applicants with criminal histories in a manner consistent with the San Francisco Fair Chance Ordinance, as applicable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all