> Markdown version of [/jobs/ext/3009757-security-engineer-enterprise-security](https://www.wearedevelopers.com/jobs/ext/3009757-security-engineer-enterprise-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Enterprise Security - **Company:** Ai Robotics - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $150,000.0 - $250,000.0 - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, IEEE 802.1X, Microsoft Windows, Artificial Intelligence, Apple Mac Systems, Bash Shell, Chrome OS, Software as a Service, Cloud Computing Security, Information Systems, Continuous Integration, Extract Transform Load (ETL), Data Security, Linux, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Identity and Access Management, Python (Programming Language), OAuth, OpenID, Windows PowerShell, Role-Based Access Control, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Engineering, Systems Integration, Software Vulnerability Management, Data Logging, Large Language Models, Sender Policy Framework (SPF), Information Technology - **Published:** September 20, 2026 - **Apply:** https://startup.jobs/security-engineer-enterprise-security-figure-2-10114609 ## About the Role * Software engineering discipline in Python, Bash, PowerShell, or similar: integrations and internal tooling as normal work * Configuration-as-code and CI/CD applied to corporate infrastructure * Threat-modeling judgment that separates the problems worth solving from the ones existing controls already cover, and drives the former to completion * 6+ years in corporate or enterprise security engineering * Bachelor's in Computer Science, Engineering, or Information Systems, or equivalent experience Depth required in at least one of the below, knowledge of the others * Endpoint security on at least two of macOS, Windows, Linux, and ChromeOS: MDM profile engineering, application allowlisting, endpoint security frameworks, and the OS internals behind them. Preferred: fleet-wide osquery telemetry, certificate-based device identity in production, a phased enforcement change shipped with a recovery plan, and devices that live off the corporate network. * Identity and access: IAM, SaaS security, and zero trust from fundamentals rather than vendor docs, and being able to explain a SAML, OIDC, or SCIM integration for a developer who has never built one. Preferred: mTLS, 802.1X, SSH certificate authorities, and DKIM, DMARC, and SPF in production. * Application access design: threat modeling what an application exposes, specifying authentication and authorization for the team building it, and designing the provisioning and revocation behind it. Preferred: securing agentic or LLM-integrated systems, including permission models, credential isolation, and egress control. ## Description Endpoints and access * Build the endpoint hardening controls across macOS, Windows, Linux, and ChromeOS. Our fleet runs on FleetDM, an osquery-based MDM managed through GitOps: you author the control, you write the query proving it landed, and you ship both in a merge request for review. * Bind data access to a healthy managed device and the person it was issued to: phishing-resistant factors, session lifetimes, and device posture checks. * Bring AI assistants and coding agents under enterprise management: configuration and permissions delivered and verified like any other endpoint control. Applications and third parties * Design application authentication, RBAC, and access lifecycle from first principles: identify what an application exposes, threat model it, propose control requirements, and guide owners to implement them. * Contribute what each engagement teaches to the team's default deployment playbooks: authentication, logging, and network placement. * Run security review and governance for SaaS and third parties: vendor assessments, OAuth grants, connector integrations, browser extensions, and data movement through the browser. Visibility and measurement * Build the inventories this work depends on: application discovery, application posture management, grant tracking. Feed vulnerability management and build the controls that close what it finds. * Threat model the corporate attack surface as a repeatable practice and feed the results into what the team works on next. Partner with Detection and Response on telemetry and with IT on rollout. * Use AI where it earns its place: prepping access reviews, first-pass triage, and analysis that gets a human to a decision faster. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)