> Markdown version of [/jobs/ext/3037850-staff-corporate-security-corpsec-engineer](https://www.wearedevelopers.com/jobs/ext/3037850-staff-corporate-security-corpsec-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Corporate Security (CorpSec) Engineer - **Company:** Turing Technology, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Build Automation, Software as a Service, Linux, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), OpenID, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Scripting, Okta, Gsuite - **Published:** September 23, 2026 - **Apply:** https://startup.jobs/staff-corpsec-engineer-turing-10152038 ## About the Role * Significant experience (typically 8+ years) in security engineering, with real depth in corporate/enterprise security. * Strong hands-on experience with endpoint security and management (EDR, MDM) across macOS and Windows. * Deep expertise in identity and access management: SSO, MFA, SAML/OIDC, and modern IdPs (e.g., Okta, Entra ID, Google Workspace). * Experience securing SaaS environments and driving zero-trust access. * Strong software/scripting skills (Python, Go, or similar) to automate security at scale. * Ability to balance strong security with a good employee experience, and to lead cross-team initiatives. Nice to have * Experience with detection engineering for corporate telemetry. * Familiarity with device management tooling and osquery-style fleet visibility. * Background responding to phishing and account compromise at scale. * Experience securing a fast-growing, remote-friendly workforce. ## Description We're looking for a Staff Corporate Security (CorpSec) Engineer to secure the environment our employees work in every day - devices, identity, SaaS applications, and the corporate network. This is a senior, hands-on role focused on protecting the internal attack surface: the laptops, logins, and tools that, if compromised, give attackers a foothold into everything else. As a Staff engineer, you'll set the technical direction for corporate security, build the systems and automation that make secure the default for every employee, and raise the bar for how we protect our workforce - all while keeping the experience smooth enough that people don't route around it. What you'll do * Own the security of our endpoint fleet (macOS, Windows, Linux): hardening, EDR, patching, and device compliance via MDM. * Design and operate our identity and access architecture: SSO, MFA, conditional access, and least-privilege access to corporate systems and SaaS. * Drive our zero-trust strategy for corporate access, reducing reliance on the network perimeter. * Secure our SaaS estate: configuration hardening, monitoring, and automated detection of risky changes and access. * Build automation and tooling that scale corporate security - provisioning/deprovisioning, access reviews, and self-service guardrails. * Partner with IT and Detection & Response to instrument corporate telemetry and surface high-signal detections for phishing, account compromise, and device threats. * Lead the corporate security response to phishing, account takeover, and endpoint incidents, then build the systems that prevent recurrence. * Set standards and mentor engineers across IT and security. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)