> Markdown version of [/jobs/ext/3045336-security-engineer-enterprise-security](https://www.wearedevelopers.com/jobs/ext/3045336-security-engineer-enterprise-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Enterprise Security - **Company:** Coreweave Inc - **Location:** United States - **Experience:** Expert - **Salary:** $165,000.0 - $242,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Systems Engineering, Audit Trail, Build Automation, Business Software, Software as a Service, Cloud Computing, Cloud Computing Security, Collaborative Software, Cyber Security, Data Security, Human Resources Information System (HRIS), Hardware Security Module, Identity and Access Management, Python (Programming Language), Network Segmentation, OAuth, OpenID, Role-Based Access Control, Phishing, Zero Trust Network Access, Security Assertion Markup Language (SAML), Web Application Security, Security Information and Event Management, Systems Integration, Policy as Code, Scripting, Okta, Microsoft InTune, Containerization, Slack, Atlassian Tools, Casper Suite, Gsuite, Software Coding, Programming Languages - **Published:** September 24, 2026 - **Apply:** https://www.thejobnetwork.com/job/710d5ab3-0d53-482c-8a43-ed32f243fc34/senior-security-engineer-enterprise-security ## About the Role - **5+ years** of experience in **enterprise security** , **identity and access management** , or closely related security engineering roles. - Strong, practical understanding of modern **IAM concepts** : SSO, federation, RBAC/ABAC, JIT access, least privilege, and separation of duties. - Hands-on experience implementing and operating **SSO and workforce identity** with platforms such as **Okta, Entra ID** , or equivalent IdPs. - Deep familiarity with **SAML** , **OAuth 2.0/OIDC** , and **SCIM** , including real-world experience integrating these protocols with third-party SaaS and internal apps. - Demonstrated experience designing and rolling out **MFA** , ideally including **phishing-resistant** approaches (FIDO2/WebAuthn, hardware security keys, device-bound authenticators, step-up authentication). - Experience designing and deploying **zero trust** or context-aware access controls (e.g., device trust, network segmentation, mTLS, ZTNA) in hybrid or remote-friendly environments. - Proficiency in at least one modern scripting or programming language (e.g., **Python** , **Go** ) used to build automations, integrations, or internal tooling. - Experience securing and integrating **business-critical SaaS** (e.g., Google Workspace, Microsoft 365, Slack, Atlassian, HRIS, ticketing) including SCIM provisioning, access reviews, and audit log ingestion. - Familiarity with **MDM** and **endpoint security** tooling (e.g., Jamf, Intune, EDR platforms) and how they tie into identity and access decisions. - Exposure to **SIEM/detection** ecosystems (e.g., Elastic) and experience collaborating with detection & response teams on identity/endpoint/SaaS detections. - A track record of owning cross-functional projects from design through adoption, with an emphasis on measurable risk reduction and user experience. , - Experience working in **high-growth** or **hyperscale** environments where security must keep pace with rapid headcount and tooling expansion. - Hands-on experience with **zero trust network access** or secure access products (e.g., ZTNA, secure web gateways, or identity-aware proxies). - Familiarity with **enterprise security standards and frameworks** (e.g., SOC 2, ISO 27001, NIST 800-53) and mapping enterprise controls to these requirements. - Experience with **SaaS security posture management (SSPM)**, **CASB** , **DLP** , or **insider risk** tooling focused on collaboration platforms and data access. - Experience building or contributing to **internal security tooling** (e.g., access review automation, JML workflows, policy-as-code). - Participation in security communities, standards groups, or open-source contributions in IAM, zero trust, or enterprise security. ## Description CoreWeave is The Essential Cloud for AI . Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at [www.coreweave.com](http://www.coreweave.com/). ; ### What You'll Do: The **Enterprise Security** team at CoreWeave is responsible for securing how our people work every day-identity, endpoints, networks, and SaaS-so the company can move fast without compromising safety. This team owns the controls, guardrails, and automation that keep our workforce, contractors, and critical business applications protected in a modern, cloud-native environment. If you're excited about **zero trust** , **phishing-resistant MFA** , and building secure-by-default experiences that actually make people more productive, this is the team to join. ### About the Role: As a **Senior Security Engineer, Enterprise Security** , you'll design and ship the security controls that underpin CoreWeave's workforce and enterprise stack. You'll lead initiatives across identity, access management, device and endpoint security, and SaaS security-partnering closely with IT Engineering, Endpoint, Network, and other security teams. Your day-to-day will blend **hands-on engineering** (writing code, building integrations, tuning controls) with **architecture and program ownership** (setting standards, defining patterns, and driving adoption across teams). You'll be responsible for turning high-level objectives-like "implement zero trust for workforce access" or "deploy phishing-resistant MFA at scale"-into concrete designs, automation, and measurable risk reduction. In this role, you will: **Engineer modern identity and access controls** - Define security requirements and prototype controls for workforce identity (e.g., Okta/Entra), including SSO, MFA, conditional access, and SCIM; validate controls with IT, which owns deployment and operations. - Define phishing-resistant MFA requirements for high-value accounts and critical access paths (e.g., FIDO2/WebAuthn, hardware keys); assess coverage and exceptions. Prove out technical efficacy through engineering efforts (eg, PoC, back end integrations, adversarial testing). - Define least-privilege RBAC/IAM patterns, including roles, entitlements, JIT access, and approvals; partner with IT to close gaps and automate privilege reduction and access revocation. **Implement zero trust for workforce and enterprise access** - Design and deploy controls that combine **user identity, device posture, network context, and application sensitivity** to enforce least-privilege access. - Partner with Network and Infrastructure teams to integrate mTLS, service identity, and policy-based access into internal services and admin interfaces. - Help transition from legacy perimeter models to **zero trust network access (ZTNA)** patterns for employees, contractors, and third parties. **Secure SaaS and collaboration platforms** - Evaluate, onboard, and harden SaaS applications (Google Workspace, Microsoft 365, Slack, HRIS, ticketing, and other business apps) to align with enterprise security policies. - Implement and tune controls such as SCIM provisioning, data access policies, DLP, sharing controls, and audit logging across the SaaS estate. - Partner with business and IT owners to ensure new SaaS applications meet baseline security standards before adoption. **Harden endpoints and the extended workforce** - Collaborate with Endpoint/IT teams to define and enforce baseline configurations for laptops, workstations, and other managed devices via MDM and EDR. - Design secure patterns for contractor and vendor access, including device requirements, identity separation, and time-bound access. - Support investigations and incident response related to identity, endpoint, and SaaS domains. **Automate and instrument everything you can** - Build automation and self-service experiences for access requests, approvals, access reviews, and break-glass workflows. - Develop integrations between IdPs, HRIS, ticketing, and other systems to minimize manual toil and reduce identity-related error rates. - Define and instrument metrics for enterprise security (e.g., MFA coverage, zero trust policy enforcement, joiner/mover/leaver SLA adherence, SaaS posture). **Partner on detection, response, and governance** - Work with Security Operations and SIEM teams to ensure robust visibility into identity, device, and SaaS activity, and to build high-signal detections. - Contribute to policies, standards, and reference architectures that encode enterprise security expectations. - Author clear documentation and runbooks that make it easy for teams to consume and operate the controls you build. ### Who You Are: ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Stack Overflow: Community and AI](https://www.wearedevelopers.com/videos/600-stack-overflow-community-and-ai) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Leading Through Stagility: Human Capital Trends That Redefine Work](https://www.wearedevelopers.com/videos/1717-leading-through-stagility-human-capital-trends-that-redefine-work) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)