Staff Corporate Security Engineer
$210k - $255k • San Francisco, CA - US • FullTime
Posted 4mo ago
Job Location
San Francisco, CA - US
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Crusoe is seeking a Staff Corporate Security Engineer to serve as the principal architect for our corporate security posture. This role involves moving beyond tactical tool management to design high-assurance, preventative systems that safeguard our identity perimeter, global network, and SaaS ecosystem. As a senior technical leader, you will build a "Secure by Default" environment where security is seamlessly embedded into the employee experience, ensuring our AI-first cloud infrastructure is protected.
Responsibilities
- Lead the design and implementation of Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) architectures.
- Architect preventative SaaS security across platforms like Google Workspace, Slack, and Okta, including CASB controls.
- Implement Binary Authorization and device trust mechanisms using hardware-backed identity.
- Design and tune Data Loss Prevention (DLP) controls across endpoints and SaaS platforms.
- Strengthen email security posture, including MFA enforcement and session controls.
- Architect AI-native security frameworks, including governance and secure gateways for agent-based systems.
- Scale identity and access management systems, including SSO, SAML, OAuth, SCIM, and design Just-In-Time (JIT) access workflows.
- Define and execute a "Crown Jewels" security methodology to identify and remediate high-risk vulnerabilities.
Requirements
- 8+ years of experience designing and implementing Zero Trust, SASE, and modern identity-based security architectures.
- Strong expertise in SaaS security, including CASB, DLP, and governance across platforms like Google Workspace, Okta, and Slack.
- Experience implementing device trust, endpoint security, and hardware-backed identity solutions.
- Strong understanding of identity and access management systems (SSO, SAML 2.0, OAuth, SCIM) and secure access patterns.
- Knowledge of email security, phishing mitigation, and session security controls.
- Experience identifying and mitigating application-layer vulnerabilities such as IDOR and privilege escalation risks.
- Familiarity with emerging AI security challenges, including governance of agent-based systems and secure orchestration patterns.
- Strong architectural mindset with the ability to design preventative, scalable security systems.
- Excellent communication skills and ability to influence security decisions.
Benefits
- Competitive compensation and equity packages
- Restricted Stock Units
- Paid time off, paid holidays & leave of absence programs
- Comprehensive health, dental & vision insurance
- Employer contributions to HSA account
- Paid parental leave
- Paid life insurance, short-term and long-term disability
- Professional development & tuition reimbursement
- Mental health & wellness support
- Commuter benefits (parking & transit)
- Cell phone stipend
- 401(k) Retirement plan with company match up to 4% of salary
- Volunteer time off
- Global travel insurance & emergency assistance
- Daily meals allowance
- Additional perks & programs specific to location