Senior Security Engineer - Enterprise Security
Remote • Bellevue Office • FullTime
Posted 17h ago
About the job
Lambda is seeking a Senior Security Engineer to join its Enterprise Security team. This role is crucial for protecting Lambda's valuable digital assets, including AI training data, model weights, and sensitive inputs. You will be responsible for securing SaaS applications, corporate IT infrastructure, identity and access management (IAM), and endpoint ecosystems. The position focuses on establishing secure configurations, automating access governance, and protecting corporate environments during rapid scaling. You will implement robust Identity Governance and Administration (IGA), harden SaaS tools, automate joiner-mover-leaver (JML) workflows, and deploy zero-trust network access controls. A key aspect of this role involves pioneering AI-driven enterprise security automation using Lambda's hosted LLMs, such as intelligent access reviews and automated policy enforcement.
Responsibilities
- Design, deploy, and maintain Identity and Access Management (IAM) architectures, SSO/IdP integrations (Okta, Entra ID), and Privileged Access Management (PAM).
- Automate Joiner-Mover-Leaver (JML) workflows and lifecycle management to enforce least-privilege access and zero-trust principles.
- Build automated access certification and review tooling for compliance and governance.
- Implement strong multi-factor authentication (MFA) standards, passwordless solutions, and contextual access policies.
- Establish SaaS Security Posture Management (SSPM) and conduct security posture reviews for corporate SaaS applications (Google Workspace, Slack, GitHub, Jira, Salesforce).
- Define and enforce baseline security configurations, patch management policies, and MDM/EDR security controls across corporate endpoints.
- Partner with IT Infrastructure and Operations teams to architect Zero Trust Network Access (ZTNA), VPN/SASE solutions, and secure remote worker access.
- Develop custom security automation tools and scripts in Python or Go.
- Pioneer AI-powered enterprise security workflows leveraging LLMs for third-party risk analysis, access request approvals, and anomaly detection.
- Assess third-party vendor risks and build automated tooling to evaluate SaaS vendor security postures.
- Collaborate with IT, Legal, HR, and Compliance teams to ensure corporate systems align with frameworks like SOC 2, ISO 27001, and HIPAA.
- Establish internal security documentation, end-user security awareness guidelines, and self-service security options.
- Define strategic roadmap initiatives for corporate security and drive measurable security posture improvements.
Requirements
- 5+ years of dedicated security engineering experience, focusing on enterprise security, corporate security, or IAM infrastructure.
- Proven experience designing and scaling Identity & Access Management architectures (e.g., Okta, Entra ID, SAML/OIDC, SCIM, PAM).
- Hands-on technical expertise in securing corporate SaaS applications and managing SaaS Security Posture Management (SSPM) tools.
- Strong programming and scripting capabilities (Python, Go, or PowerShell) for automation.
- Solid understanding of Zero Trust architecture, Endpoint Detection & Response (EDR), Mobile Device Management (MDM), and corporate network security.
- Strong communication and stakeholder management skills.
- Ability to balance robust enterprise security controls with employee experience and productivity.
- Experience in fast-moving, high-growth startup environments.
- Familiarity with compliance frameworks (SOC 2, ISO 27001, FedRAMP, HIPAA) and audit preparation.
- Experience implementing Infrastructure as Code (Terraform) for managing enterprise identity and SaaS configurations.