Enterprise Security Engineer
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Enterprise Security Engineer at Benchling focusing on building a security program and implementing zero trust strategies for sensitive data protection.
Responsibilities:
- Drive the organization's zero trust strategy end to end
- Design and maintain least-privilege access patterns, Just-in-Time (JIT) access, and Privileged Access Management (PAM) controls
- Deploy, configure, and maintain MDM infrastructure for the macOS fleet
- Enforce SSO-required policies, review and restrict OAuth scopes, and audit third-party integration access
- Build processes and tooling to detect shadow IT and unauthorized OAuth app grants
- Evaluate and deploy AI-native security tooling
- Define and enforce security standards for AI agent and LLM service identities
- Develop and enforce CIS/NIST-aligned configuration baselines
- Meaningfully reduce manual toil through automation
Requirements:
- 5+ years in a security engineering or IAM-focused role
- Deep, hands-on IdP expertise (preferably Okta) — SSO, SCIM, MFA, Lifecycle Management, and NHI management
- Demonstrated experience implementing zero trust architecture in practice
- Strong working knowledge of identity protocols: SAML, OIDC, OAuth 2.0, and SCIM
- Proficiency managing macOS endpoints at scale using Fleet or an equivalent MDM platform
- Foundational cloud IAM experience across at least one major provider (AWS, GCP, or Azure)
- Demonstrated track record of building automation that eliminated recurring manual work
- Scripting proficiency in at least one language, preferably Python
- Excellent communication skills.
Benefits:
- Full-time U.S. employees enjoy a comprehensive benefits program including equity, health, dental, vision, 401(k)+ employer match, wellness, commuter, and more.




















