Enterprise Security Engineer

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Enterprise Security Engineer at Benchling focusing on building a security program and implementing zero trust strategies for sensitive data protection.

Responsibilities:

  • Drive the organization's zero trust strategy end to end
  • Design and maintain least-privilege access patterns, Just-in-Time (JIT) access, and Privileged Access Management (PAM) controls
  • Deploy, configure, and maintain MDM infrastructure for the macOS fleet
  • Enforce SSO-required policies, review and restrict OAuth scopes, and audit third-party integration access
  • Build processes and tooling to detect shadow IT and unauthorized OAuth app grants
  • Evaluate and deploy AI-native security tooling
  • Define and enforce security standards for AI agent and LLM service identities
  • Develop and enforce CIS/NIST-aligned configuration baselines
  • Meaningfully reduce manual toil through automation

Requirements:

  • 5+ years in a security engineering or IAM-focused role
  • Deep, hands-on IdP expertise (preferably Okta) — SSO, SCIM, MFA, Lifecycle Management, and NHI management
  • Demonstrated experience implementing zero trust architecture in practice
  • Strong working knowledge of identity protocols: SAML, OIDC, OAuth 2.0, and SCIM
  • Proficiency managing macOS endpoints at scale using Fleet or an equivalent MDM platform
  • Foundational cloud IAM experience across at least one major provider (AWS, GCP, or Azure)
  • Demonstrated track record of building automation that eliminated recurring manual work
  • Scripting proficiency in at least one language, preferably Python
  • Excellent communication skills.

Benefits:

  • Full-time U.S. employees enjoy a comprehensive benefits program including equity, health, dental, vision, 401(k)+ employer match, wellness, commuter, and more.