TRM Labs logo
TRM LabsPosted 4 weeks ago

Enterprise Security Engineer

$180,000–$200,000 year

RemoteUnited States

Full TimeSmall

Job Summary

Engineer secure-by-default endpoint baselines for macOS and Windows, including encryption, firewall, application controls, and device compliance. Automate and scale identity and access controls in Microsoft Entra ID and Google Workspace, codifying security controls as code using Terraform and configuration profiles. Build automations and integrations that reduce manual access grants and accelerate control changes. Harden SaaS platforms by enforcing strong authentication, least privilege, and data protection guardrails. Improve visibility and detection by integrating logging from endpoints and identity providers into Microsoft Defender and Sentinel. Drive vulnerability and configuration drift reduction through remediation pipelines and reporting. Partner with Compliance and Risk stakeholders to produce evidence and document controls. Participate in a one-week-on, every-three-weeks on-call rotation supporting identity, endpoint security, and critical enterprise systems.

Required Qualifications

  • Demonstrated experience engineering and scaling endpoint management platforms (such as Microsoft Intune) and endpoint security controls for macOS and Windows
  • Strong identity and access management (IAM) foundation with hands-on experience administering Microsoft Entra ID (Conditional Access, SSO, Access Governance) and Google Workspace and/or Microsoft 365
  • Proven ability to automate operational workflows using scripting languages such as Bash, PowerShell, or Python
  • Fluency with AI-assisted engineering
  • Strong troubleshooting and systems-thinking skills across identity, endpoints, networking, security controls, and SaaS integrations
  • Ability to balance security and usability using a risk-based approach and clearly communicate tradeoffs to both technical and non-technical stakeholders
  • Priorities and targets to change quickly as we experiment and iterate
  • Work that often requires operating with a high degree of ambiguity
  • A high level of personal ownership and accountability
  • Close collaboration across teams and functions
  • Frequent, high-touch communication
  • Creative problem solving and out-of-the-box thinking
  • A pace that rewards urgency, adaptability, and outcomes
  • Comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment
  • Excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues
  • AI fluency
  • Accelerate repeatable workflows
  • Structure and solve problems
  • Improve output quality
  • Increase speed and leverage
  • Impact-Oriented Trailblazer
  • Master Craftsperson
  • Inspiring Colleague

Desired Qualifications

  • Experience managing infrastructure-as-code or configuration-as-code, preferably Terraform, with familiarity in policy-as-code and configuration profiles
  • Security incident response and countermeasure experience
  • Security Operations Center (SOC) experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce