← Back to job listings
BE
Enterprise Security Engineer
Benchling · United States
About The Role
Join Benchling as an Enterprise Security Engineer, where you'll be part of a team dedicated to building a top-tier security program. Your responsibilities will include driving the organization's zero trust strategy, designing and maintaining access controls, deploying and maintaining MDM infrastructure, enforcing security standards, and reducing manual toil through automation. You should have at least 5 years of experience in a security engineering or IAM-focused role, proficiency in managing macOS endpoints, and a strong understanding of operating systems fundamentals.
- Conduire la stratégie de l'organisation en matière de zéro confiance de manière globale, en intégrant en continu l'identité, la santé des appareils, le contexte du réseau et la sensibilité des applications dans les décisions d'accès.
- Concevoir et maintenir des modèles d'accès à privilèges minimaux, un accès juste à temps (JIT) et des contrôles de gestion des accès privilégiés (PAM).
- Déployer, configurer et maintenir l'infrastructure MDM pour la flotte macOS, en veillant à ce que la conformité des appareils alimente directement les décisions de politique d'accès en matière de zéro confiance.
- Proficiency managing macOS endpoints at scale using Fleet or an equivalent MDM platform
- Deep, hands-on IdP expertise (preferably Okta) — SSO, SCIM, MFA, Lifecycle Management, and NHI management are all areas you can speak to with depth and demonstrate in practice
- Scripting proficiency in in at least one language, preferably Python
- Demonstrated experience implementing zero trust architecture in practice — not just familiarity with the framework, but hands-on delivery of continuous verification, device trust integration, and least-privilege enforcement across an organization
- 5+ years in a security engineering or IAM-focused role
- Excellent communication skills, with the ability to engage effectively with both technical teams and non-technical stakeholders
- Strong understanding of operating systems fundamentals (MacOS/Linux/Windows)
- Foundational cloud IAM experience across at least one major provider (AWS, GCP, or Azure) — enough to audit, scope, and remediate identity issues
- Strong working knowledge of identity protocols: SAML, OIDC, OAuth 2.0, and SCIM
- Demonstrated track record of building automation that eliminated recurring manual work
- Experience with ZTNA platforms (Cloudflare Access, Zscaler Private Access, Tailscale, or similar) and the operational patterns around replacing VPN with identity-aware access
- Experience governing AI/ML service identities or securing LLM API integrations
- Hands-on use of AI coding assistants (Copilot, Claude, Cursor, or similar) to increase velocity
- Familiarity with PAM solutions such as HashiCorp Vault, AWS Secrets Manager, or Okta Privileged Access
- Okta Certified Administrator, Okta Certified Consultant, or equivalent certification
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring