Skip to content
← Back to job listings

Senior Security Engineer (Corporate Information Security)

Betterment · New York, United States

External listingfull-timeabout 2 months ago

About The Role

Join Betterment, a leading digital investment platform, as a Senior Security Engineer in Corporate Information Security. In this hands-on role, you will design, implement, and continuously improve identity architecture, privileged access controls, endpoint hardening standards, and overall workforce security posture. You will work closely with other security teams, IT, legal, compliance, and business units to embed secure access patterns across various environments. Additionally, you will partner with the AI Governance & enablement team to evaluate, enable, and secure the use of AI tools.

  • Design, implement, and continuously improve identity architecture, privileged access controls, endpoint hardening standards, and overall workforce security posture.
  • Define and evolve the workforce IAM roadmap, architect identity patterns across Okta and SaaS estate SSO at scale, and build a sustainable Identity Governance & Administration (IGA) practice.
  • Lead initiatives across authentication, authorization, federation, and privileged access, and govern non-human identities, service accounts, API tokens, OAuth integrations, and AI agents.
  • Communication: Strong writing — RFCs, one-pagers, audit narratives — and the cross-functional patience to bring stakeholders along
  • Endpoint, mobile & browser: Familiarity with endpoint management and EDR; an opinion on operationalizing CIS benchmarks across macOS and Windows without crushing the user experience; comfort extending security to mobile and managed browser surfaces
  • Experience: 6+ years in security engineering with deep experience in IAM and corporate security, ideally with time in a regulated environment
  • Compliance posture: Comfort operating in SOC 2 and ISO 27001/NIST environments, balancing risk reduction with business enablement
  • Enterprise network: Experience with network monitoring & alerting, perimeter blocking, intelligence gathering/sharing, and other network related security controls (ZTNA); building/testing ACLs, firewall rules, cryptography, VPNs and tunneling/encapsulation
  • IAM depth: Strong command of authentication and authorization protocols (SAML, OIDC, OAuth, SCIM, LDAP), enterprise IAM platforms (Okta and Entra ID), RBAC design, and lifecycle automation. Comfortable with Identity Center / SSO patterns at scale and PIM-equivalent / break-glass models for privileged access
  • Vulnerability & posture: Experience designing remediation SLAs, running remediation campaigns to actual closure, and operating SaaS posture tooling (Wiz, Vanta, Drata, or peers)
  • AI fluency: Curiosity for AI tools and workflows; an instinct for enabling responsibly rather than reflexively blocking
  • Automation mindset: Comfortable building tools and pipelines, not just configuring them; Python, Go, or similar with a track record of automation that survives the person who built it
  • Security certifications such as CISSP or vendor IAM certifications
  • Experience partnering with an MDR / managed SOC and shaping their detection content
  • Working knowledge of policy-as-code (OPA / Rego) or similar
  • Real-world Zero Trust implementation experience, not as a slide
  • Hands-on experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea), Identity Governance & Administration (Saviynt, SailPoint, ConductorOne, Lumos), or modern secrets management (HashiCorp Vault, Doppler)

This is an external listing. JobSpring does not represent or verify the employer. Report this listing