Skip to main content
Box

Enterprise Application Security Engineer II

RemoteUnited States only
Published
Role
Security
Experience
Mid
Company size
Enterprise
$113.5k–$121.3k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Application security engineer with 3+ years in enterprise, app, cloud, or security engineering. Must know IAM, OAuth/OIDC/SAML, API security, secrets management, SaaS integrations, security tooling, and scripting/automation. US remote; no relocation assistance.

Core skills

IAMApplication SecuritySaaS integrations

Required skills

OAuth/OIDC/SAMLAPI securitysecrets managementSalesforce/WorkdayEDRDLPemail securityWAFvulnerability managementSIEMSplunk/Elastic/SentinelAWS/GCP/AzurePython/PowerShell/GoREST APIsinfrastructure-as-code

What you'll do

  • Design, implement, and maintain security controls that protect Box's enterprise applications, corporate infrastructure, and cloud services.
  • Partner with IT, Enterprise Engineering, and business application owners to securely deploy, configure, and operate enterprise platforms, AI and SaaS applications.
  • Perform security assessments and architecture reviews for new enterprise applications, integrations, and third-party vendors, recommending mitigations aligned with security best practices.
  • Build and maintain security monitoring, dashboards, and automation to improve visibility into enterprise application risk, identity, and access.
  • Develop and automate security controls for enterprise platforms, including identity, secrets management, privileged access, and application integrations.
  • Support vulnerability management, incident response, and remediation efforts by identifying security gaps and driving risk reduction across the enterprise environment.

What they require

  • We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.
  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • 3+ years of experience in enterprise security, application security, cloud security, or security engineering.
  • Strong understanding of application security principles, including authentication and authorization, identity and access management (IAM), OAuth/OIDC/SAML, API security, secrets management, and secure application integrations.
  • Hands-on experience securing enterprise application integrations across SaaS platforms such as Salesforce, Workday, or similar enterprise technologies.
  • Experience with security technologies including EDR, DLP, email security, WAFs, vulnerability management, SIEM platforms (Splunk, Elastic, Sentinel, etc.), and cloud security services across AWS, GCP, and/or Azure.
  • Experience with scripting or automation using Python, PowerShell, Go, or similar languages, and familiarity with REST APIs and infrastructure-as-code.
  • Strong communication and collaboration skills
  • Familiarity with AI tools and services.
  • Based on current business needs, there is no relocation assistance provided for this role.

Benefits

  • This role is also eligible for equity and benefits.
  • For more information, check out our benefits and perks.

Box

Box is a leading Intelligent Content Management platform company that helps enterprises collaborate, manage the content lifecycle, protect important content, and transform workflows with enterprise AI.

🇺🇸 United StatesEnterprise SoftwareEnterprise
$113.5k–$121.3k/yr