Skip to main content
TRM Labs
TRM Labs

Enterprise Security Engineer

RemoteUnited States only
Published
Role
Fullstack
Employment
Full-time
$180k–$200k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

We're looking for an Enterprise Security Engineer to help harden and scale our corporate environment.

Core skills

Microsoft IntuneMicrosoft Entra IDGoogle Workspace

Required skills

macOSWindowsMicrosoft 365BashPowerShellPythonTerraformn8nClaude CodeMCPMicrosoft DefenderMicrosoft SentinelEndpoint management/Identity and access management/Automation/AI-assisted engineering

Optional skills

Experience managing infrastructure-as-code or configuration-as-code, preferably Terraform, with familiarity in policy-as-code and configuration profiles.Security incident response and countermeasure experience.Security Operations Center (SOC) experience.Experience securing or governing enterprise AI adoption, including AI usage policies, DLP for AI tools, and agent/MCP access governance.

Required languages

English unknown

What you'll do

  • Engineer secure-by-default endpoint baselines for macOS and Windows, including encryption, firewall, application controls, device compliance, and configuration standards.
  • Automate and scale identity and access controls in Microsoft Entra ID and Google Workspace, including SSO, SCIM, Conditional Access, privileged access workflows, access reviews, and joiner/mover/leaver processes.
  • Codify security controls as code using Terraform, configuration profiles, and policy-as-code, with peer review, testing, rollback capabilities, change history, and measurable outcomes.
  • Build and maintain automations and integrations (e.g., n8n, SlackOps, APIs, and scripts) that reduce manual access grants, accelerate control changes, and eliminate repetitive workflows.
  • Apply AI tooling (Claude Code, agentic workflows, MCP integrations, and LLM-backed automations) to accelerate engineering and triage work while helping secure how the rest of the company uses AI through sanctioned tooling, data handling guardrails, and visibility into shadow AI.
  • Harden SaaS and collaboration platforms by reducing unmanaged applications and enforcing strong authentication, least privilege, sharing controls, and data protection guardrails.
  • Improve visibility and detection by ensuring logging from endpoints, identity providers, and key SaaS applications is integrated into Microsoft Defender, Microsoft Sentinel, and other relevant security platforms.
  • Drive vulnerability and configuration drift reduction through remediation pipelines, automation, metrics, and reporting that leadership can act on.
  • Partner with Compliance and Risk stakeholders to produce evidence, document controls, and operationalize requirements without creating brittle or manual processes.
  • Participate in an approximately one-week-on, every-three-weeks on-call rotation supporting identity, endpoint security, and critical enterprise systems.

What they require

  • Demonstrated experience engineering and scaling endpoint management platforms (such as Microsoft Intune) and endpoint security controls for macOS and Windows.
  • Strong identity and access management (IAM) foundation with hands-on experience administering Microsoft Entra ID (Conditional Access, SSO, Access Governance) and Google Workspace and/or Microsoft 365.
  • Proven ability to automate operational workflows using scripting languages such as Bash, PowerShell, or Python.
  • Fluency with AI-assisted engineering. You already leverage coding agents and LLM tooling to build, review, troubleshoot, and investigate more effectively, while knowing when human verification is required.
  • Strong troubleshooting and systems-thinking skills across identity, endpoints, networking, security controls, and SaaS integrations.
  • Ability to balance security and usability using a risk-based approach and clearly communicate tradeoffs to both technical and non-technical stakeholders.

Benefits

  • Equity: This role is also eligible to participate in TRM's equity program.

Blockchain intelligence platform for investigating, monitoring, and detecting crypto fraud and financial crime

🇺🇸 United StatesAIMid-sizetrmlabs.com/
$180k–$200k/yr