You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Early Window: Be the first to open itNo views yetCloses in
Company hidden

Paranoids Endpoint Security Engineer

  • Hybrid
  • 3-6 years

Salary

$110,000+/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

The company serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, the company Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

A Little About Us

The company reaches hundreds of millions of people every day, and that scale makes us a constant target for attackers of every kind, at every layer of our systems. Our job is to protect our users and make the company one of the safest places on the Internet. We are the information security team at the company, known as The Paranoids.

Within Cyber Resilience, our team is responsible for the security of the laptops and browsers the company employees use every day, and we’re growing the team to take that program further.

A Lot About You

We’re looking for someone who wants to own a security program end to end. You’ll lead the rollout of a new browser security platform, running the proof of concept with our device management partners and carrying it through to full production.

From there, you’ll become our source of truth for endpoint security: owning the program in steady state, building the policies the platform runs on, and taking on each new milestone as our endpoint hardening roadmap grows. You’ll build relationships across teams to get security work prioritized and delivered, make pragmatic calls that balance security with how people actually get work done, and stay curious about the browser and endpoint threat landscape with a bias toward fixing root causes.

Building and tuning the policies our browser security platform runs on, and partnering with our device management team to move a rollout from pilot devices to the full fleet

Automating and refining how we review and score browser extension requests, using AI tools to make that process automated over time

Reviewing and validating AI-generated policy logic, scripts, and rule changes before deployment, to make sure the output is accurate and doesn’t introduce a policy bypass

Partnering with identity, legal, and communications teams to take the next milestone on our security roadmap from design to launch

Triaging exceptions from employees and business stakeholders, and updating the underlying policy so the same issue doesn’t keep coming back as a one-off request

Reporting on fleet risk posture and program progress to security leadership

AI-Augmented Automating: Develop and refine AI-assisted workflows using enterprise AI tools (e.g., Claude) to automate the review, risk-scoring, and triage of browser extension requests and endpoint policy exceptions.

Triage incoming requests for endpoint security related exceptions and reviews

Support team initiatives for Container Security and Cloud Security

This role is what you make of it. Our endpoint hardening program has a multi-year roadmap ahead of it, and you will have real ownership over how it evolves and where it goes next.

Basic Qualifications

Bachelor’s degree in a technical discipline (i.e., Computer Science, Engineering, Information Security) or equivalent practical experience.

Direct experience with one or more enterprise browser security or zero-trust access platforms, such as LayerX, Spin.AI, Island, Talon, NordLayer, or similar

4+ years of experience in information security, specifically within endpoint security or security engineering.

Hands-on experience hardening and managing macOS and Windows endpoints at enterprise scale, with an emphasis on security best practices and policy requirements, using MDM platforms such as Jamf or InTune, and administering browser policy through consoles like Google Workspace or Chrome Enterprise

Working knowledge of how browser extensions actually work, including manifest permissions and content scripts, and how the security model differs across Chrome, Firefox, Safari, and Edge

Experience with enterprise identity providers such as Okta or SAML, and how they intersect with device and browser management

Experience defining and enforcing policies for removable media and data transfer paths, including USB device control, to reduce unauthorized data movement.

Experience with endpoint or browser-based data loss prevention: what it can and cannot catch, and how to tune policy without breaking legitimate work

Strong communication skills, with the ability to work through security tradeoffs with engineers and non-technical stakeholders alike

Experience using enterprise AI tools such as Claude to automate repetitive work and speed up investigations

Practical experience utilizing enterprise AI platforms (e.g., Claude, Gemini) for structured prompting, log analysis, policy generation, or administrative workflow automation.

Preferred Qualifications

A certification specific to endpoint or device management, such as Jamf Certified Admin, Microsoft Certified: Endpoint Administrator Associate, or GIAC GCWN (Certified Windows Security Administrator), or equivalent hands-on experience

Comfort working with large-scale data platforms such as Databricks or similar to build reporting and track program metrics

Experience with cloud based security infrastructure, with prior experience working in both AWS and GCP

Familiarity with container security, kubernetes and how the container lifecycle works

Demonstrated experience engineering prompts or scripting automated workflows that integrate AI capabilities into security operation pipelines.

The material job duties and responsibilities of this role include those listed above as well as adhering to the company policies ; exercising sound judgment ; working effectively, safely and inclusively with others ; exhibiting trustworthiness and meeting expectations ; and safeguarding business operations and brand integrity.

At the company, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a the company office or facility. If you have any questions about how this applies to the role, just ask the recruiter!

We believe that a diverse and inclusive workplace strengthens the company and deepens our relationships. When you support everyone to be their best selves, they spark discovery, innovation and creativity. Among other efforts, our 11 employee resource groups (ERGs) enhance a culture of belonging with programs, events and fellowship that help educate, support and create a workplace where all feel welcome.

The compensation for this position ranges from $111,000.00 - $231,250.00/yr and will vary depending on factors such as your location, skills and experience.The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions. Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.

Currently work for the company? Please apply on our internal career site.

Where you’d work

Part of the week in the office

You can work from

  • United States

About the company

Company hidden

Office in United States

Your chances

Still hiring, not crowded yet, and you'd be among the first.

  • 18 checks run
  • 7 good signs
  • 1 red flag

Still hiring?

12 checks

Actively hiring

In its favour5

  • Still on the company's own careers site, checked 1 h agoModerate evidence
  • Found in the last 48 hours, before the big job boardsModerate evidence
  • The company posted 10 roles in the last 2 weeksSlight evidence
2 moreFewer
  • Specific about the basics: pay, place, level, stack and contract all statedSlight evidence
  • States its salary: $110K+Slight evidence

Against it1

  • Pays less than 97% of similar roles we trackSlight evidence

How crowded?

6 checks

Low

In its favour2

  • In its Early Window: not on the big job boards yetStrong evidence
  • Pays below most similar roles, which thins the crowdSlight evidence

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details11 facts · Role, Location, Compensation, Employment
Tech stack
  • AWS
  • Kubernetes
Type
Full-time
Specialty
Security
Region
United States
Pay period
Annual
Show 6 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Experience
4+ years
Tech stack
  • AWS
  • Kubernetes

Location

Work model
Hybrid
Region
United States
Office
  • United States
Remote from
  • United States

Compensation

Salary
$110,000+ / year
Pay period
Annual

Employment

Type
Full-time

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason