- Company Name
- Obsidian Security
- Job Title
- Staff Security Engineer - Corporate Security
- Job Description
-
**Job Title:** Staff Security Engineer - Corporate Security
**Role Summary**
Lead corporate security engineering initiatives to optimize, automate, and mature security controls across cloud-native environments. Focus on enterprise SaaS platforms, endpoint management, and identity access systems to protect critical infrastructure and operational continuity in a high-growth startup.
**Expectations**
Demonstrate technical ownership, cross-functional collaboration, and initiative to drive security excellence. Deliver scalable, zero-trust-aligned solutions while supporting governance, risk management, and compliance (GRC) frameworks. Thrive in a dynamic startup with evolving security demands.
**Key Responsibilities**
- Design, implement, and automate security controls for corporate IT systems (Google Workspace, Microsoft 365, Salesforce, etc.).
- Operate and integrate security tools (SIEM, EDR, CNAPP, MDM, EPM, firewall) to monitor, detect, and respond to incidents.
- Enforce hardening standards for endpoints, IAM/PAM systems, and password/secrets management.
- Develop automated workflows for incident detection, response, and vulnerability management.
- Support red teaming, penetration testing, and security documentation/playbook development.
- Maturing access reviews, third-party risk assessments, and security awareness programs.
- Drive compliance with SOC 2, ISO 27001, and internal audit requirements.
- Advise on secure network design and zero-trust architecture across hybrid/cloud environments.
**Required Skills**
- Advanced proficiency in cloud security (Azure, AWS), SIEM (Splunk, QRadar), and CNAPP tooling.
- Expertise in incident response, threat modeling, and SOC operations.
- Strong coding/scripting skills (Python, PowerShell, YAML) for automation workflows.
- Deep understanding of IAM/PAM, endpoint hardening, and secure software development practices.
- Experience with GRC frameworks (SOC 2, ISO 27001, CSA STAR) and audit processes.
- Familiarity with enterprise SaaS security, CNAPP, and secure DevOps toolchains.
**Required Education & Certifications**
- Bachelor’s degree in cybersecurity, computer science, or related field.
- Certifications: CISSP, CISM, CEH, or GSEC preferred.
- 8+ years of enterprise cybersecurity engineering or operational security (SecOps) experience.