{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/sharing-controls"},"x-facet":{"type":"skill","slug":"sharing-controls","display":"Sharing Controls","count":1},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_a585fcb5-07b"},"title":"Senior Security Engineer, Enterprise Security","description":"<p>As a Senior Security Engineer, Enterprise Security, you will design and ship the security controls that underpin CoreWeave&#39;s workforce and enterprise stack. You will lead initiatives across identity, access management, device and endpoint security, and SaaS security,partnering closely with IT Engineering, Endpoint, Network, and other security teams.</p>\n<p>Your day-to-day will blend hands-on engineering (writing code, building integrations, tuning controls) with architecture and program ownership (setting standards, defining patterns, and driving adoption across teams). You will be responsible for turning high-level objectives,like “implement zero trust for workforce access” or “deploy phishing-resistant MFA at scale”,into concrete designs, automation, and measurable risk reduction.</p>\n<p>In this role, you will:</p>\n<ul>\n<li>Engineer modern identity and access controls</li>\n<li>Design, implement, and operate workforce identity solutions (e.g., Okta/Entra and other IdPs) including SSO, MFA, conditional access, and lifecycle automation via SCIM.</li>\n<li>Develop and roll out phishing-resistant MFA for high-value accounts and critical access paths (e.g., FIDO2/WebAuthn, hardware keys, device-bound authenticators).</li>\n<li>Define and maintain RBAC/IAM patterns for enterprise applications (role models, groups, entitlements, JIT access, and approvals).</li>\n</ul>\n<ul>\n<li>Implement zero trust for workforce and enterprise access</li>\n<li>Design and deploy controls that combine user identity, device posture, network context, and application sensitivity to enforce least-privilege access.</li>\n<li>Partner with Network and Infrastructure teams to integrate mTLS, service identity, and policy-based access into internal services and admin interfaces.</li>\n<li>Help transition from legacy perimeter models to zero trust network access (ZTNA) patterns for employees, contractors, and third parties.</li>\n</ul>\n<ul>\n<li>Secure SaaS and collaboration platforms</li>\n<li>Evaluate, onboard, and harden SaaS applications (Google Workspace, Microsoft 365, Slack, HRIS, ticketing, and other business apps) to align with enterprise security policies.</li>\n<li>Implement and tune controls such as SCIM provisioning, data access policies, DLP, sharing controls, and audit logging across the SaaS estate.</li>\n<li>Partner with business and IT owners to ensure new SaaS applications meet baseline security standards before adoption.</li>\n</ul>\n<ul>\n<li>Harden endpoints and the extended workforce</li>\n<li>Collaborate with Endpoint/IT teams to define and enforce baseline configurations for laptops, workstations, and other managed devices via MDM and EDR.</li>\n<li>Design secure patterns for contractor and vendor access, including device requirements, identity separation, and time-bound access.</li>\n<li>Support investigations and incident response related to identity, endpoint, and SaaS domains.</li>\n</ul>\n<ul>\n<li>Automate and instrument everything you can</li>\n<li>Build automation and self-service experiences for access requests, approvals, access reviews, and break-glass workflows.</li>\n<li>Develop integrations between IdPs, HRIS, ticketing, and other systems to minimize manual toil and reduce identity-related error rates.</li>\n<li>Define and instrument metrics for enterprise security (e.g., MFA coverage, zero trust policy enforcement, joiner/mover/leaver SLA adherence, SaaS posture).</li>\n</ul>\n<ul>\n<li>Partner on detection, response, and governance</li>\n<li>Work with Security Operations and SIEM teams to ensure robust visibility into identity, device, and SaaS activity, and to build high-signal detections.</li>\n<li>Contribute to policies, standards, and reference architectures that encode enterprise security expectations.</li>\n<li>Author clear documentation and runbooks that make it easy for teams to consume and operate the controls you build.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_a585fcb5-07b","directApply":true,"hiringOrganization":{"@type":"Organization","name":"CoreWeave","sameAs":"https://www.coreweave.com","logo":"https://logos.yubhub.co/coreweave.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coreweave/jobs/4653764006","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Identity and Access Management","Security Engineering","Zero Trust Architecture","Phishing-Resistant MFA","RBAC/IAM Patterns","SCIM Provisioning","Data Access Policies","DLP","Sharing Controls","Audit Logging","Endpoint Security","MDM","EDR","Automation","Self-Service Experiences","Integrations","Metrics","Enterprise Security","Security Operations","SIEM","Policies","Standards","Reference Architectures"],"x-skills-preferred":["Cloud Computing","AI Applications","Containerization","Kubernetes","DevOps","CI/CD Pipelines","Agile Methodologies","Scrum","Kanban","Project Management","Leadership","Communication","Collaboration"],"datePosted":"2026-04-18T15:49:47.000Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York, NY / Sunnyvale, CA / Bellevue, WA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Identity and Access Management, Security Engineering, Zero Trust Architecture, Phishing-Resistant MFA, RBAC/IAM Patterns, SCIM Provisioning, Data Access Policies, DLP, Sharing Controls, Audit Logging, Endpoint Security, MDM, EDR, Automation, Self-Service Experiences, Integrations, Metrics, Enterprise Security, Security Operations, SIEM, Policies, Standards, Reference Architectures, Cloud Computing, AI Applications, Containerization, Kubernetes, DevOps, CI/CD Pipelines, Agile Methodologies, Scrum, Kanban, Project Management, Leadership, Communication, Collaboration"}]}