Biotechnology is rewriting life as we know it, from the medicines we take, to the crops we grow, and the household goods that we rely on every day. But moving at the new speed of science requires better technology. Benchling’s mission is to unlock the power of biotechnology. The world’s most innovative biotech companies use Benchling’s R&D Cloud to power the development of breakthrough products. Help us bring modern software to modern science. We’re on Team Science We believe in the promise of science and the teamwork required to fulfill that promise. Whether your background is in science, engineering, business, or another field, you’re on Team Science if you believe in the power of science to solve the world’s most pressing problems.
Enterprise Security Engineer
Location
United States
Posted
17 days ago
Salary
$176K - $300K / year
Seniority
Senior
Job Description
Enterprise Security Engineer
Benchling
• Drive the organization's zero trust strategy end to end • Design and maintain least-privilege access patterns, Just-in-Time (JIT) access, and Privileged Access Management (PAM) controls • Deploy, configure, and maintain MDM infrastructure for the macOS fleet • Enforce SSO-required policies, review and restrict OAuth scopes, and audit third-party integration access • Build processes and tooling to detect shadow IT and unauthorized OAuth app grants • Evaluate and deploy AI-native security tooling • Define and enforce security standards for AI agent and LLM service identities • Develop and enforce CIS/NIST-aligned configuration baselines • Meaningfully reduce manual toil through automation
Job Requirements
- 5+ years in a security engineering or IAM-focused role
- Deep, hands-on IdP expertise (preferably Okta) — SSO, SCIM, MFA, Lifecycle Management, and NHI management
- Demonstrated experience implementing zero trust architecture in practice
- Strong working knowledge of identity protocols: SAML, OIDC, OAuth 2.0, and SCIM
- Proficiency managing macOS endpoints at scale using Fleet or an equivalent MDM platform
- Foundational cloud IAM experience across at least one major provider (AWS, GCP, or Azure)
- Demonstrated track record of building automation that eliminated recurring manual work
- Scripting proficiency in at least one language, preferably Python
- Excellent communication skills.
Benefits
- Full-time U.S. employees enjoy a comprehensive benefits program including equity, health, dental, vision, 401(k)+ employer match, wellness, commuter, and more.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Staff Security Researcher
BeyondTrustProtect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.
• Conduct original security research to identify emerging identity attack vectors and develop novel detection methodologies • Design and implement advanced analytics including rule-based systems, behavioral analysis, and machine learning models for threat detection • Expand and optimize our large-scale entitlement graph systems that map privilege escalation paths across customer environments • Develop proactive recommendation engines that identify security misconfigurations before they become attack vectors • Utilize graph theory to build entitlement paths from new areas of research across multiple domains • Integrate AI usage into engineering workflows to optimize efficiency • Design custom data representations (graphs, time-series, etc.) to support advanced analytical capabilities • Establish engineering best practices including comprehensive unit testing, automation, and CI/CD pipelines • Explore large-scale customer datasets using Spark and Databricks to validate detection hypotheses and uncover new threat patterns • Continuously monitor and tune detection algorithms based on real-world telemetry and performance metrics • Collaborate with data science teams to integrate machine learning models into production detection systems • Optimize system performance to handle massive data volumes efficiently • Provide technical leadership and mentorship to product and engineering teams • Present research findings at industry conferences and security forums • Publish technical blogs and research papers to establish thought leadership • Collaborate with cross-functional teams to translate research insights into product roadmap priorities
PNT Principal Investigator
ArcfieldThis is the projected compensation range for this position: Min: $152,483.71 Max: $265,139.59 We are an equal opportunity employer and federal government contractor. We do not discriminate against any employee or applicant for employment as protected by law.
Role Description This position is for Strategic Technology Consulting (STC), an Arcfield Company. STC is seeking a seasoned Tech Lead and Principal Investigator (PI) to lead the design, integration, and testing of innovative Alternative Assured Position, Navigation, and Timing (A2PNT) solutions. This role requires driving technical efforts, managing program milestones, and producing mission-ready capabilities that enable resilient PNT across diverse platforms, from maritime vessels to ground-based systems. - Program Leadership: Lead program planning, design reviews, and technical oversight of A2PNT solutions, ensuring alignment with operational needs and milestones. - Design and Integration: Lead efforts to architect, prototype, and implement A2PNT solutions emphasizing data fusion, decision logic pipelines, AI, and MOSA integration. - Testing and Validation: Oversee system integration, testing, and performance analysis, delivering prototypes and findings that inform operational decision-making. - Collaboration: Work closely with government stakeholders, mission engineers, and subcontractors to ensure seamless integration and technical excellence. Qualifications - BS 8-10, MS 6-8, PhD 3-5 (Bachelor’s degree in Systems Engineering, Aerospace Engineering, Electrical Engineering, or a related technical discipline) - Experience leading R&D programs as a PI, Project Manager, or Program Manager, demonstrating the ability to drive technical vision and execution. - Familiarity with embedded systems, including expertise in VPX, VITA90/VNX+ standards, product line engineering, and sensor fusion. - Knowledgeable about NAVWAR challenges and solutions. Familiarity with USMC mission sets. - 5+ years of relevant systems engineering experience, with demonstrated PNT integration exposure. - Proven track record in conducting lab and field demonstrations of complex HW/SW systems. - Experience integrating PNT technologies across diverse platforms (ground, air, maritime, space, or joint systems). - Demonstrated expertise in managing government relationships, with experience transitioning programs from the R&D phase to full production and scaling operational capabilities. - Strong analytical, problem-solving, and cross-functional communication skills. - Must be able to obtain and maintain a U.S. DoD Secret Security Clearance. - Ability to travel up to 25%. Requirements - Equal Pay Act: This is the projected compensation range for this position. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. - Min: $105,199.68 - Max: $206,990.49 Benefits - Health Insurance - Life Insurance - Paid Time Off - Holiday Pay - Short Term and Long-Term Disability - Retirement and Savings - Learning and Development opportunities - Wellness programs - Other optional benefit elections EEO Statement We are an equal opportunity employer and federal government contractor. We do not discriminate against any employee or applicant for employment as protected by law.
Product Marketing Manager, Security Products
ConnectWiseA platform of software & services built for TSPs. Follow us for product updates, company news, business advice and more.
• Sets an example for other GTM function members in all phases of planning and execution • Is a subject matter expert on security products to other GTM function members • Ensures policies, practices, and procedures are understood and followed by team members, partners, customers, and stakeholders • Develops unified product positioning and messaging that differentiates our products in the market • Develops and communicates ideal customer profiles and value propositions of our products as well as the tools that support the selling process • Oversees security product launches and releases while coordinating the cross-functional execution • Monitors internal processes for efficiency and validity pre- and post- product launch • Serves as a resource for customer-facing release webinars, analyst research and briefings, and other market-centric engagements • Understands the market landscape and works with the competitive intelligence team to drive actionable insights about opportunities and threats in the market • Assists with communications, marketing campaigns and sales programs to drive demand for products • Develops and manages the positioning and messaging for product expansion strategies • Engages in continuous improvement of team processes
Infrastructure Security Engineer
QuidaxProcess large volumes of crypto, build crypto products with our API & get your token listed on Africa's leading exchange
• Security Solutions Configuration, Review & Optimization • Within 30 days, the Infrastructure Security Engineer should be able to carry out configuration of various security solutions including network firewalls, Endpoint Detection & Response Solutions, Web Application Firewalls, Cloud Native Application Protection Platforms, Security Incident and Event Management, Security Orchestration Automation and Response Solutions, Identity Provider Solutions and Threat Management Solutions among others • Within 90 days, the Infrastructure Security Engineer should be able to carry out reviews & optimizations on various security solutions in compliance with the established policies • Within 180 days, the Infrastructure Security Engineer should review current security baselines & ensure alignment of all security and technology solutions with the security baselines across all environments (cloud, endpoints, network) • Audits & Compliance Reviews • Within 90 days, the Infrastructure Security Engineer should have adequate understanding of our existing infrastructure security systems and technical controls (how they work, effectiveness & gaps if any) to be able to provide insights during audits & compliance reviews • Within 180 days, the Infrastructure Security Engineer should be able to assume roles within our Information Systems Management framework • Within 180 days, the Infrastructure Security Engineer should be able to work with Governance Risk & Compliance to close audit findings quickly and effectively • Access Control Management & Optimization • Within 30 days, the Infrastructure Security Engineer should have an understanding of our Access Control Policies, Processes & Technologies • Within 30 days, the Infrastructure Security Engineer should be able to take ownership of Access provisioning, decommissioning & access management optimization • Within 90 days, the Infrastructure Security Engineer should have conducted a review of the current access management system, identified gaps and propose recommendations • Vulnerability Management • Within 60 days, establish a consistent vulnerability management process across infrastructure and endpoints • Within 90 days, ensure all critical & high vulnerabilities have clearly defined remediation SLAs • Within 180 days, reduce monthly recurring unremediated vulnerabilities by 40% • Provide clear, actionable vulnerability remediation guidance to Engineering and DevOps teams. • Security Monitoring, Detection & Response • Within 30 days, review and be conversant with existing SIEM architecture • Within 90 days, identify and document all areas of improvement in our security event monitoring • Within 180 days, start implementing all areas of improvement to log aggregation, security event analysis and alerting • Within 90 days, identify new playbooks for automated incident response in the SOAR and document the recommendations • Within 12 months, implement the playbooks for automated incident response recommendations in the SOAR • Continuously improve detection coverage and incident response automation and orchestration across cloud, endpoints, and network layers • Secure Cloud & Network • Within 30 days, review and understand services & configurations across multi-cloud platforms • Within 60 days, be able to administer security policies & security services across multi-cloud platforms • Within 60 days, partner with relevant Engineering teams to ensure security is embedded in infrastructure design and configuration from day one • Security Operations & Automation • Within 30 days, review existing automations, test them out and identify areas of for optimization/improvement • Within 180 days, automate at least 30% of repetitive security operations tasks • Continuously evaluate and implement new tools that improve detection, prevention, or efficiency • Continuously improve security policies and enforcement mechanisms • Cross-Functional Security Enablement • Work closely with Engineering, DevOps, and Product teams to embed security into workflows • Provide hands-on guidance during system design, deployments, and incident response • Promote strong security practices across the company — not just enforce them



