FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesCloudDNSJamfMacOSPython
About the role
Key responsibilities & impact- Own engineering of security controls for OpenLoop’s macOS and Windows fleet, including MDM, disk encryption, patch compliance, and local admin controls
- Engineer MDM and MAM policies protecting company and PHI data on managed devices and BYOD
- Deploy and manage an enterprise browser securing SaaS and web access through data controls, session policies, and extension management
- Build, apply, and continuously measure CIS Benchmark baselines across the fleet
- Track configuration drift, manage documented exceptions, and produce fleet-level evidence for HITRUST and SOC 2 auditors
- Drive application control and least privilege on endpoints
- Own Google Workspace email security, including SPF, DKIM, DMARC, phishing and BEC defenses, attachment and link protection, and PHI data loss prevention
- Tune security controls to reduce risk and false positives and partner with SecOps on phishing triage workflows
- Write security standards, configuration baselines, and runbooks
- Implement and validate controls identified through threat modeling and security reviews
- Map controls to HITRUST and SOC 2 requirements and own audit evidence
- Automate repetitive work through scripting
- Mentor SAE and adjacent-team engineers and serve as an incident escalation point
- Partner with IT, Engineering, Compliance, and SecOps to translate security risk into business and operational terms
- Perform other duties as assigned
Requirements
What you’ll need- 8+ years in security engineering, with a track record of owning outcomes end to end
- Deep, hands-on expertise in endpoint security and email security
- Experience deploying and operating MDM/MAM platforms (Kandji, Jamf, Intune, or similar) and email security platforms
- Experience deploying and managing an enterprise browser platform
- Hands-on experience implementing CIS Benchmarks and measuring compliance against them at fleet scale
- Exposure to network security: secure remote access (ZTNA/VPN), DNS filtering, segmentation, or firewall policy
- Working knowledge of cloud security fundamentals, including IAM, network controls, logging, and workforce access to cloud environments
- Exposure to DevSecOps practices, including infrastructure as code, CI/CD security, secrets management, or security tooling in pipelines
- Scripting ability in Python, Bash, PowerShell, or similar
- Experience working in a regulated environment (HIPAA, HITRUST, SOC 2, PCI, or similar) and producing audit evidence
- Clear written communication; ability to write standards, defend decisions, and explain risks to non-security executives
- Relevant certifications such as GIAC, CISSP, OSCP, or cloud security certifications are preferred, not required
- Must answer whether visa sponsorship is required now or in the future
Benefits
Comp & perks- Medical, Dental & Vision
- Flexible Spending / Health Savings Accounts
- Generous PTO
- Hybrid-work flexibility
- 401(k) with Company Match
- Life Insurance
- Pet Insurance
- Competitive compensation
