Senior Security Engineer (Enterprise Security)

CoreWeave

York and North Yorkshire

Hybrid

GBP 90,000 - 130,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CoreWeave is seeking a Senior Security Engineer, Enterprise Security, to design and ship security controls underpinning our workforce and enterprise stack in a fast-growing cloud environment.

You will lead identity, access management, device and SaaS security initiatives, blend hands-on engineering with architecture, and translate objectives like zero trust and phishing-resistant MFA into concrete designs, automation, and measurable risk reduction.

Qualifications

  • 5+ years in enterprise security, identity and access management, or related security engineering roles.
  • Hands-on experience implementing SSO and workforce identity with IdPs (Okta/Entra).
  • Experience securing and integrating major SaaS (Google Workspace, Microsoft 365, Slack) including SCIM provisioning and audit logs.

Responsibilities

  • Design and ship security controls for workforce identity, devices, and SaaS security.
  • Lead initiatives across IAM, device security, and SaaS, partnering with IT and security teams.
  • Turn high-level objectives (zero trust, phishing-resistant MFA) into concrete designs, automation, and risk reduction measures.

Skills

Zero trust concepts
IAM concepts
SaaS security
Security architecture

Tools

Okta/Entra
SAML/OIDC
SCIM
MDM/EDR tooling

Job description

  • The Enterprise Security team at CoreWeave is responsible for securing how our people work every day—identity, endpoints, networks, and SaaS—so the company can move fast without compromising safety
  • This team owns the controls, guardrails, and automation that keep our workforce, contractors, and critical business applications protected in a modern, cloud-native environment
  • As a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls that underpin CoreWeave’s workforce and enterprise stack
  • You’ll lead initiatives across identity, access management, device and endpoint security, and SaaS security—partnering closely with IT Engineering, Endpoint, Network, and other security teams
  • Your day-to-day will blend hands-on engineering (writing code, building integrations, tuning controls) with architecture and program ownership (setting standards, defining patterns, and driving adoption across teams)
  • You’ll be responsible for turning high-level objectives—like “implement zero trust for workforce access” or “deploy phishing-resistant MFA at scale”—into concrete designs, automation, and measurable risk reduction
  • Design, implement, and operate workforce identity solutions (e.g., Okta/Entra and other IdPs) including SSO, MFA, conditional access, and lifecycle automation via SCIM
  • Develop and roll out phishing-resistant MFA for high-value accounts and critical access paths (e.g., FIDO2/WebAuthn, hardware keys, device-bound authenticators)
  • Define and maintain RBAC/IAM patterns for enterprise applications (role models, groups, entitlements, JIT access, and approvals)
  • Design and deploy controls that combine user identity, device posture, network context, and application sensitivity to enforce least-privilege access
  • Partner with Network and Infrastructure teams to integrate mTLS, service identity, and policy-based access into internal services and admin interfaces
  • Help transition from legacy perimeter models to zero trust network access (ZTNA) patterns for employees, contractors, and third parties
  • Evaluate, onboard, and harden SaaS applications (Google Workspace, Microsoft 365, Slack, HRIS, ticketing, and other business apps) to align with enterprise security policies
  • Implement and tune controls such as SCIM provisioning, data access policies, DLP, sharing controls, and audit logging across the SaaS estate
  • Partner with business and IT owners to ensure new SaaS applications meet baseline security standards before adoption
  • Collaborate with Endpoint/IT teams to define and enforce baseline configurations for laptops, workstations, and other managed devices via MDM and EDR
  • Design secure patterns for contractor and vendor access, including device requirements, identity separation, and time-bound access
  • Support investigations and incident response related to identity, endpoint, and SaaS domains
  • Build automation and self-service experiences for access requests, approvals, access reviews, and break-glass workflows
  • Develop integrations between IdPs, HRIS, ticketing, and other systems to minimize manual toil and reduce identity-related error rates
  • Define and instrument metrics for enterprise security (e.g., MFA coverage, zero trust policy enforcement, joiner/mover/leaver SLA adherence, SaaS posture)
  • Work with Security Operations and SIEM teams to ensure robust visibility into identity, device, and SaaS activity, and to build high-signal detections
  • Contribute to policies, standards, and reference architectures that encode enterprise security expectations
  • Author clear documentation and runbooks that make it easy for teams to consume and operate the controls you build

If you’re excited about zero trust, phishing-resistant MFA, and building secure-by-default experiences that actually make people more productive, this is the team to joinDemonstrated experience designing and rolling out MFA, ideally including phishing-resistant approaches (FIDO2/WebAuthn, hardware security keys, device-bound authenticators, step-up authentication)Exposure to SIEM/detection ecosystems (e.g., Elastic) and experience collaborating with detection & response teams on identity/endpoint/SaaS detectionsDeep familiarity with SAML, OAuth 2.0/OIDC, and SCIM, including real-world experience integrating these protocols with third-party SaaS and internal appsStrong, practical understanding of modern IAM concepts: SSO, federation, RBAC/ABAC, JIT access, least privilege, and separation of dutiesExperience designing and deploying zero trust or context-aware access controls (e.g., device trust, network segmentation, mTLS, ZTNA) in hybrid or remote-friendly environmentsFamiliarity with MDM and endpoint security tooling (e.g., Jamf, Intune, EDR platforms) and how they tie into identity and access decisionsA track record of owning cross-functional projects from design through adoption, with an emphasis on measurable risk reduction and user experienceProficiency in at least one modern scripting or programming language (e.g., Python, Go) used to build automations, integrations, or internal toolingExperience securing and integrating business-critical SaaS (e.g., Google Workspace, Microsoft 365, Slack, Atlassian, HRIS, ticketing) including SCIM provisioning, access reviews, and audit log ingestion5+ years of experience in enterprise security, identity and access management, or closely related security engineering rolesHands-on experience implementing and operating SSO and workforce identity with platforms such as Okta, Entra ID, or equivalent IdPsExperience working in high-growth or hyperscale environments where security must keep pace with rapid headcount and tooling expansionHands-on experience with zero trust network access or secure access products (e.g., ZTNA, secure web gateways, or identity-aware proxies)Experience with SaaS security posture management (SSPM), CASB, DLP, or insider risk tooling focused on collaboration platforms and data accessFamiliarity with enterprise security standards and frameworks (e.g., SOC 2, ISO 27001, NIST 800-53) and mapping enterprise controls to these requirementsExperience building or contributing to internal security tooling (e.g., access review automation, JML workflows, policy-as-code)Participation in security communities, standards groups, or open-source contributions in IAM, zero trust, or enterprise security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technical Program Manager (Security Programs)
Senior Technical Program Manager (Security Programs)

CoreWeave • York and North Yorkshire

On-site
GBP 104,000 - 149,000
Senior Enterprise Security Engineer: Zero-Trust & MFA
Senior Enterprise Security Engineer: Zero-Trust & MFA

CoreWeave • York and North Yorkshire

Hybrid
GBP 90,000 - 130,000
Security Engineer (Corporate Security)
Security Engineer (Corporate Security)

Anthropic • York and North Yorkshire

On-site
GBP 120,000 - 180,000
Comprehensive health insurance
Dental and vision coverage
15–22 weeks parental leave
Security Engineer
Security Engineer

Conduct • Greater London

On-site
GBP 70,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Intropic • Greater London

On-site
GBP 110,000 - 150,000
Security Engineer
Security Engineer

Conduct AI • Greater London

On-site
GBP 70,000 - 110,000
Security Engineer
Security Engineer

Conduct AI Ltd • City Of London

On-site
GBP 75,000 - 110,000
Security Engineer
Security Engineer

Portage Ventures GP Inc. • Greater London

On-site
GBP 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Intropic • City Of London

On-site
GBP 90,000 - 140,000
Senior Security Engineer
Senior Security Engineer

Natter • United Kingdom

On-site
GBP 90,000 - 130,000