Endpoint Security Engineer

Schmidt Entities

San Francisco (CA)

On-site

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hillspire is seeking an experienced Endpoint & SaaS Security Engineer to advance a modern security program in San Francisco. The role focuses on endpoint and SaaS security within a Zero Trust framework, with emphasis on device posture, insider threat prevention, automation, and AI-driven operations.

This hands-on engineering role offers significant ownership and the opportunity to shape security across endpoints, SaaS platforms, and AI initiatives, including RAG-based security ops and automated

Qualifications

  • 5+ years of cybersecurity engineering experience.
  • Strong experience securing Windows and macOS endpoints.
  • Experience with MDR services.
  • Experience implementing Zero Trust security principles.
  • Knowledge of insider threat detection techniques.
  • Experience with SaaS security and Shadow IT governance.
  • Experience supporting BYOD environments.

Responsibilities

  • Own health, configuration, and continuous improvement of endpoint security platform.
  • Administer endpoint protection, XDR, and MDR across corporate devices.
  • Ensure 100% endpoint visibility and security coverage.
  • Investigate and remediate compromised, vulnerable, or non-compliant endpoints.
  • Develop endpoint security baselines aligned with Zero Trust principles.
  • Improve device security posture through vulnerability management and hardening.
  • Build automated remediation workflows and detection logic.
  • Develop documentation, playbooks, and operational procedures.
  • Monitor, investigate, and respond to security alerts.

Skills

Endpoint security
SaaS security
Zero Trust
Automation
AI in security

Tools

Sophos Central
Splunk Enterprise Security
CrowdStrike
Okta
Google Workspace security
CASB or SSPM
Threat Intelligence Platforms

Job description

About the Role

Hillspire is seeking an experienced Endpoint & SaaS Security Engineer to help build one of the industry's most advanced modern security programs. This role is responsible for protecting endpoints and the SaaS platforms running on them, while helping mature Hillspire's Zero Trust security architecture with a strong emphasis on device security posture, insider threat prevention, automation, and AI.

The ideal candidate is equally comfortable investigating security alerts, engineering new security controls, building automation, and leveraging AI to improve operational efficiency. This is a hands-on engineering role with significant ownership and the opportunity to shape the future of endpoint, SaaS, and AI security across the organization.

This position is based full-time in our San Francisco headquarters in the Embarcadero and is offered as a contract-to-hire opportunity.

Endpoint Security Engineering
  • Own the health, configuration, and continuous improvement of Hillspire's endpoint security platform.
  • Administer Sophos Endpoint Protection, XDR, and MDR capabilities across all corporate devices.
  • Ensure 100% endpoint visibility and security coverage.
  • Investigate and remediate compromised, vulnerable, or non-compliant endpoints.
  • Develop endpoint security baselines aligned with Zero Trust principles.
  • Improve device security posture through vulnerability management, compliance monitoring, and hardening.
  • Build controls that reduce insider threats and prevent lateral movement.
SaaS Security

Develop and mature Hillspire's SaaS Security program by:

  • Maintaining visibility into SaaS applications
  • Identifying Shadow IT and unauthorized SaaS usage
  • Governing BYOD, BYO-SaaS, and BYO-AI risks
  • Monitoring SaaS security posture
  • Improving SaaS authentication and identity controls
  • Partnering with business teams to securely onboard new SaaS platforms
  • Supporting vendor security reviews and third‑party risk assessments
AI Security & Automation

Help shape Hillspire's next‑generation AI security program by:

  • Building Retrieval‑Augmented Generation (RAG) solutions for security operations
  • Developing automation that continuously scans Hillspire's security posture
  • Using AI to improve incident response, investigations, and operational efficiency
  • Helping secure the organization’s adoption of Generative AI technologies
Security Engineering & Operations
  • Monitor, investigate, and respond to security alerts.
  • Develop detection logic for insider threats.
  • Build automated remediation workflows.
  • Improve endpoint telemetry and visibility.
  • Enhance Zero Trust controls across users, devices, and applications.
  • Develop documentation, playbooks, and operational procedures.
  • 5+ years of cybersecurity engineering experience
  • Strong experience securing Windows and macOS endpoints
  • Experience working with Managed Detection & Response (MDR)
  • Experience implementing Zero Trust security principles
  • Knowledge of insider threat detection techniques
  • Experience with SaaS security
  • Understanding of Shadow IT and SaaS governance
  • Experience supporting BYOD environments

Experience with two or more of:

  • Sophos Central
  • Splunk Enterprise Security
  • CrowdStrike
  • Okta
  • Google Workspace security
  • CASB or SSPM platforms
  • Threat Intelligence Platforms
  • NIST Cybersecurity Framework
  • CISA Zero Trust Architecture

We are looking for engineers who embrace AI as a force multiplier. Ideal candidates will implement solutions that rely on:

  • Prompt engineering using leading AI platforms
  • Building AI‑assisted workflows
  • Experimenting with AI agents
  • Creating MCP servers
  • Developing automation using modern AI frameworks

Previous production AI experience is beneficial but not required. We value curiosity and a willingness to learn.

Hillspire is heavily investing in AI and next‑generation cybersecurity capabilities. Upon hiring, this engineer will receive company-sponsored training in:

  • Advanced Splunk engineering
  • AI Advanced training

You’ll join a small, highly technical security team with the opportunity to build—not just maintain—security capabilities. You’ll have access to cutting‑edge AI platforms, best‑in‑class enterprise security tooling such as Wiz, Splunk, Palo Alto, and the freedom to engineer innovative solutions that improve the organization’s security posture.

If you’re passionate about endpoint security, SaaS security, Zero Trust, AI, automation, and building the future of cybersecurity, we’d love to hear from you.

This is an exempt position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Security Engineer
Endpoint Security Engineer

IDT Corporation • San Francisco (CA)

On-site
USD 200,000 - 225,000
Endpoint Security Engineer
Endpoint Security Engineer

Hillspire • San Francisco (CA)

On-site
USD 200,000 - 225,000
Endpoint Security Engineer — AI, SaaS & Zero Trust
Endpoint Security Engineer — AI, SaaS & Zero Trust

IDT Corporation • San Francisco (CA)

On-site
USD 200,000 - 225,000
Endpoint & AI Security Engineer with Zero Trust
Endpoint & AI Security Engineer with Zero Trust

Schmidt Entities • San Francisco (CA)

On-site
USD 150,000 - 230,000
Zero-Trust Endpoint Security Engineer
Zero-Trust Endpoint Security Engineer

Hillspire • San Francisco (CA)

On-site
USD 200,000 - 225,000
Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Lead IT Support Engineer
Lead IT Support Engineer

Schmidt Entities • Edison (CA)

On-site
USD 110,000 - 165,000
Security Operations Engineer
Security Operations Engineer

Edison • San Francisco (CA)

On-site
USD 180,000 - 240,000
Competitive salary + equity
Full healthcare coverage for you and 1
Parental leave and fertility support
+4
Security Operations Engineer
Security Operations Engineer

Edison Scientific • San Francisco (CA)

Hybrid
USD 140,000 - 190,000
Health insurance
401(k) contribution
Parental leave
+2