Enterprise Engineer

PhysicsX

New York (NY)

Hybrid

USD 140,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity options
401(k) 5% contribution
Free team lunch 1x/week
Private health insurance
Enhanced parental leave
20 days Annual Leave
Personal development support
Gympass/Wellhub
FSA

Job summary

PhysicsX is seeking an experienced security engineer to own Entra ID and zero-trust initiatives in a hybrid New York setting. You will manage MFA, PIM, SCIM provisioning, and IAM governance while coordinating with platform teams to maintain secure cloud postures across AWS, GCP, and Azure.

The role emphasizes SASE-based access control, MDM oversight, and scripting for automation, with a strong focus on compliance (SOC 2, ISO 27001). Join a growing AI-enabled engineering company in New York.

Qualifications

  • 5–10 years in enterprise IT/security or identity roles with hands-on Entra ID in production.
  • Deep CA policy design experience with risk-based, device-aware rules.
  • Experience with Entra ID Governance: Access Reviews, Privileged Identity Management (PIM).
  • SSO/SAML/OIDC federation and SCIM provisioning across many enterprise apps.
  • Endpoint security tooling: CrowdStrike or Defender for Endpoint.
  • Scripting/automation in PowerShell or Python and using Graph API.
  • Hybrid identity with Entra Connect or on-prem AD sync.
  • Familiar with SOC 2, ISO 27001, FedRAMP; translate controls to implementations.

Responsibilities

  • Own Entra ID environment: CA policies, MFA, PIM, SSO/SCIM, and hybrid identity.
  • Manage infrastructure as code with Terraform for identity, networking, and security tooling.
  • Design zero-trust network access, replacing legacy VPN with SASE-based control.
  • Own MDM strategy across macOS/Windows/Linux/Mobile: enrolment, baselines, patching.
  • Collaborate with platform/DevOps to align AWS/GCP/Azure security postures.
  • Lead access reviews and least-privilege enforcement for audits.

Skills

Entra ID
Azure AD
Zero Trust
MDM
SASE
Terraform
PowerShell
Python
Graph API
Hybrid identity
SCIM provisioning
PIM
SOC 2/ISO 27001

Tools

CrowdStrike
Defender for Endpoint
Terraform
Microsoft Graph API

Job description

About Us

Re-architecting Engineering for the Age of Intelligence

PhysicsX is the physics AI company for industrials. The company’s mission is to accelerate hardware innovation by overhauling what industrial engineering and manufacturing look like today. PhysicsX is building a new simulation software stack to deliver deep physics AI enablement across the entire engineering lifecycle. The company partners with leading organisations in aerospace & defence, automotive, semiconductors, materials, and energy & renewables, supporting them on some of their most critical and complex challenges. PhysicsX is headquartered in the United Kingdom, with offices in London, New York, and Singapore and an expanding presence in the Bay Area.

The Role

Who we’re looking for

  • Someone who has designed and owned enterprise identity (Entra ID/Azure AD) at a company of meaningful size, not just administered an existing tenant.
  • A person who treats zero trust as an architecture to build, not a buzzword to reference. Conditional access, device trust and posture validation, and least privilege as defaults.
  • Someone who's comfortable owning MDM (Intune, Jamf, or similar) end-to-end: enrollment, compliance policy, patching, and lifecycle, across a mixed-OS fleet.
  • A collaborative operator who partners well with security, platform engineering, and the wider business.
  • Hands‑on experience deploying and operating a SASE platform (e.g., Cloudflare One, Zscaler) in production, including policy design, not just administration of an existing setup.
What you will do
  • Own and evolve our Microsoft Entra ID environment: identity architecture, conditional access policies, MFA, PIM, SSO/SCIM integrations, and hybrid identity where relevant.
  • Manage enterprise infrastructure as code in Terraform (identity, networking, and security tooling), so that configuration is versioned, reviewable, and repeatable.
  • Design and implement zero trust network access, replacing legacy VPN patterns with modern SASE-based access control.
  • Own MDM strategy and operations across the device fleet (macOS/Windows/Linux/Mobile): enrolment, compliance baselines, patch management, and endpoint security posture.
  • Partner with the platform/DevOps team to keep enterprise IT and cloud (AWS, GCP, Azure) security postures are aligned and consistent.
  • Lead access reviews, least-privilege enforcement, and identity governance work to support audits and compliance requirements (e.g., SOC 2, ISO 27001).
What you bring to the table
  • 5 - 10 years of experience in enterprise IT, security engineering, or identity/infrastructure roles, with deep, hands‑on ownership of Microsoft Entra ID/Azure AD in production.
  • Deep Conditional Access policy design experience, not just enabling MFA, but building risk based, device aware access rules.
  • Experience with Entra ID Governance: Access Reviews, Identity Protection, Privileged Identity Management (PIM) at scale.
  • SSO/SAML/OIDC federation and SCIM provisioning across a meaningful number of enterprise apps.
  • Endpoint security tooling experience: EDR platforms (CrowdStrike, Defender for Endpoint, or similar)
  • Scripting and automation ability (PowerShell, Python, or Microsoft Graph API) to automate identity and device workflows.
  • Experience with hybrid identity (Entra Connect or on prem AD sync).
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP, able to translate control requirements into actual technical implementation (access reviews, logging, encryption, change management), not just pass an audit checklist.
Nice to have skills
  • Experience with Cloud IAM and security architecture, AWS IAM Security Center, Google Workforce Identity Federation, and how it interacts with enterprise identity (Entra) via federation.
  • Compliance automation experience (Vanta, Drata)
  • Experience with Cloudflare Zero Trust.
  • Exposure to SIEM/EDR/XDR tooling and correlating identity signals with broader security monitoring.
  • Background at an AI or high‑growth SaaS company.
  • Experience supporting UK/EU data protection requirements (e.g., GDPR) from an identity and access standpoint.
  • Certifications (good to have, not required)
    • Microsoft Certified: SC-300
    • Microsoft Certified: SC-100
    • Microsoft Certified: MD-102
    • CompTIA Security+
    • Certifications from your SASE vendor of choice (e.g., Cloudflare Certified, Zscaler Certified)
    • CCNA
What We Offer
  • Equity options - share meaningfully in the company you’re helping to build.
  • 5% contribution to 401(k) - build long‑term security with a strong retirement plan.
  • Free team lunch 1x/week - good food, great company, and space to connect.
  • Private health insurance – comprehensive cover for you, offering total peace of mind.
  • Enhanced parental leave – 3 months full pay paternity and 6 months full pay maternity leave, to provide extra flexibility during the moments that matter most.
  • 20 days of Annual Leave (+ Public Holidays) - because taking time to rest matters.
  • Personal development – dedicated support for learning, development, and leveling up over time.
  • Gympass / Wellhub (subsidized) – for you and up to 3 family members, supporting both physical and mental wellbeing.
  • Flexible Spending Account (FSA) – set aside pre‑tax dollars for eligible healthcare expenses.
Build what actually matters

Help shape an AI‑native engineering company at a formative stage, tackling problems that genuinely matter for industry and society. This is work with real‑world impact - and something you can be proud to stand behind.

Learn alongside exceptional people

Work with a high‑caliber, collaborative team of engineers, scientists, and operators who care deeply about doing great work, and about helping each other get better. We come from diverse backgrounds, but we share a commitment to operating at the highest level and addressing some of the most complex challenges out there. If you’re ambitious, thoughtful, and driven by impact, you’ll feel at home.

Influence over hierarchy

We operate with a flat structure: good ideas win - wherever they come from. Questioning assumptions and challenging the status quo isn’t just welcomed, it’s expected.

Sustainable pace, long‑term ambition

Building meaningful technology is a marathon, not a sprint. We believe in balancing focused, ambitious work with a life beyond it. Our hybrid model blends time together in our New York office with work‑from‑home days, giving you the flexibility to work sustainably while staying connected in person.

And it doesn’t stop there …

Watch this space, we’re continuing to build this as we grow…

We value diversity and are committed to equal employment opportunity regardless of sex, race, religion, ethnicity, nationality, disability, age, sexual orientation or gender identity. We strongly encourage individuals from groups traditionally underrepresented in tech to apply. To help make a change, we sponsor bright women from disadvantaged backgrounds through their university degrees in science and mathematics. We collect diversity and inclusion data solely for the purpose of monitoring the effectiveness of our equal opportunities policies and ensuring compliance with employment and equality legislation. This information is confidential, used only in aggregate form, and will not influence the outcome of your application.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Devops Engineer
Devops Engineer

PhysicsX • New York (NY)

Hybrid
USD 160,000 - 230,000
Equity options
401(k) contribution
Free team lunch 1x/week
+6
Principal Identity Engineer
Principal Identity Engineer

hardrockdigital • United States

On-site
USD 180,000 - 240,000
Competitive pay and benefits
Flexible vacation allowance
Hybrid / remote working environment
+1
Manager, Engineering
Manager, Engineering

United States Digital Space LLC • United States

Hybrid
USD 150,000 - 210,000
Security Engineer – DevSecOps and Security Architect
Security Engineer – DevSecOps and Security Architect

PhysicsX • New York (NY)

On-site
USD 200,000 - 300,000
Equity options
401(k) 5% contribution
Private health insurance
+2
Security Engineer – DevSecOps and Security Architect New York, New York
Security Engineer – DevSecOps and Security Architect New York, New York

PhysicsX Ltd. • New York (NY), Northern (KY)

Hybrid
USD 200,000 - 300,000
Equity options
Pension contributions
25 days holiday plus public holidays
+7
Principal Identity Engineer
Principal Identity Engineer

Hard Rock Digital • United States

Hybrid
USD 150,000 - 230,000
Hybrid/remote work
Startup culture
Staff Software Engineer - Windows
Staff Software Engineer - Windows

United States Digital Space LLC • United States

Hybrid
USD 150,000 - 210,000
Senior Security Engineer
Senior Security Engineer

Entegrata • Indianapolis (IN)

Hybrid
USD 120,000 - 180,000
Medical insurance
401k plan with match
Unlimited paid time off
+1
Head of IT
Head of IT

Sygaldry Technologies • Ann Arbor (MI)

On-site
USD 130,000 - 180,000
Visa Sponsorship
Competitive salary
Health coverage
+2
Enterprise Account Executive, East
Enterprise Account Executive, East

Ent • United States

Remote
USD 150,000 - 230,000
Distributed workplace
Meaningful equity
Medical, dental, and vision coverage
+4