Get more replies from employers
Send a job-specific resume in minutes.
Higgsfield AI is seeking a hands-on Security Engineer to own corporate security across devices, identities, and SaaS. You’ll scale MDM, EDR, and endpoint hardening for a fast‑growing AI startup.
You’ll deploy Entra SSO, MFA, and conditional access; manage joiner/mover/leaver and password hygiene; lead security awareness programs, phishing simulations, and incident response. This is an on‑site role at our Almaty office.
Higgsfield AI is the fastest‑scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.
We're building at the absolute frontier of AI‑powered video creation and next‑generation creative tools. Joining Higgsfield means becoming part of a high‑impact team shaping the future of AI‑native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.
You'll own corporate security: the devices, identities, and SaaS the company runs on. Sister role to the Infrastructure Security Engineer — they secure the cloud and ML platform; this role secures the people side.
We are looking for someone with experience in scaling high‑growth startups who can make an immediate impact in the following areas:
Endpoints:
Own MDM across the fleet: enrollment, policy enforcement, compliance, device lifecycle.
Run EDR/XDR: detection, triage, and response on employee devices.
Set and maintain endpoint hardening standards with IT and Engineering.
Corporate identity & access
Own corporate identity: Entra SSO, MFA, conditional access.
Run joiner‑mover‑leaver: provisioning and same‑day offboarding across all SaaS.
Administer a Password Management solution and drive credential hygiene.
Awareness & response
Security‑review new SaaS before adoption; own the approved‑app list; hunt shadow IT.
Secure the collaboration stack: email, Slack, file sharing. AWARENESS & RESPONSE
Run phishing simulations and onboarding security training.
Partner with infrastructure security on centralized security monitoring: feed endpoint and identity signals into shared detection and response.
Requirements:
Hands‑on experience running MDM and EDR at fleet scale.
Production experience running an IdP: SSO/SAML/SCIM, MFA, and conditional access.
Enough scripting to automate the repetitive parts (Python, PowerShell, or Bash).
High agency.
Working English.
Nice to have:
Familiarity with SOC 2.
High‑growth startup experience.
Competitive base salary in USD
Equity: participation in the company’s stock option program, giving you the opportunity to share in the company’s long‑term growth.
On‑site role in our Almaty office (we will relocate you from anywhere).