Senior Enterprise Security Engineer - IAM & AI Automation

Pave

San Francisco (CA)

Hybrid

USD 210,000 - 240,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Equity
Medical, dental, vision
Flexible PTO
Hybrid work model
Education stipend
Parental leave
Commuter stipend
Team Sync Fridays

Job summary

Pave, headquartered in San Francisco, seeks a Corporate Security Engineer to own identity and access management, endpoint protection, SaaS security, and corporate compliance operations behind SOC 2 Type II and ISO 27001. You will automate governance across multiple locations and helpdesk processes with AI-powered tooling.

You bring 5+ years of enterprise security, design-level Okta administration, and experience with SOC 2/ISO 27001.

Qualifications

  • 5+ years of hands-on corporate/enterprise security or IT security engineering experience at a multi-office company.
  • Okta (or equivalent IdP) administration at the design level — you\'ve built an access model, not just operated one
  • Experience operating within SOC 2 and/or ISO 27001: controls you owned passed audits
  • Hands-on MDM/EDR and Google Workspace–class SaaS estate administration as a primary owner
  • A track record of shipped automations with concrete before/after impact
  • Demonstrated, specific use of AI tooling in your own workflows
  • Previous management experience (nice to have)
  • Came up through IT/helpdesk into security (or similar path), so you have empathy for the people you\’re supporting and first hand experience with the toil you\’re here to automate away
  • Experience with Okta, GCP, Iru, Sentinel one, Claude code, and or similar tools
  • Vendor security review / third-party risk experience (nice to have)
  • Background at a 150–500 person B2B SaaS company handling sensitive data (nice to have)
  • Networking fundamentals

Responsibilities

  • Identity & Access Management — Own Okta and Pave's access-management model: role/group architecture, lifecycle automation, SSO/SCIM, and the exception process
  • Keep the RBAC model current and consistently enforced, with automation that prevents drift
  • Compliance Operations — Own the SOC 2 Type II and ISO 27001 controls that touch corporate IT, end to end
  • Automate evidence collection and user access reviews
  • Endpoint & SaaS Security — Own endpoint protection (MDM/EDR) across a five-location, ~175-person company
  • Run SaaS vendor security reviews and build shadow-IT visibility; feed IT-controlled data sources into our SIEM
  • Automation & AI — Engineer away manual IT toil — laptop setup, onboarding/offboarding provisioning, access requests — using APIs, workflow tooling, and AI agents
  • Build governance for employee-built internal apps: publish detection, automated review checks, sane sharing models
  • Partnership — Design the systems that Pave's helpdesk (in G&A) operates day to day; be the design counterpart that makes that team stronger and more self-sufficient

Skills

Okta admin
IAM design
SOC 2 controls
ISO 27001
MDM/EDR
SaaS security
AI tooling
GCP
RBAC automation
Vendor risk
Networking fundamentals

Tools

Okta
GCP
SentinelOne
Claude
MDM
SIEM

Job description

Pave, headquartered in San Francisco, seeks a Corporate Security Engineer to own identity and access management, endpoint protection, SaaS security, and corporate compliance operations behind SOC 2 Type II and ISO 27001. You will automate governance across multiple locations and helpdesk processes with AI-powered tooling.

You bring 5+ years of enterprise security, design-level Okta administration, and experience with SOC 2/ISO 27001.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Corporate Security Engineer — IAM & AI Automation
Senior Corporate Security Engineer — IAM & AI Automation

Trov • San Francisco (CA), Northern (KY)

Hybrid
USD 210,000 - 260,000
Health, dental, and vision coverage
Flexible PTO
Commuter stipend
+3
Senior Corporate Security Engineer — IAM & AI Automation
Senior Corporate Security Engineer — IAM & AI Automation

Pave • New York (NY)

Hybrid
USD 187,000 - 253,000
Health insurance
Flexible PTO
Meal stipends
+3
Corporate Security Engineer: Identity & Endpoints
Corporate Security Engineer: Identity & Endpoints

Monograph • San Francisco (CA)

On-site
USD 220,000 - 260,000
Senior Identity & Access Security Engineer
Senior Identity & Access Security Engineer

Expand Energy • Oklahoma City (OK)

On-site
USD 110,000 - 160,000
Senior IAM Architect - Enterprise Identity & AI Security
Senior IAM Architect - Enterprise Identity & AI Security

Tally • San Francisco (CA)

Hybrid
USD 197,000 - 232,000
Hybrid work model
Relocation assistance
Equity eligibility and annual bonus
Systems Engineer, Corporate Security & IAM Automation
Systems Engineer, Corporate Security & IAM Automation

Apply • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Flexible PTO
Home-office equipment ordering
Health and wellness stipend
+7
Senior Identity Platform Engineer - IAM & Access Governance
Senior Identity Platform Engineer - IAM & Access Governance

Scale AI • San Francisco (CA)

On-site
USD 216,000 - 270,000
Senior Security Engineer - AI-Driven SaaS & Compliance
Senior Security Engineer - AI-Driven SaaS & Compliance

Code and Theory • United States

On-site
USD 110,000 - 150,000
Senior Security Engineer: AI-Powered SaaS & Cloud Security
Senior Security Engineer: AI-Powered SaaS & Cloud Security

C1 • San Francisco (CA)

On-site
USD 180,000 - 280,000
Senior IAM & AI-Driven Security Engineer
Senior IAM & AI-Driven Security Engineer

HealthEquity • United States

On-site
USD 115,000 - 150,000
Medical, dental, and vision
HSA contribution and match
Dependent care FSA match
+6