Sr. Security Engineer, Corporate Information Security

Betterment

New York (NY)

Hybrid

USD 165,000 - 185,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible paid time off
Equity for all employees
Professional coaching
401(k) match

Job summary

Betterment is seeking a Sr. Security Engineer with over 6 years of experience to join its Workforce Security team in NYC. This role focuses on secure identity management and access protocols using technologies like Okta and Google Workspace.

Applicants should have strong skills in security engineering and a background in vulnerability management. The position offers a competitive salary between $165,000 and $185,000, along with benefits including equity, flexible time-off, and a 401(k) match.

Qualifications

  • 6+ years of experience in security engineering with expertise in IAM.
  • Deep knowledge of authentication and authorization protocols.
  • Experience in vulnerability management and incident response.
  • Proficiency in Python or similar programming for automation.

Responsibilities

  • Design and implement identity architecture and access controls.
  • Secure corporate communications and manage security tools.
  • Lead vulnerability management for endpoints and corporate SaaS.
  • Collaborate with teams on incident response and compliance.

Skills

IAM expertise
Security engineering
Authentication protocols
Vulnerability management
Automation skills

Education

Bachelor's degree in a related field

Tools

Okta
Google Workspace
Slack
Atlassian

Job description

About Betterment

Betterment is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease. We're headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays).

About the Role

Betterment is hiring a Sr. Security Engineer, Corporate Information Security to be a principal member of the Workforce Security team. We're responsible for managing identity and logical access across the company, owning change management for the systems employees and contractors rely on every day, and operating the technologies that secure them: Okta, Google Workspace, Slack, Atlassian, Glean, Jamf, and the SaaS portfolio that surrounds them. As we extend centralized management to a small Windows and Linux footprint, you'll help shape how we do that securely from day one.

This is a hands‑on senior IC role focused on designing, implementing, and continuously improving identity architecture, privileged access controls, endpoint hardening standards, and our overall workforce security posture. You'll embed secure access patterns across SaaS, managed browser, mobile, and workstation environments partnering closely with other Security teams, IT, Legal, Compliance, and the business units we serve.

In parallel, you'll partner with our AI Governance & enablement team to evaluate, enable, and secure the use of AI tools (ChatGPT, Claude, Glean Assistant, and the agentic tooling that's coming next) establishing practical guardrails that let employees move quickly without compromising data or systems.

This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment’s total compensation package for employees.

  • New York City: $165,000-185,000

This job may also be eligible for variable compensation in the form of a company incentive bonus.

A Day in the Life

Your weeks blend strategic architecture, hands‑on implementation, and operational support:

  • Identity & Access Architecture: Define and evolve the workforce IAM roadmap. Architect identity patterns across Okta and our SaaS estate SSO at scale, RBAC that holds up under growth, and lifecycle automation that reaches every downstream system from HRIS through joiner/mover/leaver. Build a sustainable Identity Governance & Administration (IGA) practice, including User Access Review campaigns that produce real evidence rather than rubber stamps.
  • Security Design: Lead initiatives across authentication, authorization, federation, and privileged access. Design time‑bound, just‑in‑time, and break‑glass patterns (PIM‑equivalent) for high‑risk roles so standing privilege trends toward zero. Govern non‑human identities, service accounts, API tokens, OAuth integrations, and the AI agents that increasingly act on users' behalf. Embed Zero Trust and least‑privilege principles into every workforce system you touch.
  • Securing & Monitoring Corporate Communications: Manage the security of corporate communication platforms, including email and Slack, through tools such as Abnormal Security and Proofpoint. Responsibilities include DLP enforcement to protect PII and conducting email investigations for spam, phishing and other threats.
  • Endpoint, Mobile & Browser Security: Define and enforce hardening standards aligned with CIS benchmarks. Own configuration baselines for macOS, Windows, and Linux Desktops, with mobile and managed browser controls layered on top. Architect enterprise browser security, extension governance, session protection, and DLP at the browser layer.
  • Vulnerability & Posture Management: Lead the workforce vulnerability management program for endpoints and corporate SaaS. Design remediation SLAs by severity and asset class, run remediation campaigns that actually close findings, and partner with IT Systems to surface and fix identity and configuration misconfigurations. Operate SaaS posture tooling (e.g., Wiz, Vanta, Drata, or peers) as the connective tissue across our SaaS estate.
  • AI Tool Security: Establish and enforce a secure architecture for AI tool usage, data handling boundaries, connector security, identity‑aware access controls, and detection for misuse with a bias toward enabling the business safely rather than gating it.
  • Governance & Operations: Run UAR campaigns end‑to‑end, drive remediation of audit findings (SOC 2, ISO 27001), and partner with our MDR MSP and internal teams to mature identity‑related detection and incident response. Augment and assist with cross‑functional GRC capabilities
What We’re Looking For:
  • Experience: 6+ years in security engineering with deep experience in IAM and corporate security, ideally with time in a regulated environment.
  • IAM depth: Strong command of authentication and authorization protocols (SAML, OIDC, OAuth, SCIM, LDAP), enterprise IAM platforms (Okta and Entra ID), RBAC design, and lifecycle automation. Comfortable with Identity Center / SSO patterns at scale and PIM‑equivalent / break‑glass models for privileged access.
  • Endpoint, mobile & browser: Familiarity with endpoint management and EDR; an opinion on operationalizing CIS benchmarks across macOS and Windows without crushing the user experience; comfort extending security to mobile and managed browser surfaces.
  • Vulnerability & posture: Experience designing remediation SLAs, running remediation campaigns to actual closure, and operating SaaS posture tooling (Wiz, Vanta, Drata, or peers).
  • Automation mindset: Comfortable building tools and pipelines, not just configuring them; Python, Go, or similar with a track record of automation that survives the person who built it.
  • AI fluency: Curiosity for AI tools and workflows; an instinct for enabling responsibly rather than reflexively blocking.
  • Communication: Strong writing — RFCs, one‑pagers, audit narratives — and the cross‑functional patience to bring stakeholders along.
  • Compliance posture: Comfort operating in SOC 2 and ISO 27001/NIST environments, balancing risk reduction with business enablement.
  • Enterprise network: Experience with network monitoring & alerting, perimeter blocking, intelligence gathering/sharing, and other network related security controls (ZTNA); building/testing ACLs, firewall rules, cryptography, VPNs and tunneling/encapsulation.
Preferred Qualifications
  • Hands‑on experience with Privileged Access Management (CyberArk, BeyondTrust, Delinea), Identity Governance & Administration (Saviynt, SailPoint, ConductorOne, Lumos), or modern secrets management (HashiCorp Vault, Doppler).
  • Real‑world Zero Trust implementation experience, not as a slide.
  • Working knowledge of policy‑as‑code (OPA / Rego) or similar.
  • Experience partnering with an MDR / managed SOC and shaping their detection content.
  • Security certifications such as CISSP or vendor IAM certifications.
Our Commitment to Your Total Well‑being:
  • We offer a competitive suite of benefits, including medical, dental, and vision coverage; life and AD&D insurance; short‑and long‑term disability; infertility support and WPATH‑aligned transgender health benefits; an Employee Assistance Program (EAP); transit benefits and FSA and HSA options
  • Ownership: Equity for all employees, including new hire and refresher grants.
  • Time: Flexible paid time off, paid parental leave, and a fully paid four‑week sabbatical in your sixth year.
  • Growth: Company‑paid professional coaching for all employees.
  • Wealth: Day‑one 401(k) match plus matching on qualified student loan payments.

Betterment is dedicated to providing accommodations to candidates upon request. If you need accommodations at any point throughout the interview process, please reach out to your recruiter.

Please note that in any materials you submit, you may redact or remove age‑identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

We’re an equal opportunity employer and comply with all applicable federal, state, and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees, applicants, or any other covered persons because of race, color, religion, creed, national origin or ancestry, ethnicity, sex, gender (including gender nonconformity and status as a transgender or transsexual individual), sexual orientation, marital status, age, physical or mental disability, citizenship, past, current or prospective service in the uniformed services, predisposing genetic characteristic, domestic violence victim status, arrest records, or any other characteristic protected under applicable federal, state or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Engineering Manager, Application Security
Sr. Engineering Manager, Application Security

Betterment • New York (NY)

Hybrid
USD 210,000 - 250,000
Medical, dental, and vision coverage
Equity for all employees
Flexible paid time off
+2
Sr. Product Security Engineer
Sr. Product Security Engineer

GoTo Meeting • New York (NY)

On-site
USD 175,000 - 205,000
Equity package
Health, dental, and vision benefits
Flexible PTO
+2
Sr. IT Systems Engineer
Sr. IT Systems Engineer

Betterment • New York (NY)

Hybrid
USD 121,000 - 143,000
Health, dental and vision benefits
Flexible PTO policy
401(k) with employer match
+1
Sr. Product Security Engineer
Sr. Product Security Engineer

Betterment • New York (NY)

Hybrid
USD 120,000 - 150,000
Medical, dental, and vision insurance
Flexible paid time off
Community building opportunities
+2
Sr. Program Manager, Business Systems & Tooling
Sr. Program Manager, Business Systems & Tooling

Betterment • New York (NY)

Hybrid
USD 125,000 - 145,000
401(k) match
Flexible PTO
Sabbatical after 6 years
Sr. Program Manager, Business Systems & Tooling
Sr. Program Manager, Business Systems & Tooling

Doist • New York (NY)

Hybrid
USD 125,000 - 145,000
Staff Engineer, User Engagement
Staff Engineer, User Engagement

Menlo Ventures • New York (NY)

Hybrid
USD 200,000 - 238,000
Equity package
Health, dental and vision benefits
401(k) with employer match
+1
Senior IT Systems Engineer
Senior IT Systems Engineer

Betterment • New York (NY)

On-site
USD 120,000 - 140,000
Equity package
Health, dental, vision
Life & AD&D insurance
+7
Sr. Manager, Advised 401k Sales
Sr. Manager, Advised 401k Sales

Francisco Partners • New York (NY)

Hybrid
USD 240,000 - 280,000
Competitive benefits
Staff Full Stack Software Engineer
Staff Full Stack Software Engineer

Betterment • New York (NY)

Hybrid
USD 190,000 - 220,000
Competitive equity package
Health, dental and vision benefits
Flexible PTO policy
+1