Enterprise Security Engineer

TRM Labs · Remote · United States

BUILD A SAFER WORLD. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure. TRM's Enterprise Security team secures the identities, endpoints, and core SaaS infrastructure used by every employee and contractor, enabling the company to move quickly without taking unnecessary risk. We operate at the intersection of IT and Security, building secure-by-default systems, automating controls, and reducing operational toil through engineering. We use AI tooling extensively as part of how we work, and we expect the same of the engineers who join us. We're looking for an Enterprise Security Engineer to help harden and scale our corporate environment. You'll design and deliver identity, endpoint, and SaaS security improvements; codify controls using automation and infrastructure-as-code; and partner closely with Security, Compliance, and Engineering teams to continuously raise our security baseline while preserving an excellent employee experience. THE IMPACT YOU WILL HAVE HERE - Engineer secure-by-default endpoint baselines for macOS and Windows, including encryption, firewall, application controls, device compliance, and configuration standards. - Automate and scale identity and access controls in Microsoft Entra ID and Google Workspace, including SSO, SCIM, Conditional Access, privileged access workflows, access reviews, and joiner/mover/leaver processes. - Codify security controls as code using Terraform, configuration profiles, and policy-as-code, with peer review, testing, rollback capabilities, change history, and measurable outcomes. - Build and maintain automations and integrations (e.g., n8n, SlackOps, APIs, and scripts) that reduce manual access grants, accelerate control changes, and eliminate repetitive workflows. - Apply AI tooling (Claude Code, agentic workflows, MCP integrations, and LLM-backed automations) to accelerate engineering and triage work while helping secure how the rest of the company uses AI through sanctioned tooling, data handling guardrails, and visibility into shadow AI. - Harden SaaS and collaboration platforms by reducing unmanaged applications and enforcing strong authentication, least privilege, sharing controls, and data protection guardrails. - Improve visibility and detection by ensuring logging from endpoints, identity providers, and key SaaS applications is integrated into Microsoft Defender, Microsoft Sentinel, and other relevant security platforms. - Drive vulnerability and configuration drift reduction through remediation pipelines, automation, metrics, and reporting that leadership can act on. - Partner with Compliance and Risk stakeholders to produce evidence, document controls, and operationalize requirements without creating brittle or manual processes. - Participate in an approximately one-week-on, every-three-weeks on-call rotation supporting identity, endpoint security, and critical enterprise systems. WHAT WE'RE LOOKING FOR - Demonstrated experience engineering and scaling endpoint management platforms (such as Microsoft Intune) and endpoint security controls for macOS and Windows. - Strong identity and access management (IAM) foundation with hands-on experience administering Microsoft Entra ID (Conditional Access, SSO, Access Governance) and Google Workspace and/or Microsoft 365. - Proven ability to automate operational workflows using scripting languages such as Bash, PowerShell, or Python. - Fluency with AI-assisted engineering. You already leverage coding agents and LLM tooling to build, review, troubleshoot, and investigate more effectively, while knowing when human verification is required. - Strong troubleshooting and systems-thinking skills across

Sign in to apply — one profile, every role on PreferHired.

Sign in to apply
Enterprise Security Engineer at TRM Labs — PreferHired