GrepJob
Thumbtack

Senior Enterprise Security Engineer

Thumbtack
Apply
about 2 months ago
Remote, United StatesSenior
H1B Sponsor

Base Salary

$179k - $273k/yr

Responsibilities

  • Conduct security assessments and threat models for first-party and third-party AI tools, agents, and AI-integrated systems.
  • Design and validate reusable security guardrails for agent behavior, permissions, human-in-the-loop boundaries, input and output controls, auditing, observability, MCP servers, integrations, trust boundaries, and AI data pipelines.
  • Harden enterprise IAM for service accounts, agent credentials, SaaS-to-SaaS OAuth, and SCIM federation using least-privilege and lifecycle controls.
  • Provide security engineering support across SaaS security, third-party and integration security, data governance, endpoint security, identity-centric controls, and enterprise platforms.
  • Build paved paths, shared tooling, automation, frameworks, and reusable patterns for secure AI development and enterprise security.
  • Lead cross-functional security initiatives and architecture reviews with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders.
  • Mentor engineers and partner-team members while raising security standards.
  • Support security incident response and conduct post-incident analysis.

Requirements

  • 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field.
  • Experience developing threat models and technical guardrails for AI tooling and agentic systems, including non-human identities, permission scoping, and safe agent defaults.
  • Deep expertise in SSO, OAuth/OIDC, SAML, federation, SCIM, API security, token handling, secrets management, least-privilege design, and SaaS security and posture management.
  • Experience evaluating risk and conducting security design and architecture reviews across enterprise applications, SaaS platforms, integrations, internal systems, data flows, trust boundaries, automation platforms, AI workflows, and MCP patterns.
  • Strong experience securing cloud-native systems using AWS and/or GCP, with familiarity with audit logging, encryption, access control, data retention, and incident response.
  • Ability to balance hands-on technical execution with mentoring, ownership, accountability, and measurable enterprise security improvements.
  • Excellent written and verbal communication skills, including influencing without authority and translating technical risk into clear requirements for technical and non-technical audiences.