GrepJob
Thumbtack

Senior Enterprise Security Engineer

Thumbtack
Apply
about 2 months ago
Remote, CanadaSenior
H1B Sponsor

Base Salary

$180k - $233k/yr

Responsibilities

  • Conduct security assessments and threat models for first-party and third-party AI tools, agents, and AI-integrated systems.
  • Design and validate guardrails and reusable patterns for safe agent behavior, tool and permission scoping, human-in-the-loop access, input and output controls, auditing, observability, MCP servers, integrations, trust boundaries, and AI data pipelines.
  • Contribute to frameworks, tooling, paved paths, shared automation, and secure defaults for AI development and enterprise security.
  • Harden enterprise IAM for service accounts, agent credentials, SaaS-to-SaaS OAuth, and SCIM federation using least-privilege and lifecycle-hygiene principles.
  • Support SaaS security and posture management, third-party and integration security, data governance, endpoint security, and identity-centric controls.
  • Lead cross-functional security initiatives and conduct security design and architecture reviews with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders.
  • Mentor engineers and partner-team members and support security incident response and post-incident analysis.

Requirements

  • 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field.
  • Experience developing threat models and technical guardrails for AI tooling and agentic systems, including non-human identities and permission scoping.
  • Deep expertise in authentication, authorization, SSO, OAuth/OIDC, SAML, federation, SCIM, API security, token handling, secrets management, least privilege, and SaaS security posture management.
  • Strong experience evaluating risks and conducting security design and architecture reviews for enterprise applications, SaaS platforms, integrations, automation platforms, AI-connected workflows, and emerging patterns such as MCP.
  • Strong experience securing modern cloud-native systems on AWS and/or GCP, with familiarity with audit logging, encryption, access control, data retention, and incident response.
  • Ability to balance hands-on technical execution with mentoring, ownership, accountability, and measurable security improvements.
  • Excellent written and verbal communication skills, including the ability to influence without authority and translate technical risk into actionable guidance.