Staff Corporate Security Engineer

Crusoe
San Francisco
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 8+ yearsSkills: ["Communication","Leadership","Problem-solving"]

Lead the design of the company's corporate security program, acting as the principal architect for Zero Trust, SASE, and identity-based security. Architect preventative security across SaaS platforms, device trust, and AI-enabled workflows, embedding a 'Secure by Default' mindset into the employee experience while collaborating with IT, security, and business teams to safeguard critical systems and data.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Crusoe
Crusoe
3 months ago

Staff Corporate Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Lead the design of the company's corporate security program, acting as the principal architect for Zero Trust, SASE, and identity-based security. Architect preventative security across SaaS platforms, device trust, and AI-enabled workflows, embedding a 'Secure by Default' mindset into the employee experience while collaborating with IT, security, and business teams to safeguard critical systems and data.
Location: San Francisco
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead the design and implementation of Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) architectures, replacing legacy VPNs with identity-aware, perimeter-less access models.
  • •Architect preventative SaaS security across platforms such as Google Workspace, Slack, and Okta, including CASB controls to enforce data protection and monitor unauthorized applications or extensions.
  • •Implement Binary Authorization and device trust mechanisms, leveraging hardware-backed identity (e.g., TPM, Secure Enclave) to ensure only compliant devices can access corporate systems.
  • •Design and tune Data Loss Prevention (DLP) controls across endpoints and SaaS platforms to protect intellectual property.
  • •Strengthen email security posture, including MFA enforcement and session controls to mitigate phishing and session hijacking risks.

Pay and Benefits

Equity and Bonus:Equity
Perks:EquityHealth Insurance401kParental LeaveLife InsuranceCommuter BenefitsPhone StipendTravel Allowance

Key Requirements

  • •8+ years of experience designing and implementing Zero Trust, SASE, and modern identity-based security architectures.
  • •Strong expertise in SaaS security, including CASB, DLP, and governance across platforms like Google Workspace, Okta, and Slack.
  • •Experience implementing device trust, endpoint security, and hardware-backed identity solutions.
  • •Strong understanding of identity and access management systems (SSO, SAML 2.0, OAuth, SCIM) and secure access patterns.
  • •Knowledge of email security, phishing mitigation, and session security controls.
Experience:8+ yearsSecurityCybersecurityZero trustSaseIamMfaSaas security
Skills:CommunicationLeadershipProblem-solving
Tech Stack:ZTNASASEGoogle WorkspaceSlackOktaCASBDLPTPMSecure EnclaveSSOSAML 2.0OAuthSCIMMFAMCPAI governanceIDORPrivilege escalation

Company Brief

Crusoe
Builds vertically integrated, energy-first AI infrastructure and purpose-built AI data centers (Crusoe Cloud), leveraging clean/stranded energy to power large-scale GPU compute for AI training and inference.
Industry: Data Centers
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Decacorn (USD 10B+)
Funding: Series E+
Headquarters: Denver, United States
Founded: 2018
Glassdoor
Glassdoor: 3.7
WebsiteLinkedInGlassdoor