Oh My JobFind Jobs
Company
  • About Us
  • Blog
  • Contact
Tools
  • Paycheck Calculator
Legal
  • Terms of Service
  • Privacy Policy
  • California Privacy Rights
For Employers
Post a Job

Enterprise Security Engineer

Benchling
Benchling
San Francisco, CA
Jul 14, 2026
189K – $256K • Offers Equity
FullTime

Job Description

Benchling is seeking an Enterprise Security Engineer to build and mature a best-in-class security program focused on real-world defense and automation. You'll own the organization's zero trust strategy, identity access management, and endpoint security across a platform trusted by over 200,000 scientists globally, including more than half of the world's top 50 biopharma companies.

About the Role

Join a security team building comprehensive, automation-first defenses for sensitive biotech R&D data. This role emphasizes pragmatic security outcomes—continuous verification, least-privilege access, and AI-assisted tooling—rather than checkbox compliance. You'll drive identity strategy and access controls across cloud, on-premises, and SaaS environments.

Responsibilities

  • Lead the organization's zero trust architecture strategy end to end, integrating identity, device health, network context, and application sensitivity into continuous access decisions
  • Design and operate least-privilege access patterns, Just-in-Time (JIT) access provisioning, and Privileged Access Management (PAM) systems
  • Deploy and maintain Mobile Device Management (MDM) infrastructure for macOS fleets, feeding device compliance directly into zero trust policy enforcement
  • Enforce single sign-on policies, audit and restrict OAuth scopes, and govern third-party application access
  • Build detection and enforcement processes for shadow IT, unauthorized OAuth grants, and SaaS tools circumventing identity controls
  • Evaluate and deploy AI-native security tooling to reduce analyst toil and close coverage gaps faster than traditional approaches
  • Define and enforce security standards for AI agent and LLM service identities, including scoped API keys, short-lived credentials, and workload identity federation
  • Develop and enforce CIS and NIST-aligned configuration baselines across the infrastructure
  • Eliminate recurring manual security work through infrastructure automation and AI-assisted tooling

Requirements

  • 5+ years in security engineering or Identity and Access Management (IAM) roles
  • Deep hands-on expertise with identity providers—preferably Okta—including SSO, SCIM, MFA, lifecycle management, and non-human identity (NHI) governance
  • Demonstrated experience implementing zero trust architecture in production environments, covering continuous verification, device trust integration, and least-privilege enforcement across an organization
  • Strong command of identity protocols: SAML, OIDC, OAuth 2.0, and SCIM
  • Proficiency managing macOS endpoints at scale using Fleet or equivalent MDM platforms
  • Foundational cloud IAM experience with at least one major provider (AWS, GCP, or Azure), including audit, scoping, and remediation of identity issues
  • Proven track record building automation to eliminate recurring manual work
  • Scripting proficiency in at least one language, preferably Python
  • Strong communication skills across technical teams and non-technical stakeholders
  • Solid understanding of operating systems fundamentals (macOS, Linux, Windows)

Preferred Qualifications

  • Hands-on experience with Zero Trust Network Access (ZTNA) platforms such as Cloudflare Access, Zscaler Private Access, Tailscale, or similar
  • Active use of AI coding assistants (GitHub Copilot, Claude, Cursor, or similar) to increase engineering velocity
  • Experience securing AI and ML service identities or governing LLM API integrations
  • Familiarity with PAM solutions including HashiCorp Vault, AWS Secrets Manager, or Okta Privileged Access
  • Okta Certified Administrator, Okta Certified Consultant, or equivalent credential

Benefits and Work Arrangement

Benchling offers a hybrid work model with a 3-day weekly on-site expectation (Monday, Tuesday, Thursday) in San Francisco, CA.

Apply now
Share: