Role at a GlanceGecko is seeking an Enterprise Security Engineer to help build and operate the shared systems that protect our people, devices, applications, and sensitive data.
You will sit within InfoSec Engineering and partner closely with IT Engineering. Your primary focus will be workforce endpoint and device security, identity security, SaaS and OAuth governance, enterprise detections, and the protection of regulated data.
Our goal is to eliminate friction: solve shared security and technology problems so everyone else can focus on their unique roles. Security and compliance should create trustworthy paths for the company to move faster and remain in compliance, not unnecessary barriers that teams must work around.
Responsible use of AI tools is an important example. Gecko should be able to benefit fully from emerging technology without misusing sensitive data or creating unacceptable security, privacy, contractual, or compliance risk. This role will help establish the systems, guardrails, and guidance that make responsible adoption possible.
What You Will Do- Build, configure, and operate endpoint-management, device-compliance, browser-security, and endpoint detection and response controls; harden workforce devices and shared enterprise systems.
- Own and improve identity security-including Okta policies, MFA, Conditional Access, and lifecycle controls-and establish practical governance for SaaS applications, OAuth access, browser extensions, AI tools, and other third-party technology.
- Create clear, usable paths that let employees adopt approved AI tooling and other technology while protecting regulated and sensitive data and meeting security, privacy, contractual, and compliance obligations.
- Translate requirements into effective configurations and workflows, partnering closely with IT Engineering to solve shared problems, reduce recurring friction, and make controls easy to operate.
- Build and tune enterprise detections; evaluate alerts and control gaps; lead corporate-side incident response; make proportionate risk decisions and coordinate remediation with the teams that own the affected systems.
- Partner with Product Security, Cloud Infrastructure, IT, and Facilities when enterprise-security concerns intersect with applications, cloud services, engineering systems, or physical security.
- Establish and maintain governance for the adoption and use of AI tools and other rapidly emerging workplace technologies, ensuring security, privacy, and compliance requirements are met.
- Travel up to 20% to Gecko offices and other locations as needed to support enterprise security initiatives, physical security projects, incident response, and cross-functional collaboration.
Technologies and Security frameworks You Should Be Familiar WithExperience with every technology or framework is not required. Relevant technologies include:
- Identity management (e.g., Okta, Onelogin, Active Directory)
- MDM systems (e.g., Jamf, Intune, NinjaOne)
- EDR/MDR tools (e.g., CrowdStrike, TrendMicro, SentinelOne)
- AI management (e.g., Claude, ChatGPT, Cursor, Grok)
- Government security frameworks (FedRAMP, CMMC, NIST 800-171, NIST 800-53, CUI handling)
- Commercial security frameworks (SOC2 Type II, ISO 27001, ISO 42001)
About You Required Skills- 3+ years of experience in Enterprise Security Engineering, Security Engineering, IT Security, or a related hands-on security engineering role.
- Hands-on experience administering endpoint management and endpoint detection and response (EDR) solutions in production environments.
- Experience administering or securing identity and access management (IAM) platforms, including SSO, MFA, or lifecycle management
- Experience evaluating, governing, or administering SaaS applications, OAuth integrations, and enterprise security controls.
- Experience working with regulated, customer-protected, or other sensitive data (e.g., CUI, HIPAA, PCI, SOC 2).
- Strong systems configuration, troubleshooting, workflow design, and operational ownership skills.
- Demonstrated ability to balance security and compliance requirements with business needs and user experience.
- Excellent written and verbal communication skills, with the ability to partner effectively across Security, IT, Engineering, Compliance, Legal, and other cross-functional teams.
Preferred Skills- Experience governing AI tools or other rapidly adopted workplace technology.
- Experience in government, defense, critical infrastructure, or another highly regulated industry, including familiarity with CUI, CMMC, FedRAMP, NIST, SOC 2, or ISO 27001.
- Experience administering CrowdStrike Falcon, Microsoft Defender, SentinelOne, or another enterprise EDR platform.
- Experience administering Okta, Microsoft Intune, Jamf, or comparable identity and endpoint management platforms.
- Experience with DLP, CASB, browser security, or SaaS/OAuth governance technologies.
- Experience automating security or IT workflows using Python, PowerShell, Bash, or similar scripting languages.
- Experience working on a small, high-growth, or startup team where security processes, tooling, and ownership were built from the ground up.