Senior Corporate Security Engineer

Walden Robotics

• $135K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in information security with hands-on operational experience.
  • Demonstrated experience with SOC 2 compliance, including evidence collection and working with auditors.
  • Hands-on experience with EDR platforms like CrowdStrike, including policy tuning.
  • Experience leading security incident responses from investigation to post-incident review.
  • Proficient in vulnerability management across various systems and applications.
  • Experience performing actionable security assessments of products and vendors.
  • Working knowledge of cloud security concepts, particularly on AWS.

Responsibilities

  • Own the daily operation of the CrowdStrike Falcon stack and related security tools.
  • Triage alerts and develop runbooks for common alert classes to reduce noise.
  • Lead technical responses for security incidents, coordinating across IT and engineering.
  • Run vulnerability management programs, including scanning and patch coordination.
  • Conduct vendor security assessments and maintain a third-party risk inventory.
  • Draft and maintain security policies and track compliance across systems.
  • Build and run the security awareness program, including training and phishing simulations.

Benefits

  • Company-subsidized insurance programs.
  • 401(k) with company match.
  • Flexible PTO.
  • Daily lunch provided.
  • Equity in the company.
Full Job Description
Position Summary:

We're looking for a Senior Corporate Security Engineer to be our first dedicated information security hire. Reporting to the Head of IT & Infrastructure, you will run the day-to-day operation of our corporate security program: compliance and audit readiness, security operations and incident response, vulnerability management, security assessments, and the security awareness program. This is a hands-on execution role with real program ownership and latitude to choose tooling, write policy, and shape how the function runs day to day. We're looking for someone who can move between writing a detection rule in the morning and walking an auditor through evidence in the afternoon.

Expectations:

In this role, you are expected to:

  • Own complex work end-to-end, including cross-functional efforts. You take a program area from ambiguous problem to operating outcome - scoping, sequencing, and driving it across IT, engineering, and leadership without needing the path defined for you.
  • Act as the subject-matter expert and communicate clearly across the org. You are the go-to authority on security at Walden Robotics, and you translate risk and technical findings into decisions that non-technical stakeholders and leadership can act on.
  • Mentor teammates and raise the quality bar. You set standards for how security work is done here and lift the people around you - reviewing others' work, sharing judgment, and improving how the whole team operates.
  • Align your work to Walden Robotics' broader mission. You connect security decisions to company goals and make pragmatic trade-offs that move the business forward rather than applying controls for their own sake. You will work closely with the Product Security Engineer to ensure that corporate and product security initiatives are complimentary and aligned.

Core Responsibilities:

Security Operations, Incident Response & Vulnerability Management

  • Own the day-to-day operation of our CrowdStrike Falcon stack, including the Next-Gen SIEM, EDR policy, detections, and integrations.
  • Triage alerts, tune detection content, and reduce noise; develop runbooks for the most common alert classes.
  • Serve as the lead technical responder for security incidents: investigate, execute containment, coordinate the technical response across IT and engineering, and write the post-incident report, working closely with the Head of IT on incident command and org-wide coordination.
  • Serve as the primary point of contact for CrowdStrike's managed services and incident response team, directing their day-to-day engagement.
  • Plan and run periodic tabletop exercises with IT, engineering, and leadership; capture and close gaps.
  • Run the vulnerability management program day to day - scanning cadence, patch coordination, exception tracking - across corporate endpoints, SaaS applications, and identity systems.
  • Bring prioritized findings and risk-based recommendations to the Head of IT for final sign-off.

Security Assessments & Technical Risk

  • Run vendor and SaaS third-party security assessments end-to-end - intake, technical review, findings - and bring a clear recommendation to the Head of IT for final sign-off.
  • Maintain the third-party risk inventory and coordinate annual re-reviews of critical vendors.
  • Perform technical security reviews of internal systems and configurations, including identity, network, cloud, and endpoint configurations.
  • Partner with engineering on threat modeling for new product and platform work; provide pragmatic, actionable findings rather than blocking checklists.
  • Lead threat modeling for corporate IT systems and infrastructure changes - model the environment, prioritize risks, and drive mitigation with IT and engineering owners.
  • Implement and maintain the corporate AWS account's IAM baseline, logging, and hardening day to day, working with the Head of IT to set and evolve the target posture.
  • Own security review and risk management for corporate AI usage - SaaS AI feature adoption, employee AI tool usage - including practical guidance for safe adoption.

Compliance, Risk & Audit Readiness

  • Own day-to-day execution of our SOC 2 compliance program for our corporate systems.
  • Draft and maintain security policies, standards, and procedures, and work with control owners to get them adopted.
  • Track control evidence collection, gap remediation, and audit readiness; serve as the operational counterpart to our auditors and external GRC consultants.
  • Track and report on policy compliance across the fleet, including MDM enrollment, EDR coverage, patch state, encryption, and identity hygiene; drive remediation with IT and engineering owners.
  • Maintain the risk register and run periodic risk reviews; bring trends and mitigation recommendations to the Head of IT.

Security Awareness & Enablement

  • Build and run the security awareness program: new-hire onboarding security training, annual refreshers, and targeted training (phishing, data handling, secure development practices).
  • Run phishing simulations and use results to inform training and process changes.
  • Maintain user-facing security documentation and self-service guidance; treat training as a product to be improved based on feedback and outcomes.

Vendor & Consultant Coordination

  • Direct day-to-day work with our existing external information security consultants across strategy, audit preparation, and offensive testing; assign work, review deliverables, and integrate findings into the program.
  • Manage relationships with security tooling vendors: licensing, support escalations, and renewals.
  • Escalate scope, performance, or budget concerns to the Head of IT.

Required Qualifications:

  • 5+ years in information security with progressive responsibility, including hands-on operational work and program ownership.
  • Demonstrated experience preparing for or maintaining a SOC 2 program in a growing organization, including evidence collection, control design, and working with external auditors.
  • Hands-on experience with an EDR platform (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or similar), including policy tuning and detection content.
  • Hands-on experience with a SIEM or modern logging/detection platform, including writing or tuning detection rules and triaging alerts end-to-end.
  • Experience leading the response to security incidents end-to-end, from investigation through post-incident review.
  • Experience running vulnerability management programs (scanning, prioritization, remediation coordination) across endpoints, SaaS, or identity systems.
  • Experience performing security assessments of products, services, or vendors, with the judgment to produce actionable findings rather than checklists.
  • Working knowledge of identity (SSO, SCIM, conditional access) with a provider like JumpCloud, Okta, or Entra ID, including how to evaluate and harden tenant configuration.
  • Working knowledge of cloud security concepts on AWS or another major public cloud (IAM, logging, basic service hardening) - ideally hands-on experience implementing an account-level IAM/logging baseline.
  • Working knowledge of corporate networking (DHCP, DNS, VLANs, VPN, Wi-Fi, firewall rules) sufficient to read configurations and reason about controls.
  • Comfort with light scripting (Python, PowerShell, Bash) for automation, evidence collection, and one-off analysis.
  • Clear written and verbal communication, especially translating risk and technical findings for non-technical staff and leadership.
  • An inquisitive mindset, comfort with ambiguity, and the ability to operate independently while seeking guidance when appropriate.

Preferred Qualifications:

  • Experience as the first or among the first dedicated security hires at a growth-stage company.
  • Experience supporting highly technical engineering staff (robotics, embedded, ML, or similar) and understanding their workflows enough to make security work for them.
  • Experience with CrowdStrike Falcon specifically, including Next-Gen SIEM, Falcon Complete, and Identity Protection.
  • Experience with Cisco Meraki networking and Fortigate firewalls.
  • Experience with virtualization platforms (Proxmox, VMware, or similar) and on-prem compute security.
  • Experience administering Google Workspace from a security perspective (DLP, alerting, audit log analysis).
  • Experience with infrastructure-as-code patterns and tooling (Terraform, Pulumi, Ansible, or similar) applied to security controls.
  • Experience with Tailscale or another zero-trust / WireGuard-based remote access tool.
  • Experience with MDM tooling (Fleet, JumpCloud, Intune, JAMF, or similar) from a compliance and policy perspective.
  • Experience leading or substantially contributing to threat modeling programs for corporate/IT environments.
  • Relevant certifications (CISSP, CISM, GIAC, AWS Security Specialty, OSCP, or similar). Certifications are not required; demonstrated capability matters more.
  • Experience working alongside AI tooling (Claude, ChatGPT, Gemini) both for personal productivity and for evaluating their secure adoption in the workplace.

Logistics:

  • Location: This role is on-site at our Cambridge, MA office. It is not available for remote work.
  • Travel: Occasional travel to other Walden Robotics sites (e.g., San Francisco) for site assessments, audits, and incident response coverage. Expect
  • Hours & On-Call: Standard business hours. Best-effort after-hours response for security incidents today; we will move to a formal on-call rotation as the team and company grows.
  • Physical Requirements: Ability to lift up to 40 lbs (servers, networking gear), work on ladders, and perform work in network closets, IDFs, and lab spaces as part of physical security and infrastructure work.


Walden Robotics offers a competitive total compensation program, including salary, annual cash bonus, company equity, company-subsidized insurance programs, 401(k) with company match, flexible PTO, daily lunch, and other benefits. The pay ranges noted on our posts are for salary only.

The pay range for this role is:

135,000 - 180,000 USD per year (BOS)

Similar Jobs

More Jobs at Walden Robotics

More Information Technology Jobs

Find similar Senior Corporate Security Engineer jobs: