Enterprise Security Engineer

TRM Labs
      30+ days ago

      Job Description

      Build a Safer World.

      TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

      TRM's Enterprise Security team secures the identities, endpoints, and core SaaS infrastructure used by every employee and contractor, enabling the company to move quickly without taking unnecessary risk. We operate at the intersection of IT and Security, building secure-by-default systems, automating controls, and reducing operational toil through engineering.

      We use AI tooling extensively as part of how we work, and we expect the same of the engineers who join us.

      We're looking for an Enterprise Security Engineer to help harden and scale our corporate environment. You'll design and deliver identity, endpoint, and SaaS security improvements; codify controls using automation and infrastructure-as-code; and partner closely with Security, Compliance, and Engineering teams to continuously raise our security baseline while preserving an excellent employee experience.


      The impact you will have here

      • Engineer secure-by-default endpoint baselines for macOS and Windows, including encryption, firewall, application controls, device compliance, and configuration standards.

      • Automate and scale identity and access controls in Microsoft Entra ID and Google Workspace, including SSO, SCIM, Conditional Access, privileged access workflows, access reviews, and joiner/mover/leaver processes.

      • Codify security controls as code using Terraform, configuration profiles, and policy-as-code, with peer review, testing, rollback capabilities, change history, and measurable outcomes.

      • Build and maintain automations and integrations (e.g., n8n, SlackOps, APIs, and scripts) that reduce manual access grants, accelerate control changes, and eliminate repetitive workflows.

      • Apply AI tooling (Claude Code, agentic workflows, MCP integrations, and LLM-backed automations) to accelerate engineering and triage work while helping secure how the rest of the company uses AI through sanctioned tooling, data handling guardrails, and visibility into shadow AI.

      • Harden SaaS and collaboration platforms by reducing unmanaged applications and enforcing strong authentication, least privilege, sharing controls, and data protection guardrails.

      • Improve visibility and detection by ensuring logging from endpoints, identity providers, and key SaaS applications is integrated into Microsoft Defender, Microsoft Sentinel, and other relevant security platforms.

      • Drive vulnerability and configuration drift reduction through remediation pipelines, automation, metrics, and reporting that leadership can act on.

      • Partner with Compliance and Risk stakeholders to produce evidence, document controls, and operationalize requirements without creating brittle or manual processes.

      • Participate in an approximately one-week-on, every-three-weeks on-call rotation supporting identity, endpoint security, and critical enterprise systems.

      What we're looking for

      • Demonstrated experience engineering and scaling endpoint management platforms (such as Microsoft Intune) and endpoint security controls for macOS and Windows.

      • Strong identity and access management (IAM) foundation with hands-on experience administering Microsoft Entra ID (Conditional Access, SSO, Access Governance) and Google Workspace and/or Microsoft 365.

      • Proven ability to automate operational workflows using scripting languages such as Bash, PowerShell, or Python.

      • Fluency with AI-assisted engineering. You already leverage coding agents and LLM tooling to build, review, troubleshoot, and investigate more effectively, while knowing when human verification is required.

      • Strong troubleshooting and systems-thinking skills across identity, endpoints, networking, security controls, and SaaS integrations.

      • Ability to balance security and usability using a risk-based approach and clearly communicate tradeoffs to both technical and non-technical stakeholders.

      Strong Plus

      • Experience managing infrastructure-as-code or configuration-as-code, preferably Terraform, with familiarity in policy-as-code and configuration profiles.

      • Security incident response and countermeasure experience.

      • Security Operations Center (SOC) experience.

      • Experience securing or governing enterprise AI adoption, including AI usage policies, DLP for AI tools, and agent/MCP access governance.

      Compensation

      Individual compensation is determined by skills, qualifications, experience, and location. The compensation details below reflect the U.S. base salary range for this role.

      • Base salary: $180,000–$200,000 USD

      • Equity: This role is also eligible to participate in TRM's equity program.

      Life at TRM

      We are building a safer world. That promise shows up in how we work every day.

      TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.

      Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.

      At TRM, you should expect:

      • Priorities and targets to change quickly as we experiment and iterate

      • Work that often requires operating with a high degree of ambiguity

      • A high level of personal ownership and accountability

      • Close collaboration across teams and functions

      • Frequent, high-touch communication

      • Creative problem solving and out-of-the-box thinking

      • A pace that rewards urgency, adaptability, and outcomes

      This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.

      We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.

      At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more: Interviewing at TRM: How We Hire and What Success Looks Like

       

      AI Fluency at TRM

      AI fluency is a baseline expectation at TRM.

      We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.

      At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:

      • Accelerate repeatable workflows

      • Structure and solve problems

      • Improve output quality

      • Increase speed and leverage

      You will be evaluated on applied AI fluency during the interview process.

      Leadership Principles

      We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.

      • Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.

      • Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday.

      • Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one‑team mindset — giving and receiving feedback to make the team stronger.

      Join our Mission

      At TRM we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.

      TRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.

      Privacy Policy and Additional Information

      By submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our .

      We collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM.

      Because our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law.

      If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at

      privacy@trmlabs.com

      .

      To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

      The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates.

      We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form.

      Recruitment agencies

      TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.

      Learn More: Company Values | Interviewing | FAQs

      Numbers & Facts

      Location
      Websitehttps://www.trmlabs.com/

      Skills

      • Application Programming Interface (API)unmatched
      • Artificial Intelligence (AI)unmatched
      • Automationunmatched
      • Bash Scriptingunmatched
      • Coachingunmatched
      • Communication Skillsunmatched
      • Compensation Managementunmatched
      • Computer Securityunmatched
      • Endpoint Securityunmatched
      • Enterprise Protectionunmatched
      • Follow Throughunmatched
      • Frequently Asked Questions (FAQ)unmatched
      • Fundingunmatched
      • Hubsunmatched
      • Identify Issuesunmatched
      • Identity Data Managementunmatched
      • Leadershipunmatched
      • MCP - Microsoft Certified Professionalunmatched
      • Mac Operating Systemunmatched
      • Machine Toolunmatched
      • Metricsunmatched
      • Microsoft Access Databaseunmatched
      • Microsoft Product Familyunmatched
      • Microsoft Windows Operating Systemunmatched
      • Network Securityunmatched
      • On Callunmatched
      • Problem Solving Skillsunmatched
      • Productivity Managementunmatched
      • Python Programming/Scripting Languageunmatched
      • Quality Managementunmatched
      • Riskunmatched
      • Scripting (Scripting Languages)unmatched
      • Security Infrastructureunmatched
      • Single Sign-On (SSO)unmatched
      • Software as a Service (SaaS)unmatched
      • Testingunmatched
      • Top Sales Repunmatched
      • Usability Engineeringunmatched
      • Windows PowerShellunmatched

      Be found by employers

      5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

      Level up your application

      Professional resume templates

      Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

      Free resume templates

      Free resume builder

      Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

      Free resume builder