Enterprise Security Engineer
Trm Labs
| Company | Trm Labs |
| Category | Engineering |
| Location | United States |
| Remote | Remote |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 29 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
BUILD A SAFER WORLD.
TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.
Job Summary:
- TRM's Enterprise Security Team secures the identities, endpoints, and core SaaS infrastructure used by every employee and contractor, so the company can move fast without taking unnecessary risk. We operate at the intersection of IT and Security: building secure-by-default systems, automating controls, and reducing operational toil through engineering. We use AI tooling heavily as part of how we work, and we expect the same of the engineers who join us.
- We're looking for an Enterprise Security Engineer to help harden and scale our corporate environment. You'll design and ship identity, endpoint, and SaaS security improvements; codify controls using automation and infrastructure-as-code; and partner closely with Security, Compliance, and engineering teams to continuously raise the security baseline while preserving a great employee experience.
The impact you will have here:
- Engineer secure-by-default endpoint baselines for macOS and Windows, including encryption, firewall, application controls, device compliance, and configuration standards.
- Automate and scale identity and access controls in Entra ID and Google Workspace (SSO, SCIM, conditional access, privileged access workflows, access reviews, joiner/mover/leaver).
- Codify security controls as code (Terraform/configuration profiles/policy-as-code), with peer review, change history, testing/rollback, and measurable outcomes.
- Build and maintain automations and integrations (e.g., n8n/SlackOps/APIs/scripts) that reduce manual access grants, speed up control changes, and eliminate repetitive workflows.
- Apply AI tooling (Claude Code, agentic workflows, MCP integrations, LLM-backed automations) to accelerate your own engineering and triage work, and help secure how the rest of the company uses AI: sanctioned tooling, data handling guardrails, and visibility into shadow AI.
- Harden SaaS and collaboration platforms by reducing unmanaged apps and enforcing strong authentication, least privilege, sharing controls, and data protection guardrails.
- Improve visibility and detection by ensuring loggingr endpoint, identity, and key SaaS applications (e.g.,Defender/Sentinel and vendor logs where relevant).
- Drive vulnerability and configuration drift reductio targets, remediation pipelines, and reporting that
leadership can act on.
- Partner with compliance and risk stakeholders to produce evidence, document controls, and operationalize requirements without
creating brittle, manual processes.
- Participate in an on-call rotation (every ~3 weeks) identity, endpoint security, and critical enterprise systems.
What we're looking for:
- Demonstrated experience engineering and scaling endpor Intune) and endpoint security controls for macOS and
Windows.
- Strong IAM foundation: hands-on experience with Entra ID (conditional access, SSO, access governance) and Google Workspace and/or
Microsoft 365 administration.
- Proven ability to automate real operational workflow (Bash, PowerShell, Python, etc.).
- Fluency with AI-assisted engineering: you already reach for coding agents and LLM tooling to build, review, and investigate faster,
and you can judge where their output needs verification
- Strong troubleshooting and systems thinking: identity, endpoint, network controls, and SaaS integrations.
- Comfort balancing security and usability using a risk-based approach, communicating tradeoffs clearly to technical and non-technical
stakeholders.
Strong Plus:
- Working knowledge of operating Infrastructure-as-Code / configuration-as-code (Terraform pr
991,236 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →