{"id":1229580,"url":"https://alion.io/job/coreweave-senior-security-engineer-enterprise-security","title":"Senior Security Engineer, Enterprise Security","company":{"id":7348,"name":"CoreWeave","domain":"coreweave.com","url":"https://alion.io/company/coreweave","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":165000,"max":242000,"currency":"USD","period":"year","gross":null,"usd_annual":242000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"CoreWeave","optional":false},{"name":"DLP","optional":false},{"name":"Google Workspace","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"NIST 800-53","optional":false},{"name":"Okta","optional":false},{"name":"Outlook","optional":false},{"name":"PoC Library","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"Slack","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"SOC 2","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-02-11T23:44:10Z","employer_posted_date":"2026-09-17","last_verified_at":"2026-09-26T23:01:38Z","board_verified":true,"closed_at":null,"days_open":227,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":227},"description":"CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at www.coreweave.com.\nWhat You’ll Do:\nThe Enterprise Security team at CoreWeave is responsible for securing how our people work every day-identity, endpoints, networks, and SaaS-so the company can move fast without compromising safety. This team owns the controls, guardrails, and automation that keep our workforce, contractors, and critical business applications protected in a modern, cloud-native environment.\nIf you’re excited about zero trust, phishing-resistant MFA, and building secure-by-default experiences that actually make people more productive, this is the team to join.\nAbout the Role:\nAs a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls that underpin CoreWeave’s workforce and enterprise stack. You’ll lead initiatives across identity, access management, device and endpoint security, and SaaS security-partnering closely with IT Engineering, Endpoint, Network, and other security teams.\nYour day-to-day will blend hands-on engineering (writing code, building integrations, tuning controls) with architecture and program ownership (setting standards, defining patterns, and driving adoption across teams). You’ll be responsible for turning high-level objectives-like “implement zero trust for workforce access” or “deploy phishing-resistant MFA at scale”-into concrete designs, automation, and measurable risk reduction.\nIn this role, you will:\nEngineer modern identity and access controls\nDefine security requirements and prototype controls for workforce identity (e.g., Okta/Entra), including SSO, MFA, conditional access, and SCIM; validate controls with IT, which owns deployment and operations.\nDefine phishing-resistant MFA requirements for high-value accounts and critical access paths (e.g., FIDO2/WebAuthn, hardware keys); assess coverage and exceptions. Prove out technical efficacy through engineering efforts (eg, PoC, back end integrations, adversarial testing).\nDefine least-privilege RBAC/IAM patterns, including roles, entitlements, JIT access, and approvals; partner with IT to close gaps and automate privilege reduction and access revocation.\nImplement zero trust for workforce and enterprise access\nDesign and deploy controls that combine user identity, device posture, network context, and application sensitivity to enforce least-privilege access.\nPartner with Network and Infrastructure teams to integrate mTLS, service identity, and policy-based access into internal services and admin interfaces.\nHelp transition from legacy perimeter models to zero trust network access (ZTNA) patterns for employees, contractors, and third parties.\nSecure SaaS and collaboration platforms\nEvaluate, onboard, and harden SaaS applications (Google Workspace, Microsoft 365, Slack, HRIS, ticketing, and other business apps) to align with enterprise security policies.\nImplement and tune controls such as SCIM provisioning, data access policies, DLP, sharing controls, and audit logging across the SaaS estate.\nPartner with business and IT owners to ensure new SaaS applications meet baseline security standards before adoption.\nHarden endpoints and the extended workforce\nCollaborate with Endpoint/IT teams to define and enforce baseline configurations for laptops, workstations, and other managed devices via MDM and EDR.\nDesign secure patterns for contractor and vendor access, including device requirements, identity separation, and time-bound access.\nSupport investigations and incident response related to identity, endpoint, and SaaS domains.\nAutomate and instrument everything you can\nBuild automation and self-service experiences for access requests, approvals, access reviews, and break-glass workflows.\nDevelop integrations between IdPs, HRIS, ticketing, and other systems to minimize manual toil and reduce identity-related error rates.\nDefine and instrument metrics for enterprise security (e.g., MFA coverage, zero trust policy enforcement, joiner/mover/leaver SLA adherence, SaaS posture).\nPartner on detection, response, and governance\nWork with Security Operations and SIEM teams to ensure robust visibility into identity, device, and SaaS activity, and to build high-signal detections.\nContribute to policies, standards, and reference architectures that encode enterprise security expectations.\nAuthor clear documentation and runbooks that make it easy for teams to consume and operate the controls you build.\nWho You Are:\nMinimum Qualifications\n5+ years of experience in enterprise security, identity and access management, or closely related security engineering roles.\nStrong, practical understanding of modern IAM concepts: SSO, federation, RBAC/ABAC, JIT access, least privilege, and separation of duties.\nHands-on experience implementing and operating SSO and workforce identity with platforms such as Okta, Entra ID, or equivalent IdPs.\nDeep familiarity with SAML, OAuth 2.0/OIDC, and SCIM, including real-world experience integrating these protocols with third-party SaaS and internal apps.\nDemonstrated experience designing and rolling out MFA, ideally including phishing-resistant approaches (FIDO2/WebAuthn, hardware security keys, device-bound authenticators, step-up authentication).\nExperience designing and deploying zero trust or context-aware access controls (e.g., device trust, network segmentation, mTLS, ZTNA) in hybrid or remote-friendly environments.\nProficiency in at least one modern scripting or programming language (e.g., Python, Go) used to build automations, integrations, or internal tooling.\nExperience securing and integrating business-critical SaaS (e.g., Google Workspace, Microsoft 365, Slack, Atlassian, HRIS, ticketing) including SCIM provisioning, access reviews, and audit log ingestion.\nFamiliarity with MDM and endpoint security tooling (e.g., Jamf, Intune, EDR platforms) and how they tie into identity and access decisions.\nExposure to SIEM/detection ecosystems (e.g., Elastic) and experience collaborating with detection & response teams on identity/endpoint/SaaS detections.\nA track record of owning cross-functional projects from design through adoption, with an emphasis on measurable risk reduction and user experience.\nPreferred\nExperience working in high-growth or hyperscale environments where security must keep pace with rapid headcount and tooling expansion.\nHands-on experience with zero trust network access or secure access products (e.g., ZTNA, secure web gateways, or identity-aware proxies).\nFamiliarity with enterprise security standards and frameworks (e.g., SOC 2, ISO 27001, NIST 800-53) and mapping enterprise controls to these requirements.\nExperience with SaaS security posture management (SSPM), CASB, DLP, or insider risk tooling focused on collaboration platforms and data access.\nExperience building or contributing to internal security tooling (e.g., access review automation, JML workflows, policy-as-code).\nParticipation in security communities, standards groups, or open-source contributions in IAM, zero trust, or enterprise security.\nWondering if you’re a good fit?\nWe believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams - even if you aren't a 100% skill or experience match. Here are a few qualities we’ve found compatible with our team. If some of this describes you, we’d love to talk.\nYou love to build secure-by-default experiences that remove friction instead of adding gates, and you think deeply about usability when you design controls.\nYou’re curious about how identity, devices, networks, and SaaS all intersect in real-world zero trust architectures-and you like “drawing the owl” where clear patterns don’t yet exist.\nYou’re an expert in turning vague risk concerns into concrete requirements, automation, and metrics, and you enjoy collaborating across Security, IT, and business teams to get it done.\nWhy CoreWeave?\nAt CoreWeave, we work hard, have fun, and move fast! We’re in an exciting stage of hyper-growth that you will not want to miss out on. We’re not afraid of a little chaos, and we’re constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: \nBe Curious at Your Core\nAct Like an Owner\nEmpower Employees\nDeliver Best-in-Class Client Experiences\nAchieve More Together\nWe support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us! \nThe base salary range for this role is $165,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). \nWhat We Offer\nThe range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.\nIn addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include:\nMedical, dental, and vision insurance - 100% paid for by CoreWeave\nCompany-paid Life Insurance \nVoluntary supplemental life insurance \nShort and long-term disability insurance \nFlexible Spending Account\nHealth Savings Account\nTuition Reimbursement \nAbility to Participate in Employee Stock Purchase Program (ESPP)\nMental Wellness Benefits through Spring Health \nFamily-Forming support provided by Carrot\nPaid Parental Leave \nFlexible, full-service childcare support with Kinside\n401(k) with a generous employer match\nFlexible PTO\nCatered lunch each day in our office and data center locations\nA casual work environment\nA work culture focused on innovative disruption\nCalifornia Applicants\nCalifornia Consumer Privacy Act \nEqual Opportunity & Accommodations\nCoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.\nAs part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: .\nExport Control Compliance\nThis position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green car...","description_format":"text","description_chars":12405,"description_truncated":true,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity","Growth opportunities","Life insurance","Parental leave","Vision insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Data Centers & Colocation","Cloud Platforms (IaaS & PaaS)","AI Compute & Inference"],"lifecycle":[{"event":"open","at":"2026-09-25T14:29:23Z"}],"liveness":{"score":37,"band":"fade","label":"Fading","p_open":1,"p_active":0.843,"p_room":0.44,"age_days":226,"expected_fill_days":154,"reasons":["conf:3","win:tail","crowd:brand"],"computed_at":"2026-09-26T05:45:00Z"},"pay":{"stated_usd_annual":242000,"is_top_pay":true},"html_url":"https://alion.io/job/coreweave-senior-security-engineer-enterprise-security","json_url":"https://alion.io/job/coreweave-senior-security-engineer-enterprise-security.json","meta":{"generated_at":"2026-09-27T01:33:25Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1431,"day_limit":5000,"remaining_today":3569,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}