688,090open jobs
40,138companies
97,702added this week
Browse all
Salary
$150k – $250k per year
Location
In office (San Jose)
Seniority
Senior · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Figure AI is an American robotics company founded in 2022 that develops general-purpose humanoid robots for commercial and household work. Its Figure 02 and Figure 03 machines combine custom actuators, battery systems and hands with the in-house Helix vision-language-action model, which lets one neural network drive both perception and motor control from natural-language instructions. Headquartered in San Jose, California, the company runs the BotQ manufacturing facility for high-volume production and has piloted its robots on logistics and automotive assembly work with commercial partners.

Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It's time to build!

We are looking for a Corporate Security Engineer to join the Security & Privacy team at Figure. Corporate Security owns the environment Figure's people work in: computers, identities, collaboration tools, and the company data flowing through all of it. The design and software behind our humanoid sit inside that environment. We keep access to managed devices, make them hard to compromise, and right-size what each can reach, without getting in the way of the people using them.

We are an engineering team. Controls ship as code, changes are versioned and reviewed, and posture is measured rather than asserted. This is a senior, hands-on individual contributor role. Nobody arrives deep in all of it; we want real depth in one of endpoint engineering, identity and access, or application access design, working knowledge of the rest, and room to build depth here.

Responsibilities

Endpoints and access

  • Build the endpoint hardening controls across macOS, Windows, Linux, and ChromeOS. Our fleet runs on FleetDM, an osquery-based MDM managed through GitOps: you author the control, you write the query proving it landed, and you ship both in a merge request for review.
  • Bind data access to a healthy managed device and the person it was issued to: phishing-resistant factors, session lifetimes, and device posture checks.
  • Bring AI assistants and coding agents under enterprise management: configuration and permissions delivered and verified like any other endpoint control.

Applications and third parties

  • Design application authentication, RBAC, and access lifecycle from first principles: identify what an application exposes, threat model it, propose control requirements, and guide owners to implement them.
  • Contribute what each engagement teaches to the team's default deployment playbooks: authentication, logging, and network placement.
  • Run security review and governance for SaaS and third parties: vendor assessments, OAuth grants, connector integrations, browser extensions, and data movement through the browser.

Visibility and measurement

  • Build the inventories this work depends on: application discovery, application posture management, grant tracking. Feed vulnerability management and build the controls that close what it finds.
  • Threat model the corporate attack surface as a repeatable practice and feed the results into what the team works on next. Partner with Detection and Response on telemetry and with IT on rollout.
  • Use AI where it earns its place: prepping access reviews, first-pass triage, and analysis that gets a human to a decision faster.

Requirements

  • Software engineering discipline in Python, Bash, PowerShell, or similar: integrations and internal tooling as normal work
  • Configuration-as-code and CI/CD applied to corporate infrastructure
  • Threat-modeling judgment that separates the problems worth solving from the ones existing controls already cover, and drives the former to completion
  • 6+ years in corporate or enterprise security engineering
  • Bachelor's in Computer Science, Engineering, or Information Systems, or equivalent experience

Depth required in at least one of the below, knowledge of the others

  • Endpoint security on at least two of macOS, Windows, Linux, and ChromeOS: MDM profile engineering, application allowlisting, endpoint security frameworks, and the OS internals behind them. Preferred: fleet-wide osquery telemetry, certificate-based device identity in production, a phased enforcement change shipped with a recovery plan, and devices that live off the corporate network.
  • Identity and access: IAM, SaaS security, and zero trust from fundamentals rather than vendor docs, and being able to explain a SAML, OIDC, or SCIM integration for a developer who has never built one. Preferred: mTLS, 802.1X, SSH certificate authorities, and DKIM, DMARC, and SPF in production.
  • Application access design: threat modeling what an application exposes, specifying authentication and authorization for the team building it, and designing the provisioning and revocation behind it. Preferred: securing agentic or LLM-integrated systems, including permission models, credential isolation, and egress control.

The US base salary range for this full-time position is between $150,000 - $250,000 annually.

The pay offered for this position may vary based on several individual factors, including job-related knowledge, skills, and experience. The total compensation package may also include additional components/benefits depending on the specific role. This information will be shared if an employment offer is extended.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
688,090 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Jose
Senior Data Developer 10 hours ago
$44k – $107k per year (Estimated) • Remote • Full-Time • PhD
Python
SQL
Python
pySpark
Databases
Databricks
Oracle
Delta Lake
MS SQL
Azure SQL Database
AI/ML
Spark
Airflow
Claude Code
OpenAI Codex
DevOps
Terraform
Azure
CI/CD
Git
Analytics
ETL/ELT
SSIS
Apply
$62k – $180k per year (Estimated) • Remote/Hybrid • Internship • Dublin
Python
JavaScript
C#
AI/ML
NLP
Machine Learning
DevOps
Linux
Apply
$37k – $108k per year (Estimated) • Remote • Full-Time
Databases
DynamoDB
AI/ML
LangChain
AI Agents
AWS Bedrock
RAG
DevOps
Terraform
Datadog
CI/CD
AWS
Kubernetes
Amazon EKS
AWS Lambda
Amazon ECS
Amazon CloudWatch
AWS Step Functions
Apply
$75k – $184k per year (Estimated) • Remote • 5+ years exp
Python
Java
SQL
Databases
Redis
Apache Kafka
AI/ML
LangChain
Dify
LLM
Anomaly Detection
OpenAI
Agno
DevOps
Terraform
Ansible
GCP
GitHub Actions
Azure
CI/CD
AWS
Docker
Kubernetes
AIOps
Apply
$109k – $221k per year (Estimated) • In office • Full-Time • 8+ years exp • Seoul
Python
Java
C++
DevOps
AWS
IAM
Apply
$150k – $250k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • San Jose
Python
Go
Rust
C++
DevOps
GCP
Azure
AWS
Kubernetes
Service Mesh
Cybersecurity
Zero Trust
Least Privilege
Apply
$160k – $250k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • San Jose
Python
TypeScript
DevOps
Terraform
Azure
Git
Kubernetes
Linux
QA
Playwright
Pytest
Vitest
Apply
$137k – $266k per year (Estimated) • In office • 5+ years exp • San Jose
Python
DevOps
Linux
Management
Confluence
Jira
Apply
$80k – $105k per year • In office • Full-Time • San Jose
Apply
$80k – $90k per year • In office • Internship • Master's Degree • San Jose
Python
AI/ML
Machine Learning
DevOps
Linux
Robotics
Motion Planning
Apply
$56k – $64k per year • Remote • Full-Time • 5+ years exp • San Francisco • San Jose
Chips/EDA
OpenLane
Apply
$234k – $311k per year • Equity • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • San Jose
Apply
$158k – $193k per year • In office • Full-Time • 8+ years exp • San Jose
AI/ML
AI Agents
Apply
$234k – $311k per year • Equity • Remote/Hybrid • Full-Time • Bachelor's Degree • San Jose
Analytics
Tableau
Power BI
Apply
$164k – $204k per year • Remote/Hybrid • Full-Time • 5+ years exp • San Jose
AI/ML
Model Context Protocol
Cybersecurity
Zscaler
Zero Trust
DLP
Management
Agile
Apply
See all jobs
This is one of many
688,090 more open roles from verified company boards, updated every day.