368,746open jobs
9,444companies
47,506added this week
Browse all
Salary
$180k – $200k per year
Location
Remote (United States)
Seniority
Senior · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Onebrief is collaboration and AI-powered workflow software designed specifically for military staffs. Onebrief makes the staff as a whole superhuman — faster, smarter, and more efficient — to ultimately support stronger decision-making.

Consequential Work. Dedicated People.

About Onebrief

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination.

Military planning is complex by nature, requiring teams to coordinate information, people, and decisions across systems and locations. Onebrief brings planning, collaboration, simulation, and AI into one connected environment, helping teams test strategies, adapt to changing conditions, and make decisions with greater clarity when the stakes are real.

We are a distributed team of builders from military, operational, and technology backgrounds who care deeply about improving how important work gets done. Some team members work remotely, while others work directly alongside customers in operational environments around the world.

Founded in 2019, Onebrief is backed by leading investors including General Catalyst, Battery Ventures, Insight Partners, Sapphire Ventures, and Human Capital. Valued at more than $2 billion, we continue to invest in product innovation, AI capabilities, and team growth.

Why This Role Exists

Onebrief is growing, and the systems our employees rely on need to remain secure, resilient, and audit-ready as the company scales. We’re hiring a Corporate Systems Security Engineer to help build and operate the technical security foundations that protect our corporate environment.

This is a hands-on security engineering role focused on owning and improving security across endpoints, identity, SaaS applications, browsers, Zero Trust infrastructure, and the broader corporate security stack. You’ll work at the intersection of security engineering, systems configuration, and automation-turning security requirements into technical controls that are measurable, repeatable, and difficult to drift away from.

A major focus of this role is reducing manual security operations. Rather than repeatedly collecting the same evidence or discovering configuration drift during an audit, we want to build systems that continuously enforce our security expectations and produce trustworthy evidence of their effectiveness.

You’ll work closely with Corporate IT, Security Operations, GRC, and application owners, but your mandate is security: understanding how systems can be abused or misconfigured, establishing secure defaults, and ensuring the controls protecting Onebrief continue to operate as intended.

What You’ll Do

You’ll help own and mature the security systems protecting Onebrief’s corporate environment.

Core responsibilities include:

  • Own and improve enterprise security technologies across areas such as EDR, SIEM, MDM, Zero Trust, identity, browsers, and SaaS applications, including deployment, configuration, integrations, monitoring, and lifecycle management.

  • Establish and enforce secure configuration baselines across corporate systems, continuously identifying configuration drift and building durable mechanisms to remediate it.

  • Build API-driven, infrastructure-as-code, or workflow-based automation that connects security systems, eliminates repetitive security work, and makes control enforcement and evidence collection more reliable.

  • Partner with Corporate IT and application owners to securely deploy and operate endpoints, applications, and SaaS platforms while maintaining appropriate security boundaries and technical controls.

  • Improve security telemetry by integrating corporate systems and applications with centralized monitoring and ensuring the signals necessary to detect vulnerabilities, misconfigurations, and suspicious activity are available and actionable.

  • Translate security and compliance requirements-including CMMC 2.0 and NIST-aligned controls-into practical technical implementations that can be continuously validated and supported with defensible evidence.

Minimum Qualifications

  • 4+ years of hands-on experience in security engineering, enterprise security, systems security, or a closely related technical role.

  • Experience securing identity, SaaS, or Zero Trust environments and understanding how configuration decisions affect enterprise security.

  • Experience building security automation using APIs, workflow automation platforms, infrastructure-as-code, scripting, or configuration-management technologies.

  • Experience deploying, administering, or owning endpoint security and detection technologies such as EDR and SIEM platforms, including integrating security telemetry into centralized monitoring.

  • Experience administering MDM or endpoint-management platforms to enforce security configurations, and maintain endpoint baselines.

  • Ability to evaluate technical requirements through a security lens, identify risk in proposed configurations, and work across technical teams to implement practical controls without losing sight of the security objective.

Preferred Qualifications

  • Experience owning or administering technologies such as CrowdStrike, Zscaler, enterprise MDM, identity providers, SIEM platforms, or comparable enterprise security systems.

  • Experience implementing technical controls aligned with CMMC 2.0, NIST 800-53, CIS/STIGs, or similar security frameworks.

  • Experience building integrations between SaaS or security platforms using REST APIs, webhooks, or automation platforms such as Github Actions or Okta Workflows.

  • Experience securing corporate environments in regulated, government, defense, or other high-assurance organizations.

Indicators of Success

This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.

A successful Corporate Systems Security Engineer will:

  • Become a trusted technical owner for key components of Onebrief’s corporate security stack, with clear understanding of their architecture, configuration, integrations, and security posture.

  • Reduce configuration drift across corporate endpoints, SaaS applications, identity systems, and security tooling through measurable baselines and automated enforcement.

  • Improve the reliability and coverage of security telemetry by integrating critical corporate systems with centralized monitoring and addressing meaningful visibility gaps.

  • Replace recurring manual security and compliance processes with automation that improves control consistency and produces reliable, reusable evidence.

  • Identify and remediate systemic security weaknesses rather than treating individual findings as isolated configuration issues.

  • Improve Onebrief’s ability to demonstrate that corporate security controls are continuously operating as intended, reducing the effort required to prepare for audits and assessments.

Tools, Systems & Technologies

The specific technology stack will continue to evolve. Relevant areas include:

Endpoint & Detection: EDR (crowdstrike), vulnerability management, SIEM (splunk), endpoint telemetry

Device Management: MDM (Workspace One), application deployment, configuration profiles, endpoint baselines

Identity & Access: Identity providers (Okta), SSO, MFA, lifecycle management, conditional access

Network & Zero Trust: Zero Trust access platforms (Zscaler), secure web gateways, browser security, network security controls

SaaS Security: Enterprise SaaS administration, configuration management, logging, access controls, API integrations

Automation: REST APIs, webhooks, no-code/low-code security automation, infrastructure-as-code, configuration management

Security & Compliance: CMMC 2.0, NIST 800-53, security baselines, continuous control validation, audit evidence

Notice to Third Party Recruitment Agencies

Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,746 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$164k – $307k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp
C++
Assembly
Assembly
WinDbg
DevOps
VMWare
Cybersecurity
Zero Trust
Zscaler
Apply
$88k – $199k per year (Estimated) • In office • 3+ years exp • Hudson
Python
DevOps
Ansible
AWS
Azure
GCP
Kubernetes
Terraform
Cybersecurity
CIS Benchmarks
SOC 2
Zero Trust
Apply
$77k – $167k per year (Estimated) • Remote/Hybrid • Internship • 5+ years exp
DevOps
AWS
Azure
GCP
Cybersecurity
Zero Trust
Zscaler
Apply
Lead IAM Engineer 6 hours ago
$117k – $254k per year (Estimated) • In office • Full-Time • 10+ years exp • Jersey City
DevOps
AWS
Azure
Docker
GCP
IAM
Kubernetes
Cybersecurity
GDPR
HIPAA
Okta
Ping Identity
SOC 2
Zero Trust
Apply
$191k – $297k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • Seattle
AI/ML
AI Agents
DevOps
AWS
Azure
CI/CD
GCP
IAM
Platform Engineering
Cybersecurity
Least Privilege
Microsoft Entra ID
PCI DSS
Threat Modeling
Zero Trust
Apply
$185k – $230k per year • Remote • Full-Time
AI/ML
AI Agents
Knowledge Graph
DevOps
Amazon EKS
AWS
CI/CD
Docker
Kubernetes
Vector
GitHub
Apply
AI Product Designer 5 days ago
$160k – $230k per year • Remote • Full-Time
AI/ML
AI Agents
Apply
$205k – $230k per year • Remote • Full-Time • 12+ years exp
Node JS
TypeScript
JavaScript
Databases
PostgreSQL
Redis
Frontend
React.js
Vite
DevOps
AWS
CI/CD
Kubernetes
Terraform
Cybersecurity
FedRAMP
Keycloak
SOC 2
Apply
$150k – $185k per year • Remote • Full-Time • 2+ years exp
C#
C++
Python
DevOps
Azure
Azure DevOps
CI/CD
Docker
GitHub Actions
Grafana
Kibana
Kubernetes
Prometheus
Shift-Left
GitHub
Cybersecurity
Shift-Left Security
QA
JMeter
k6
Apply
$180k – $220k per year • Remote/Hybrid • Full-Time • 5+ years exp
Bash
Python
TypeScript
Node JS
JavaScript
Node JS
Commander.js
DevOps
Ansible
AWS
CI/CD
Datadog
GitHub Actions
GitLab CI
GitOps
Grafana
Hyper-V
Istio
Jenkins
kubectl
Kubernetes
Linkerd
Loki
Prometheus
Proxmox VE
Service Mesh
Terraform
VMWare
GitHub
GitLab
Apply
See all jobs
This is one of many
368,746 more open roles from verified company boards, updated every day.