Benchling
Enterprise Security Engineer
San Francisco, CA
Sponsorship not specifiedDetected 7 days ago
PythonAWSGCPAzureLinuxOAuthMachine LearningLLMsAgentic AICybersecurityVPNZero TrustCommunication
About the role
- Our focus is on providing value to the organization by emphasizing real world security and embracing automation and AI.
- We're looking for engineers who are excited to apply their expertise to our mission of securing some of society's most sensitive data.
Responsibilities
- Design and maintain least-privilege access patterns, Just-in-Time (JIT) access, and Privileged Access Management (PAM) controls
- Deploy, configure, and maintain MDM infrastructure for the macOS fleet, ensuring device compliance feeds directly into zero trust access policy decisions
- Build processes and tooling to detect shadow IT, unauthorized OAuth app grants, and SaaS tools that bypass identity controls
- Develop and enforce CIS/NIST-aligned configuration baselines
Requirements
- 5+ years in a security engineering or IAM-focused role
- Deep, hands-on IdP expertise (preferably Okta) - SSO, SCIM, MFA, Lifecycle Management, and NHI management are all areas you can speak to with depth and demonstrate in practice
- Strong working knowledge of identity protocols: SAML, OIDC, OAuth 2.0, and SCIM
- Proficiency managing macOS endpoints at scale using Fleet or an equivalent MDM platform
- Scripting proficiency in in at least one language, preferably Python
- Excellent communication skills, with the ability to engage effectively with both technical teams and non-technical stakeholders.
- Strong understanding of operating systems fundamentals (MacOS/Linux/Windows)
- Demonstrated experience implementing zero trust architecture in practice - not just familiarity with the framework, but hands-on delivery of continuous verification, device trust integration, and least-privilege enforcement across an organization
Nice to have
- Experience with ZTNA platforms (Cloudflare Access, Zscaler Private Access, Tailscale, or similar) and the operational patterns around replacing VPN with identity-aware access
- Hands-on use of AI coding assistants (Copilot, Claude, Cursor, or similar) to increase velocity
- Experience governing AI/ML service identities or securing LLM API integrations
- Familiarity with PAM solutions such as HashiCorp Vault, AWS Secrets Manager, or Okta Privileged Access
- Okta Certified Administrator, Okta Certified Consultant, or equivalent certification
Skills
- When a breakthrough is delayed, the world waits.
- Getting a molecule from discovery to patients, or a crop from lab to field, involves thousands of slow, manual, disconnected steps.
- AI has the potential to change this, compressing decades of R&D work into years.
- But that only happens when clean, structured scientific data and AI are built into how science gets done.
- Benchling is the AI platform for biotech R&D.
Benefits
- Drive the organization's zero trust strategy end to end - treating identity, device health, network context, and application sensitivity as continuous inputs to access decisions rather than one-time gates
- Evaluate and deploy AI-native security tooling where it demonstrably reduces analyst burden or closes coverage gaps faster than traditional approaches
Apply directly at Benchling →Create a free account for alerts like thisView Benchling immigration profile
This listing is sourced directly from Benchling's careers page and normalized into a canonical job model.