Enterprise Security Engineer
Drive zero trust strategy using identity, device health, and network context
As an Enterprise Security Engineer at Benchling, you will drive the organization's zero trust strategy end to end by treating identity, device health, network context, and application sensitivity as continuous inputs to access decisions. You will design and maintain least-privilege access patterns, Just-in-Time access, and Privileged Access Management controls. You will also deploy and maintain MDM infrastructure for the macOS fleet, enforce S...
Why This Role?
Help build a best-in-class security program from the ground up with AI and automation focus
Key Responsibilities
- Drive zero trust strategy using identity, device health, network context, and application sensitivity
- Design and maintain least-privilege access, Just-in-Time access, and Privileged Access Management controls
- Deploy, configure, and maintain MDM infrastructure for macOS fleet compliance
- Enforce SSO-required policies, review and restrict OAuth scopes, and audit third-party integrations
- Build processes and tooling to detect shadow IT, unauthorized OAuth app grants, and bypassing SaaS tools
- Evaluate and deploy AI-native security solutions
Requirements
- Experience with zero trust architecture implementation
- Knowledge of identity and access management (IAM) systems
- Experience with MDM solutions for macOS fleets
- Proficiency in SSO, OAuth scope management, and third-party access auditing
- Familiarity with Privileged Access Management (PAM) and Just-in-Time access controls
- Experience building security tooling to detect shadow IT and unauthorized access
Required Skills
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
We are rebuilding biotech for the AI era. When a breakthrough is delayed, the world waits. Getting a molecule from discovery to patients, or a crop from lab to field, involves thousands of slow, manual, disconnected steps. AI has the potential to change this, compressing decades of R&D work into years. But that only happens when clean, structured scientific data and AI are built into how science gets done. Benchling is the AI platform for biotech R&D. Scientists use Benchling to design experiments, capture structured data, and run AI agents and models directly in their workflows. Over 200,000 scientists around the world trust Benchling to power their most important work, from academic labs to Sanofi, Moderna, and more than half of the world's top 50 biopharma. We’re building an AI scientist for our customers. We can’t do that if we haven’t built the muscle ourselves. AI fluency is the foundation we build on; it's core to how we work, and we're committed to helping every new hire integrate it into their day-to-day. As part of our interview process, you'll complete a brief AI-focused exercise or discussion so we can understand how you think about and use AI to drive impact in your role. Feel free to reference any tools, platforms, or workflows you use today. ROLE OVERVIEW As an Enterprise Security Engineer at Benchling you’ll be joining a team responsible for building a best-in-class security program from the ground up. Our focus is on providing value to the organization by emphasizing real world security and embracing automation and AI. We’re looking for engineers who are excited to apply their expertise to our mission of securing some of society's most sensitive data. RESPONSIBILITIES - Drive the organization's zero trust strategy end to end — treating identity, device health, network context, and application sensitivity as continuous inputs to access decisions rather than one-time gates - Design and maintain least-privilege access patterns, Just-in-Time (JIT) access, and Privileged Access Management (PAM) controls - Deploy, configure, and maintain MDM infrastructure for the macOS fleet, ensuring device compliance feeds directly into zero trust access policy decisions - Enforce SSO-required policies, review and restrict OAuth scopes, and audit third-party integration access - Build processes and tooling to detect shadow IT, unauthorized OAuth app grants, and SaaS tools that bypass identity controls - Evaluate and deploy AI-native security tooling where it demonstrably reduces analyst burden or closes coverage gaps faster than traditional approaches - Define and enforce security standards for AI agent and LLM service identities — including scoped API keys, short-lived credentials, and workload identity federation - Develop and enforce CIS/NIST-aligned configuration baselines - Meaningfully reduce manual toil through automation and, where applicable, AI-assisted tooling QUALIFICATIONS - 5+ years in a security engineering or IAM-focused role - Deep, hands-on IdP expertise (preferably Okta) — SSO, SCIM, MFA, Lifecycle Management, and NHI management are all areas you can speak to with depth and demonstrate in practice - Demonstrated experience implementing zero trust architecture in practice — not just familiarity with the framework, but hands-on delivery of continuous verification, device trust integration, and least-privilege enforcement across an organization - Strong working knowledge of identity protocols: SAML, OIDC, OAuth 2.0, and SCIM - Proficiency managing macOS endpoints at scale using Fleet or an equivalent MDM platform - Foundational cloud IAM experience across at least one major provider (AWS, GCP, or Azure) — enough to audit, scope, and remediate identity issues - Demonstrated track record of building automation that eliminated recurring manual work - Scripting proficiency in in at least one language, preferably Python - Excellent communication skills, with the ability to engage effectively with both technical teams and non-technical stakeholders. - Strong understanding of operating systems fundamentals (MacOS/Linux/Windows) PREFERRED - Experience with ZTNA platforms (Cloudflare Access, Zscaler Private Access, Tailscale, or similar) and the operational patterns around replacing VPN with identity-aware access - Hands-on use of AI coding assistants (Copilot, Claude, Cursor, or similar) to increase velocity - Experience governing AI/ML service identities or securing LLM API integrations - Familiarity with PAM solutions such as HashiCorp Vault, AWS Secrets Manager, or Okta Privileged Access - Okta Certified Administrator, Okta Certified Consultant, or equivalent certification HOW WE WORK We offer a flexible hybrid work arrangement that prioritizes in-office collaboration. Employees are expected to be on-site 3 days per week (Monday, Tuesday, and Thursday). #LI-Hybrid #BI-Hybrid #LI-CG1 Benchling welcomes everyone. We believe diversity enriches our team so we hire people with a wide range of identities, backgrounds, and experiences. We are an equal opportunity employer. That means we don’t discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We also consider for employment qualified applicants with arrest and conviction records, consistent with applicable federal, state and local law, including but not limited to the San Francisco Fair Chance Ordinance.
Salary Context
Similar Engineering roles on LokerDollar pay around $160k/yr (range $1.8k–999.999k/yr, n=643 active listings).
Hiring at Benchling
Benchling has 17 other active roles on LokerDollar and has been hiring here since Aug 11, 2026 — across Engineering.
View all Benchling openings →Openness not stated by employer — check the listing
Frequently asked questions
- Is Enterprise Security Engineer at Benchling a remote job?
- This role is based in Remote. See the listing for remote/onsite details.
- What is the salary for Enterprise Security Engineer at Benchling?
- The listed pay range for this role is $189k–256k/yr.
- What type of employment is Enterprise Security Engineer at Benchling?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at Benchling.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Remote ≠ Remote: The Skills That Open Global Work to Indonesians (2026)12,891 remote listings: the highest-paid coding skills are the most geo-locked for Indonesia-based applicants. CC BY 4.0 aggregate dataset.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Interview Radiologist Remote: What You NeedBreaking down the remote radiology interview process for USD-paying jobs, from screening to offer letter.
- Remote Radiology Jobs: August 2026 UpdateDiscover the latest remote radiology jobs and salary trends for August 2026. Learn about the opportunities and challenges of remote work in radiology.
- Unlocking Remote USD Jobs: A GuideDiscover the best remote USD-paying jobs and learn how to succeed in the global job market.