Enterprise Security Engineer

PaveSan Francisco, CA
$220,000Hybrid

About The Position

Security at Pave protects the world's largest real-time compensation dataset and the company that runs on it. The team is small, senior, and AI pilled: everyone builds, everyone automates, and everyone flexes across domains. As Pave's Corporate Security Engineer, you'll own the corporate side of that mission: identity and access management, endpoint protection, SaaS security, and the corporate compliance operations behind our SOC 2 Type II and ISO 27001 programs, with an explicit charter to aggressively automate all the things.

Requirements

  • 5+ years of hands-on corporate/enterprise security or IT security engineering experience at a multi-office company
  • Okta (or equivalent IdP) administration at the design level — you've built an access model, not just operated one
  • Experience operating within SOC 2 and/or ISO 27001: controls you owned passed audits
  • Hands-on MDM/EDR and Google Workspace–class SaaS estate administration as a primary owner
  • A track record of shipped automations with concrete before/after impact
  • Demonstrated, specific use of AI tooling in your own workflows

Nice To Haves

  • Previous management experience
  • Came up through IT/helpdesk into security (or similar path), so you have empathy for the people you’re supporting and first hand experience with the toil you’re here to automate away
  • Experience with Okta, GCP, Iru, Sentinel one, Claude code
  • Vendor security review / third-party risk experience
  • Background at a 150–500 person B2B SaaS company handling sensitive data
  • Networking fundamentals

Responsibilities

  • Own Okta and Pave's access-management model: role/group architecture, lifecycle automation, SSO/SCIM, and the exception process
  • Keep the RBAC model current and consistently enforced, with automation that prevents drift
  • Own the SOC 2 Type II and ISO 27001 controls that touch corporate IT, end to end
  • Automate evidence collection and user access reviews
  • Own endpoint protection (MDM/EDR) across a five-location, ~175-person company
  • Run SaaS vendor security reviews and build shadow-IT visibility; feed IT-controlled data sources into our SIEM
  • Engineer away manual IT toil — laptop setup, onboarding/offboarding provisioning, access requests — using APIs, workflow tooling, and AI agents
  • Build governance for employee-built internal apps: publish detection, automated review checks, sane sharing models
  • Design the systems that Pave's helpdesk (in G&A) operates day to day; be the design counterpart that makes that team stronger and more self-sufficient

Benefits

  • Meaningful equity
  • Best-in-class medical, dental, and vision coverage
  • Unlimited PTO
  • Region-specific benefits
  • Comprehensive medical, dental, and vision coverage for you and your family, with a range of options designed to meet you where you are.
  • Flexible PTO
  • The freedom to work from anywhere in the world for up to a month
  • Lunch and dinner stipends
  • Fully stocked kitchens
  • A quarterly education stipend to invest in the skills and knowledge that matter most to you.
  • Robust parental leave
  • A commuter stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service