
Senior Enterprise Security Engineer
About the role
As a Senior Enterprise Security Engineer, you will be a foundational architect of our corporate security posture, directly safeguarding our infrastructure, sensitive data, and global workforce. This is a highly hands-on, configuration-driven role focused on hardening our environment through identity governance, endpoint security, and automated threat response.
What You’ll Do
- Identity & Zero Trust:
Architect robust IAM principles (Okta, Entra ID) and Zero Trust strategies. Enforce granular authentication, lifecycle management, and device trust to ensure secure access across all corporate resources.
- Endpoint Security & Fleet Hardening:
Lead the administration of our EDR (Crowd Strike Falcon) and MDM/UEM (Intune, Jamf). Manage patch lifecycles, endpoint state attestation, and proactive threat hunting to neutralize threats across all corporate devices.
- Threat Detection & Automation:
Develop advanced detection logic (SIEM/XDR) and build SOAR workflows to reduce Mean Time to Detect (MTTD) and Respond (MTTR).
- SaaS Security & DLP:
Secure our ecosystem by managing email security (e.g., Material Security) and implementing Data Loss Prevention (DLP) across SaaS platforms (Google Workspace, Salesforce, Box).
- Cross-Functional Leadership:
Partner with Engineering and IT to embed security-by-design, automate compliance checks for new infrastructure, and manage security integration for mergers and acquisitions.
What We’re Looking For
- Experience:
5+ years in corporate security engineering within high-growth, cloud-native environments.
- Identity Expertise:
Expert-level proficiency with Okta (SSO, MFA, IGA) and experience with federation protocols (SAML, OIDC, SCIM).
- Endpoint/Device Security:
Deep hands-on experience with EDR (Crowd Strike) and MDM solutions (Intune, Jamf).
- Automation:
Strong track record of automating security workflows using SOAR or scripting (Okta Workflows, Python, etc.) to drive efficiency.
- Technical Breadth:
Proficiency in Zero Trust models, SaaS/Cloud security, and vulnerability management.
- Soft Skills:
Proven ability to translate complex technical risks into business context and collaborate effectively across technical and non-technical teams.
Required skills
enterprise security
IAM
endpoint security
security automation
Zero Trust
About Navan
Tel-Aviv
Headquarters