The Enterprise Security Engineer is a hands-on engineer who implements, operates, and improves security controls across corporate architecture, SaaS platforms, cloud services, endpoints, identity, data, and workforce technologies. This role translates enterprise security strategy into practical, measurable controls and secure-by-default solutions that reduce risk without slowing the business.
The engineer partners with Enterprise IT, Corporate Engineering, SRE and Platform teams, Business Systems, Product Security, Legal, Privacy, and other stakeholders to deliver scalable security improvements across Atlassian’s corporate environment. As part of Atlassian’s “Customer Zero” initiative, the engineer helps validate and improve security capabilities internally before broader adoption.
Design, implement, operate, and maintain security controls across identity, endpoints, network, cloud (AWS/GCP), SaaS, and data-protection domains.
Remediate identified gaps in access controls, device posture, SaaS configurations, and sensitive data protections.
Assist with the rollout and adoption of secure baseline configurations and paved-path implementations across internal teams.
Participate in security reviews for new tools, internal workflows, and SaaS integrations under the guidance of senior engineers.
Support cyber-related physical security operations, including maintaining integrations between physical access-control systems and identity platforms, monitoring access lifecycles, and addressing facility-related cyber risks.
Strengthen identity lifecycle management, privileged access, authentication, authorisation, and access reviews.
Help validate agentic identity, AI-native governance, data-protection, and access controls internally before broader release.
Monitor insider risk signals, anomalous access patterns, and policy violations to support triage and response.
Support the secure implementation of service accounts and automated bot credentials.
Implement and monitor security guardrails and posture baselines across cloud environments (AWS/GCP) and SaaS suites (Google Workspace, Slack, Okta).
Maintain endpoint security agents, device compliance policies, and configuration baselines across macOS and Windows fleets.
Help implement and tune Data Loss Prevention (DLP) and data-classification controls to safeguard internal and customer information.
Build scripts, API integrations, and automations (e.g., Python, Bash, Go) to eliminate repetitive tasks and streamline security operations.
Maintain infrastructure-as-code and CI/CD security checks for enterprise tooling.
Track operational metrics, monitor control health, and contribute to standard operating procedures (SOPs) and runbooks.
Participate in on-call rotations, troubleshooting, and post-incident reviews (PIRs) for security tooling outages, pipeline failures, and platform availability issues.
Execute security evaluations and vendor risk reviews for new SaaS tooling and browser extensions against defined security criteria.
Track remediation of identified vendor vulnerabilities and configuration risks.
Execution and Delivery: Successfully deliver scoped technical tasks, control deployments, and automation milestones on time with high code and configuration quality.
Operational Excellence: Triage and resolve security escalations, access tickets, and alert queues within established SLOs, actively reducing backlog and manual toil.
Automation and Tooling: Write reliable scripts and workflow automations that reduce manual operational effort and improve control reliability.
Security Hygiene & Remediation: Close identified posture gaps across SaaS, endpoints, or IAM systems, demonstrating measurable improvements in baseline compliance.
Collaboration & Learning: Partner effectively with senior engineers and cross-functional teams, actively expanding your technical depth across enterprise security domains.
3–5+ years of experience in cybersecurity, security engineering, cloud security, systems engineering, or enterprise technology.
Experience implementing, operating, and maintaining security controls across identity, endpoint, SaaS, cloud, network, and data protection domains.
Hands-on experience with IAM, directory services, SSO/MFA, and access governance (e.g., Okta, Google Workspace, Azure AD / Entra ID).
Practical experience securing cloud environments (AWS or GCP) and enterprise SaaS collaboration suites (e.g., Google Workspace, Slack).
Experience automating security tasks and operational workflows using scripting (e.g., Python, Bash, Go), REST APIs, and CI/CD pipelines.
Working knowledge of endpoint security architectures, device posture management (MDM), and data protection / DLP controls across macOS and Windows.
Understanding of SaaS vendor risk assessments, third-party integration risks, and secure baseline standards.
Foundational awareness of cyber-related physical access-control systems and their integration with enterprise identity lifecycles.
Strong troubleshooting and communication skills, with the ability to write clear runbooks and technical documentation, and collaborate effectively across engineering and operations teams.
Software Powered by ICIMS
www.icims.com