JobRaahGet matched free

Jobs

Security Engineer, Enterprise Security

Figure · San Jose, CA · United States · On-site

Pay: USD 150,000 – 250,000 a year

Posted Sep 17, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Figure is an AI robotics company developing autonomous general-purpose humanoid robots. The goal of the company is to ship humanoid robots with human level intelligence. Its robots are engineered to perform a variety of tasks in the home and commercial markets. Figure is headquartered in San Jose, CA. We are looking for a Corporate Security Engineer to join the Security & Privacy team at Figure. Corporate Security owns the environment Figure's people work in: computers, identities, collaboration tools, and the company data flowing through all of it. The design and software behind our humanoid sit inside that environment. We keep access to managed devices, make them hard to compromise, and right-size what each can reach, without getting in the way of the people using them. We are an engineering team. Controls ship as code, changes are versioned and reviewed, and posture is measured rather than asserted. This is a senior, hands-on individual contributor role. Nobody arrives deep in all of it; we want real depth in one of endpoint engineering, identity and access, or application access design, working knowledge of the rest, and room to build depth here. Responsibilities: Endpoints and Access Build the endpoint hardening controls across macOS, Windows, Linux, and ChromeOS. Our fleet runs on FleetDM, an osquery-based MDM managed through GitOps: you author the control, you write the query proving it landed, and you ship both in a merge request for review. Bind data access to a healthy managed device and the person it was issued to: phishing-resistant factors, session lifetimes, and device posture checks. Bring AI assistants and coding agents under enterprise management: configuration and permissions delivered and verified like any other endpoint control. Applications and Third Parties Design application authentication, RBAC, and access lifecycle from first principles: identify what an application exposes, threat model it, propose control requirements, and guide owners to implement them. Contribute what each engagement teaches to the team's default deployment playbooks: authentication, logging, and network placement. Run security review and governance for SaaS and third parties: vendor assessments, OAuth grants, connector integrations, browser extensions, and data movement through the browser. Visibility and Measurement Build the inventories this work depends on: application discovery, application posture management, grant tracking. Feed vulnerability management and build the controls that close what it finds. Threat model the corporate attack surface as a repeatable practice and feed the results into what the team works on next. Partner with Detection and Response on telemetry and with IT on rollout. Use AI where it earns its place: prepping access reviews, first-pass triage, and analysis that gets a human to a decision faster. Requirements: Software engineering discipline in Python, Bash, PowerShell, or similar:…