Security Engineer, Enterprise Infrastructure Security, Level 5
Listed on 2025-12-02
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, IT Support
Security Engineer, Enterprise Infrastructure Security, Level 5
Join to apply for the Security Engineer, Enterprise Infrastructure Security, Level 5 role at Snap Inc.
Snap Inc is a technology company. We believe the camera presents the greatest opportunity to improve the way people live and communicate. Snap contributes to human progress by empowering people to express themselves, live in the moment, learn about the world, and have fun together. The Company’s three core products are Snapchat, a visual messaging app that enhances your relationships with friends, family, and the world;
Lens Studio, an augmented reality platform that powers AR across Snapchat and other services; and its AR glasses, Spectacles.
Snap Engineering teams build fun and technically sophisticated products that reach hundreds of millions of Snap chatters around the world, every day. We’re deeply committed to the well-being of everyone in our global community, which is why our values are at the root of everything we do. We move fast, with precision, and always execute with privacy at the forefront.
We’re looking for a Security Engineer to join our Enterprise Infrastructure Security (EIS) team!
What you’ll do:
- You will help design and operate the security controls that protect our corporate devices, applications, and infrastructure. Our team’s scope is broad. We’re looking for someone with deep expertise in a few areas and the curiosity to learn and collaborate across the rest:
- Build and maintain execution control tooling such as endpoint agents, binary allow listing, and related enforcement systems while driving resilient device posture through configuration standards, hardening, and continuous validation across endpoints, BYOD, browsers, IoT, lab, network, and IT systems
- Architect and deploy device trust capabilities by defining and enforcing policies that validate device posture, health, and identity, ensuring only trusted devices can access internal and SaaS applications
- Secure corporate and SaaS applications, including Google Workspace, by establishing baseline configurations, enforcing access governance, managing browser policies, and ensuring secure communication and data sharing across collaboration platforms
- Build and operate enterprise vulnerability and risk management platforms, establishing patching and configuration standards, managing exceptions, and reducing attack surface across operating environments
- Design and operate secure networking and Zero Trust access controls, ensuring that device trust, identity, and network segmentation principles are consistently enforced across corporate and SaaS environments
- Partner with IT and identity platform teams to define security requirements for IAM, IDP, and SSO integrations, ensuring strong authentication, least-privilege access, and alignment with Zero Trust principles across corporate and SaaS environments
- Implement and enforce secure network architectures and firewall policies to protect on-premise infrastructure, maintaining resilient security across datacenters, PoP sites, and manufacturing environments
- Conduct security reviews and partner with cross-functional teams to evaluate new and existing systems, including AI tools and features, providing actionable mitigation guidance that upholds access control boundaries, protects sensitive data, and enables the business to move securely, while also managing exception handling and formal risk acceptance processes
Knowledge, Skills & Abilities:
- Proven experience designing, building, and maintaining corporate security controls, with depth in areas such as device posture management, endpoint agents/binary allow listing, or SaaS application security
- Advanced knowledge of operating system internals and hardening, with competency across two or more of the following: macOS, Windows, Linux, mobile (iOS/Android), IoT, or cloud environments (AWS, GCP)
- Strong understanding of corporate networking concepts and protocols (e.g., VPNs, firewalls, DNS, TLS, identity-aware networking) and their role in enforcing device and application security
- Experience conducting security design reviews and providing actionable mitigation guidance that balances…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).