{"schemaVersion":"jobsearcher.job.v1","id":"f1e0c2d49b7190fb62e5634e","url":"https://jobsearcher.com/jobs/f1e0c2d49b7190fb62e5634e","canonicalUrl":"https://jobsearcher.com/jobs/f1e0c2d49b7190fb62e5634e","title":"IT Security Engineer","description":"Why work at Higgsfield AI?\n\nHiggsfield AI is the fastest-scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.\n\nWe're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.\n\nAbout the role\n\nWe’re looking for an IT Security Engineer to own and strengthen the security of our corporate technology environment. This is a hands-on role spanning identity and access management, endpoint security, SaaS security, Zero Trust, security automation, and incident response.\n\nYou’ll work closely with Security, IT, Engineering, and business teams to build secure, scalable systems and automate the controls that protect our people, devices, applications, and data.\n\nWhat You’ll Do\nIdentity & Access Management\n\nOwn and strengthen identity and access controls across our corporate environment, with a focus on Microsoft Entra ID.\n\nImplement and maintain SSO/SAML, SCIM provisioning, MFA, Conditional Access, and RBAC.\n\nBuild and improve automated joiner, mover, and leaver (JML) workflows.\n\nRegularly review permissions, privileged access, and authentication policies to reduce unnecessary access and security risk.\n\nHelp establish identity as the foundation of our Zero Trust security model.\n\nEndpoint Security\n\nManage and improve endpoint security through Microsoft Intune/MDM, device compliance policies, and endpoint protection tooling.\n\nDeploy and maintain EDR capabilities across the corporate fleet.\n\nEstablish and enforce security baselines for employee devices.\n\nInvestigate endpoint security events and remediate compromised or non-compliant devices.\n\nSaaS & Corporate Application Security\n\nAssess and improve the security posture of corporate SaaS applications.\n\nPartner with application owners to implement appropriate authentication, authorization, provisioning, and data-access controls.\n\nIdentify shadow IT, excessive permissions, insecure configurations, and other SaaS-related risks.\n\nHelp establish scalable security standards for onboarding and managing new corporate applications.\n\nZero Trust & Corporate Access\n\nDesign and implement Zero Trust principles across identity, endpoints, applications, and corporate access.\n\nStrengthen controls around privileged access, remote access, and access to sensitive systems.\n\nApply practical security controls that balance strong protection with employee productivity.\n\nSecurity Automation\n\nAutomate repetitive security and IT workflows using scripts, APIs, and integrations.\n\nBuild tooling to automate access reviews, provisioning, compliance checks, alert enrichment, remediation, and other security processes.\n\nUse scripting languages such as Python or JavaScript to improve security operations and reduce manual work.\n\nLook for opportunities to turn manual security processes into scalable, reliable systems.\n\nDetection & Incident Response\n\nMonitor and investigate security alerts across identity, endpoint, and corporate systems.\n\nPerform initial investigation and triage of suspicious activity and potential security incidents.\n\nSupport incident containment, remediation, and post-incident improvements.\n\nBuild lightweight detections and alerts for meaningful risks within the corporate environment.\n\nWhat We’re Looking For\n\nStrong hands-on experience with identity and access management, ideally within Microsoft Entra ID.\n\nExperience implementing or managing SSO/SAML, SCIM, MFA, Conditional Access, RBAC, and JML workflows.\n\nExperience with MDM and endpoint security, ideally Microsoft Intune and modern EDR tooling.\n\nUnderstanding of SaaS and corporate application security.\n\nExperience implementing or operating within a Zero Trust security model.\n\nAbility to automate workflows using scripts and APIs, with experience in a language such as Python or JavaScript.\n\nWorking knowledge of security detection, investigation, and incident response.\n\nStrong security judgment — you can distinguish theoretical risk from meaningful business risk and prioritize accordingly.\n\nComfortable operating independently in a fast-moving startup environment where priorities can change quickly.\n\nBuilder mindset: you look for ways to automate, simplify, and improve systems rather than relying on manual processes.\n\nNice to Have\n\nExperience with reverse engineering, CTFs, security competitions, or similar hands-on security challenges.\n\nStrong understanding of networking fundamentals, including VPNs, network segmentation, authentication protocols, and common lateral-movement techniques.\n\nExperience securing rapidly scaling or highly technical organizations.\n\nExperience working closely with engineering or product security teams.\n\nFamiliarity with cloud security concepts and modern security monitoring tools.\n\nCompensation & Benefits\n\n• We offer a competitive and thoughtfully structured compensation package designed to align with impact, experience, and long-term growth.\n\n• Base Salary: The anticipated salary range for this role is $165 - $250k, depending on experience, skills, scope, and location.\n\n• Equity: In addition to cash compensation, employees are eligible to participate in the company’s stock option program and share in Higgsfield’s long-term growth. •\n\n• Benefits: We offer a comprehensive benefits package designed to support employees professionally and personally\n\n• The opportunity to work on ambitious AI products alongside a highly experienced, fast-moving, and international team.\n\n• Significant ownership, direct impact, and opportunities for professional growth as the company scales.\n\nThis is a hybrid role based in the San Francisco Bay Area. Team members are expected to work from our San Francisco office three full days per week, with the remaining days worked remotely and are expected to be available during agreed working hours and to maintain sufficient overlap with the relevant team’s time zone. We value in-person collaboration, active communication, responsiveness, and close partnership across teams.\n\nHiggsfield AI is an equal opportunity employer. We are committed to building a diverse and inclusive team and do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic.\n\nCompensation Range: $165K - $250K","company":"Higgsfield","rawCompany":"higgsfield","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-09-06T12:15:56.541Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"IT Security Engineer","description":"Why work at Higgsfield AI?\n\nHiggsfield AI is the fastest-scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.\n\nWe're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.\n\nAbout the role\n\nWe’re looking for an IT Security Engineer to own and strengthen the security of our corporate technology environment. This is a hands-on role spanning identity and access management, endpoint security, SaaS security, Zero Trust, security automation, and incident response.\n\nYou’ll work closely with Security, IT, Engineering, and business teams to build secure, scalable systems and automate the controls that protect our people, devices, applications, and data.\n\nWhat You’ll Do\nIdentity & Access Management\n\nOwn and strengthen identity and access controls across our corporate environment, with a focus on Microsoft Entra ID.\n\nImplement and maintain SSO/SAML, SCIM provisioning, MFA, Conditional Access, and RBAC.\n\nBuild and improve automated joiner, mover, and leaver (JML) workflows.\n\nRegularly review permissions, privileged access, and authentication policies to reduce unnecessary access and security risk.\n\nHelp establish identity as the foundation of our Zero Trust security model.\n\nEndpoint Security\n\nManage and improve endpoint security through Microsoft Intune/MDM, device compliance policies, and endpoint protection tooling.\n\nDeploy and maintain EDR capabilities across the corporate fleet.\n\nEstablish and enforce security baselines for employee devices.\n\nInvestigate endpoint security events and remediate compromised or non-compliant devices.\n\nSaaS & Corporate Application Security\n\nAssess and improve the security posture of corporate SaaS applications.\n\nPartner with application owners to implement appropriate authentication, authorization, provisioning, and data-access controls.\n\nIdentify shadow IT, excessive permissions, insecure configurations, and other SaaS-related risks.\n\nHelp establish scalable security standards for onboarding and managing new corporate applications.\n\nZero Trust & Corporate Access\n\nDesign and implement Zero Trust principles across identity, endpoints, applications, and corporate access.\n\nStrengthen controls around privileged access, remote access, and access to sensitive systems.\n\nApply practical security controls that balance strong protection with employee productivity.\n\nSecurity Automation\n\nAutomate repetitive security and IT workflows using scripts, APIs, and integrations.\n\nBuild tooling to automate access reviews, provisioning, compliance checks, alert enrichment, remediation, and other security processes.\n\nUse scripting languages such as Python or JavaScript to improve security operations and reduce manual work.\n\nLook for opportunities to turn manual security processes into scalable, reliable systems.\n\nDetection & Incident Response\n\nMonitor and investigate security alerts across identity, endpoint, and corporate systems.\n\nPerform initial investigation and triage of suspicious activity and potential security incidents.\n\nSupport incident containment, remediation, and post-incident improvements.\n\nBuild lightweight detections and alerts for meaningful risks within the corporate environment.\n\nWhat We’re Looking For\n\nStrong hands-on experience with identity and access management, ideally within Microsoft Entra ID.\n\nExperience implementing or managing SSO/SAML, SCIM, MFA, Conditional Access, RBAC, and JML workflows.\n\nExperience with MDM and endpoint security, ideally Microsoft Intune and modern EDR tooling.\n\nUnderstanding of SaaS and corporate application security.\n\nExperience implementing or operating within a Zero Trust security model.\n\nAbility to automate workflows using scripts and APIs, with experience in a language such as Python or JavaScript.\n\nWorking knowledge of security detection, investigation, and incident response.\n\nStrong security judgment — you can distinguish theoretical risk from meaningful business risk and prioritize accordingly.\n\nComfortable operating independently in a fast-moving startup environment where priorities can change quickly.\n\nBuilder mindset: you look for ways to automate, simplify, and improve systems rather than relying on manual processes.\n\nNice to Have\n\nExperience with reverse engineering, CTFs, security competitions, or similar hands-on security challenges.\n\nStrong understanding of networking fundamentals, including VPNs, network segmentation, authentication protocols, and common lateral-movement techniques.\n\nExperience securing rapidly scaling or highly technical organizations.\n\nExperience working closely with engineering or product security teams.\n\nFamiliarity with cloud security concepts and modern security monitoring tools.\n\nCompensation & Benefits\n\n• We offer a competitive and thoughtfully structured compensation package designed to align with impact, experience, and long-term growth.\n\n• Base Salary: The anticipated salary range for this role is $165 - $250k, depending on experience, skills, scope, and location.\n\n• Equity: In addition to cash compensation, employees are eligible to participate in the company’s stock option program and share in Higgsfield’s long-term growth. •\n\n• Benefits: We offer a comprehensive benefits package designed to support employees professionally and personally\n\n• The opportunity to work on ambitious AI products alongside a highly experienced, fast-moving, and international team.\n\n• Significant ownership, direct impact, and opportunities for professional growth as the company scales.\n\nThis is a hybrid role based in the San Francisco Bay Area. Team members are expected to work from our San Francisco office three full days per week, with the remaining days worked remotely and are expected to be available during agreed working hours and to maintain sufficient overlap with the relevant team’s time zone. We value in-person collaboration, active communication, responsiveness, and close partnership across teams.\n\nHiggsfield AI is an equal opportunity employer. We are committed to building a diverse and inclusive team and do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic.\n\nCompensation Range: $165K - $250K","datePosted":"2026-09-06T12:15:56.541Z","dateModified":"2026-09-06T12:15:56.541Z","hiringOrganization":{"@type":"Organization","name":"Higgsfield","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f1e0c2d49b7190fb62e5634e"},"url":"https://jobsearcher.com/jobs/f1e0c2d49b7190fb62e5634e"}}