Sr. Corporate Security Engineer
CockroachDB · New York, NY
About this role
**Sr. Corporate Security Engineer** **About the role** Cockroach Labs is seeking a **Senior Corporate Security Engineer** to help protect **endpoints, cloud platforms, internal applications, and the enterprise SaaS environment**. This is a **hands-on, cross-functional** role with a focus on **AI governance, data protection, and corporate security operations**—including shaping how the company securely adopts AI tools and agents, strengthening **DLP** and **SaaS security controls**, and leading security initiatives from design through implementation. **Location** - Must be **based in the NYC area**. --- **You will** - Build and manage an **AI governance program** (security controls for AI tools, agents, MCP connections, and data flows) - Develop and secure **internal applications hosted on GCP**, including an **internal LLM gateway** - Design and maintain **DLP, data classification, and governance controls** - Administer and optimize **CASB** and **SaaS security controls** - Assess security risks for **internal applications, AI use cases, and third-party tools** - Monitor and respond to security alerts and incidents across **email, endpoints, SaaS, and cloud** - Identify and reduce risks related to **Shadow IT, Shadow AI, and SaaS sprawl** - Build **automations** to improve security visibility, response, and operational efficiency - Partner with **IT, Legal, Compliance, and Security** on access management, endpoint security, regulatory requirements, and third-party risk - Lead corporate security projects **from design through implementation** **You have** - **5+ years** of experience in corporate security, security operations, IT security, or related work - Experience owning a security program, major initiative, or complex cross-functional project - Hands-on experience with **DLP, CASB, or SaaS security tools** (creating/tuning policies) - Experience securing **cloud-hosted applications** and corporate IT environments - Strong understanding of **IAM, endpoints, email, file-sharing, networks, and enterprise SaaS** - Familiarity with security/data risks associated with **AI tools, applications, agents, and integrations** - Experience conducting **risk assessments, gap assessments, or threat modeling** - Strong **project management, communication, and cross-functional collaboration** skills **Bonus points** - Experience building **AI governance controls** or securing AI applications/agents - Experience with tools such as **Netskope, Zscaler, GCP, Okta, Google Workspace, CrowdStrike Falcon**, or similar - Experience with **SIEM/SOAR** and security automation tools (e.g., **Tines** or **Python**) - Prior experience in **IT support** or **systems administration** - Familiarity with frameworks such as **NIST, SOC 2, ISO 27001, GDPR, CIS Critical Controls** - Experience using AI development tools such as **Claude Code** or **Cursor** - Relevant certifications such as **Security+, CISSP, or CCSP** --- **What to expect (first months)** - **First 30 days:** integrate with the Corporate Engineering Team and learn existing systems/processes - **Second month:** evaluate the current AI governance program and propose improvements - **Third month:** lead projects within Corporate Security, manage the AI governance program, and help build AI gateway/infrastructure **Team** - Manager: **Elliot Kartus – Manager, Corporate Security** - Manager’s manager: **Adam Brennick – Director, Security & GRC** --- **Benefits (highlights)** - Stock Options - M
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.