SlipstreamJobsFresh Startup & VC-Backed Jobs

Enterprise Engineer

PhysicsX - New York, NY, United States - Hybrid - posted 2026-09-14

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

PhysicsX is a deep-tech company building an AI-driven simulation software stack for engineering and manufacturing across advanced industries including Aerospace & Defense, Materials, Energy, Semiconductors, and Automotive. The company accelerates hardware innovation by enabling high-fidelity, multi-physics simulation through AI inference across the entire engineering lifecycle. You will own and evolve the company's Microsoft Entra ID environment, including identity architecture, conditional access policies, MFA, PIM, and SSO/SCIM integrations. You'll manage enterprise infrastructure as code in Terraform for identity, networking, and security tooling to ensure configuration is versioned, reviewable, and repeatable. You'll design and implement zero trust network access, replacing legacy VPN patterns with modern SASE-based access control. You'll own MDM strategy and operations across the device fleet (macOS/Windows/Linux/Mobile), including enrollment, compliance baselines, patch management, and endpoint security posture. You'll partner with the platform/DevOps team to keep enterprise IT and cloud (AWS, GCP, Azure) security postures aligned and consistent. You'll lead access reviews, least-privilege enforcement, and identity governance work to support audits and compliance requirements such as SOC 2 and ISO 27001. The company operates with a flat structure where good ideas win regardless of hierarchy. You'll work with a high-caliber, collaborative team of engineers, scientists, and operators. The role is hybrid, blending time in the New York office with work-from-home flexibility. REQUIREMENTS: - 5–10 years of experience in enterprise IT, security engineering, or identity/infrastructure roles with deep, hands-on ownership of Microsoft Entra ID/Azure AD in production - Deep Conditional Access policy design experience, building risk-based, device-aware access rules (not just enabling MFA) - Experience with Entra ID Governance: Access Reviews, Identity Protection, Privileged Identity Management (PIM) at scale - SSO/SAML/OIDC federation and SCIM provisioning across a meaningful number of enterprise apps - Endpoint security tooling experience with EDR platforms (CrowdStrike, Defender for Endpoint, or similar) - Scripting and automation ability (PowerShell, Python, or Microsoft Graph API) to automate identity and device workflows - Experience with hybrid identity (Entra Connect or on-premises AD sync) - Familiarity with compliance frameworks (SOC 2, ISO 27001, FedRAMP) and ability to translate control requirements into technical implementation - Hands-on experience deploying and operating a SASE platform (Cloudflare One, Zscaler) in production, including policy design - MDM experience (Intune, Jamf, or similar) end-to-end: enrollment, compliance policy, patching, and lifecycle across mixed-OS fleet - Collaborative operator who partners well with security, platform engineering, and the wider business NICE TO HAVE: - Cloud IAM and security architecture experience (AWS IAM Security Center, Google Workforce Identity Federation) - Compliance automation experience (Vanta, Drata) - Cloudflare Zero Trust experience - SIEM/EDR/XDR tooling exposure - Background at an AI or high-growth SaaS company - UK/EU data protection experience (GDPR) - Relevant certifications: Microsoft SC-300, SC-100, MD-102; CompTIA Security+; SASE vendor certifications; CCNA

Similar roles