SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Corporate Security Engineer

Suno - Boston, MA, USA - In-office - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Suno is building the world's first creative entertainment platform powered by AI music, enabling millions of users—from casual creators to Grammy winners—to make music. The company is Series C-funded and the fastest-growing consumer entertainment company in AI music. As Corporate Security Engineer, you will own the corporate security domain end-to-end at Suno. You'll be a senior individual contributor and team builder responsible for setting security standards, sequencing work, and ensuring corporate systems are implemented and maintained securely. You'll work closely with IT, Business Systems, Security, and Engineering teams. Key responsibilities include: **Identity and Access Governance:** Own Suno's access model (RBAC, entitlement design, least-privilege defaults). Set standards for access review, certification, and approval. Drive access lifecycle automation for joiner/mover/leaver processes. Address non-human identity (service accounts, agents, automations) before it becomes urgent. **Endpoint Security and Vulnerability Management:** Define security standards for the fleet (hardening baseline, compliance signals, device trust). Own third-party vulnerability management as a program with risk-based remediation SLAs. Partner with IT engineers to deploy standards via Kandji without degrading user experience. **Detection and Response:** Own CrowdStrike Falcon Complete and outsourced SOC relationship. Define what good detection looks like at Suno and hold providers accountable. Lead corporate security incidents to closure and ensure learnings change systems, not just tickets. **Third-Party and Integration Risk:** Evaluate third-party access (OAuth, integrations for Slack, Google Workspace, etc.). Define risk appetite in partnership with the CISO. Turn recurring decisions into policy and tooling. **SaaS Security Posture:** Build and own the program for SaaS applications. Improve tenant-level configuration (SSO, SCIM, MFA, session policy, admin hygiene, OAuth management). **Cross-Functional Leadership:** Work with IT, Security, Engineering, AI Enablement, and Legal to shape how Suno builds and buys. Mentor technical teams and raise the security bar. Success metrics: 90 days—formed security posture view and identified top three issues; 6 months—roadmap aligned with IT and CISO, high-risk items moving; 1 year—entitlement sprawl and vulnerability backlog measurably down, detection reflects real risks, third-party review fast enough to prevent workarounds, standards embedded in tooling and shared judgment. **Requirements:** - ~8+ years in corporate/enterprise security or security engineering, with domain ownership (identity, endpoint, or SaaS security) rather than ticket-based work - Deep hands-on expertise with modern IdP (Okta preferred) and IGA/access-governance tooling (Lumos, Veza, ConductorOne, Opal, or similar) - Designed entitlement or RBAC models across large SaaS portfolios and lived with consequences - Endpoint security depth in macOS-primary fleets: MDM-delivered hardening, compliance, device trust, third-party patch/vulnerability management at scale - Real EDR depth (CrowdStrike preferred); experience holding managed detection providers or outsourced SOCs to defined standards - Strong command of OAuth, SAML, OIDC, SCIM, and third-party integration risk models - Track record of setting security standards others applied without enforcement (policy, tooling, defaults) - Experience influencing engineering and business teams without direct authority, early in their process - Automation fluency: Python or TypeScript, REST APIs, building integrations and internal tooling as routine - Excellent writing and judgment under ambiguity; ability to hold positions with executives and change when evidence warrants - Calibrated risk sense: knowing which risks to block, which to document, and how to communicate the difference Helpful but not required: detection engineering, insider risk/DLP programs, zero-trust network access, SOC 2/ISO program ownership, just-in-time access or identity-as-code, securing AI agents and non-human identity, prior experience as first or second security hire at fast-growing company.

Similar roles