SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Atlan is building the context layer for enterprise AI, connecting business context behind data to help humans and AI agents operate with accuracy and confidence. The company serves AI-forward enterprises like General Motors, Nasdaq, Workday, and Elastic, backed by investors including GIC, Insight Partners, Meritech, Peak XV, and Salesforce Ventures.
You will own and drive Corporate Security as a senior individual contributor with high autonomy and visibility. You are the technical authority for everything protecting Atlan's people, endpoints, networks, SaaS ecosystem, and corporate data—the full corporate security surface area outside production infrastructure.
Key responsibilities include designing and operating security controls for the corporate environment (macOS fleet, SaaS applications, corporate identities via Okta/Google Workspace, email, endpoints, network edge). You will evaluate, select, deploy, and operate the corporate security stack including EDR/XDR, MDM, ZTNA, CASB/SSPM, email security, DLP, and browser security. You own vendor selection, proof-of-concepts, deployment, tuning, and lifecycle management.
You will define and enforce security baselines, hardening standards, and configuration policies across all corporate platforms. You drive vulnerability management for corporate assets including patch orchestration, risk-based prioritization, exception tracking, and SLA enforcement. You build security automation and internal tooling, leveraging LLMs (Claude, custom agents) to accelerate security workflows. You lead security reviews of new SaaS adoptions, corporate infrastructure changes, and IT projects, and define safe operation in environments where AI agents act autonomously across corporate systems.
You own the Corporate Security roadmap, aligning investments to Atlan's risk register, compliance calendar, and growth trajectory. You provide technical direction to IT Operations on endpoint provisioning, network design, SaaS lifecycle management, and access controls. You partner with Detection & Response on telemetry coverage, detection engineering, and incident handling. You collaborate with Infrastructure Security and AppSec teams to ensure consistent security standards. You support compliance programs (ISO 27001, ISO 42001, SOC 2, HIPAA, GDPR) by ensuring corporate security controls satisfy audit evidence requirements.
Required: 5+ years hands-on Security Engineering in corporate/enterprise security (endpoint, network, SaaS, identity). You have built or significantly matured a corporate security program before—selected tooling, defined architecture, shipped controls. You are a strong engineer who writes code regularly and can prototype tools, write detections, build integrations, script APIs, or debug complex configuration issues. Deep experience with macOS fleet security, EDR/XDR, MDM, ZTNA/zero trust, and identity security solutions at scale. Understanding of modern SaaS security challenges: shadow IT, OAuth token sprawl, data exfiltration paths, SaaS-to-SaaS integrations, CASB/SSPM tooling. You work independently with high autonomy, manage ambiguity, and make sound risk-based prioritization decisions. Excellent communication skills translating complex security topics for engineering teams and business stakeholders. Experience supporting ISO 27001, SOC 2, or equivalent compliance frameworks from the corporate security controls side.
Bonus: Experience securing corporate environments at high-growth SaaS, AI, cloud, or developer-tools companies. Advanced macOS security (system extensions, Endpoint Security framework, MDM profile engineering, Declarative Device Management). Network security architecture for distributed/remote-first environments (SD-WAN, ZTNA, DNS security, network segmentation). Browser security and isolation technologies. Proficiency in Python, Go, or similar languages for security tooling and automation. Experience leveraging LLMs/AI to augment security operations or automate policy enforcement. Familiarity with IaC (Terraform), CI/CD pipelines, and DevSecOps practices.