SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
depthfirst is building AI-powered intelligence to detect and remediate critical software vulnerabilities, training and scaling security AI agents to discover zero-day vulnerabilities across large customer codebases and open source software. The founding team includes leaders from DeepMind, Databricks, Square, and Faire with deep expertise in data, infrastructure, security, and AI.
As one of the first security engineers, you will own corporate security at depthfirst, protecting the identities, devices, and applications the team relies on daily. You'll build tooling, integrations, and automation that keep workforce access, endpoints, and enterprise apps secure by default as the company scales.
Key responsibilities include:
- Shape corporate security foundations, protecting devices, identities, and applications
- Strengthen workforce identity and access management through Okta and SSO, implementing phishing-resistant authentication, least privilege access, and automated provisioning/removal
- Build and maintain endpoint security controls via mobile device management (MDM) and endpoint detection and response (EDR), improving device configurations, patching, and fleet visibility
- Establish secure configurations for enterprise applications (Google Workspace, Claude Cowork, Codex) with appropriate controls for administrative access, data sharing, and integrations
- Write and maintain software, integrations, and automation that enforce security policies, identify configuration gaps, and reduce manual work across identity, device, and application management
Requirements:
- Strong software engineering skills with experience building reliable internal tools, API integrations, and automation to solve security or infrastructure problems
- Hands-on experience with Okta or similar identity platforms, including SSO, MFA, access policies, and identity lifecycle management; familiarity with SAML, OIDC, and SCIM
- Experience securing employee devices through MDM, including configuration enforcement, disk encryption, patch management, and policies that use device security posture to control access
- Familiarity with EDR platforms, including deploying and maintaining coverage, investigating endpoint activity, and supporting containment and remediation
- Experience securing enterprise SaaS applications and understanding risks from OAuth integrations, excessive permissions, external sharing, and AI tools with company data access
- Strong written and verbal communication skills to explain complex security issues to technical and non-technical audiences
Bonus: Experience at high-growth startups or early-stage companies; familiarity with security, infrastructure, or developer tooling markets.