Benchling
Enterprise Security Engineer
About this role
Benchling seeks an Enterprise Security Engineer to build a zero trust security program from the ground up, focusing on identity management, device compliance, and AI-native security tooling. You'll architect least-privilege access patterns, manage macOS endpoints at scale, and automate security processes to protect sensitive biotech research data.
What you'll do
- Drive zero trust strategy across identity, device health, network context, and application sensitivity
- Design and maintain least-privilege access, JIT access, and PAM controls
- Deploy and maintain MDM infrastructure for macOS fleet with compliance integration
- Enforce SSO policies, audit OAuth scopes, and manage third-party integration access
- Build tooling to detect shadow IT and unauthorized SaaS tools
- Define security standards for AI agent and LLM service identities
What they're looking for
- Identity and Access Management (IAM)
- Zero trust architecture implementation
- Okta IdP administration
- macOS MDM management (Fleet or equivalent)
- Identity protocols (SAML, OIDC, OAuth 2.0, SCIM)
- Cloud IAM (AWS, GCP, or Azure)
- Python scripting
- Privileged Access Management
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Benchling
Benchling builds an AI-powered platform for biotech R&D that integrates scientific workflows and data processes to accelerate research breakthroughs. The company is hiring software engineers across full-stack, customer engineering, agentic AI, and security roles to enhance developer productivity, build production AI systems, and protect sensitive research data.
- Website
- benchling.com
Likely interview questions
- Walk us through a zero trust implementation you've led end-to-end. How did you integrate device health, identity, and network context into continuous access decisions?
- Describe your hands-on experience with Okta (or your primary IdP). Which features—SCIM, lifecycle management, MFA policies—have you configured and why?