About the Role
Gecko is seeking an Enterprise Security Engineer to build and operate shared systems protecting people, devices, applications, and sensitive data. The role focuses on workforce endpoint and device security, identity security, SaaS and OAuth governance, enterprise detections, and the protection of regulated data. The goal is to eliminate friction by solving shared security and technology problems, enabling teams to focus on their unique roles and ensuring security and compliance facilitate faster progress.
Responsibilities
- Build, configure, and operate endpoint-management, device-compliance, browser-security, and endpoint detection and response controls.
- Harden workforce devices and shared enterprise systems.
- Own and improve identity security, including Okta policies, MFA, Conditional Access, and lifecycle controls.
- Establish practical governance for SaaS applications, OAuth access, browser extensions, AI tools, and other third-party technology.
- Create clear, usable paths for employees to adopt approved AI tooling and other technology while protecting regulated and sensitive data.
- Meet security, privacy, contractual, and compliance obligations.
- Translate requirements into effective configurations and workflows.
- Partner closely with IT Engineering to solve shared problems, reduce recurring friction, and make controls easy to operate.
- Build and tune enterprise detections.
- Evaluate alerts and control gaps.
- Lead corporate-side incident response.
- Make proportionate risk decisions and coordinate remediation with system owners.
- Partner with Product Security, Cloud Infrastructure, IT, and Facilities on enterprise-security concerns.
- Establish and maintain governance for the adoption and use of AI tools and other rapidly emerging workplace technologies.
- Travel up to 20% to Gecko offices and other locations as needed.
Requirements
- 3+ years of experience in Enterprise Security Engineering, Security Engineering, IT Security, or a related hands-on security engineering role.
- Hands-on experience administering endpoint management and endpoint detection and response (EDR) solutions in production environments.
- Experience administering or securing identity and access management (IAM) platforms, including SSO, MFA, or lifecycle management.
- Experience evaluating, governing, or administering SaaS applications, OAuth integrations, and enterprise security controls.
- Experience working with regulated, customer-protected, or other sensitive data (e.g., CUI, HIPAA, PCI, SOC 2).
- Strong systems configuration, troubleshooting, workflow design, and operational ownership skills.
- Demonstrated ability to balance security and compliance requirements with business needs and user experience.
- Excellent written and verbal communication skills.
- Ability to partner effectively across Security, IT, Engineering, Compliance, Legal, and other cross-functional teams.
Skills
- Identity management (e.g., Okta, Onelogin, Active Directory)
- MDM systems (e.g., Jamf, Intune, NinjaOne)
- EDR/MDR tools (e.g., CrowdStrike, TrendMicro, SentinelOne)
- AI management (e.g., Claude, ChatGPT, Cursor, Grok)
- Government security frameworks (FedRAMP, CMMC, NIST 800-171, NIST 800-53, CUI handling)
- Commercial security frameworks (SOC2 Type II, ISO 27001, ISO 42001)
- Governing AI tools or other rapidly adopted workplace technology
- Experience in government, defense, critical infrastructure, or another highly regulated industry
- Familiarity with CUI, CMMC, FedRAMP, NIST, SOC 2, or ISO 27001
- Administering CrowdStrike Falcon, Microsoft Defender, SentinelOne, or another enterprise EDR platform
- Administering Okta, Microsoft Intune, Jamf, or comparable identity and endpoint management platforms
- DLP, CASB, browser security, or SaaS/OAuth governance technologies
- Automating security or IT workflows using Python, PowerShell, Bash, or similar scripting languages
- Working on a small, high-growth, or startup team where security processes, tooling, and ownership were built from the ground up
Location
- Gecko offices
Work Type
- Office-first culture
- Some flexibility for remote work
Experience Level
- 3+ years of experience in Enterprise Security Engineering, Security Engineering, IT Security, or a related hands-on security engineering role.
Benefits
- Competitive compensation packages
- Company equity
- 401(k) matching
- Gender-neutral parental leave
- Full medical, dental, and vision insurance
- Mental health support
- Ongoing professional development
- Family planning assistance
- Flexible paid time off
About the Company
- Gecko Robotics helps organizations ensure the availability, reliability, and sustainability of critical infrastructure using wall-climbing robots, sensors, and an AI-powered data platform.
- Gecko's solutions provide insights into the health of physical assets, enabling real-time decision-making to increase operational efficiency and safety, promote mission readiness, and protect the environment.
- Gecko values collaboration, innovation, and partnership.
- Gecko is committed to creating a culture of inclusion and belonging.
Equal Opportunity
- All qualified applicants will be treated with respect and receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, veteran status, age, or any other protected characteristic per federal, state, or local law.
