Corporate IT Security Engineer
Jam City
Job Summary
Jam City is seeking an IT Security Engineer to join their growing technology team. This role is responsible for supporting and strengthening the company's security posture through proactive improvements and responsive actions. The IT Security Engineer will monitor security systems, analyze events and logs, investigate and resolve incidents, and implement/maintain security tools and infrastructure, including SIEM. Key responsibilities include leading incident investigations across SaaS and cloud platforms, designing and implementing automated security workflows, developing SIEM detection rules, maintaining user access reviews, performing vulnerability remediation, and conducting red teaming exercises. The ideal candidate will have a deep understanding of authentication protocols, SIEM platforms, automation experience with Okta and scripting, familiarity with endpoint protection and DLP tools, and knowledge of secure development practices.
Must Have
- Deep understanding of authentication protocols
- Experience with SIEM platforms
- Strong automation experience
- Familiarity with endpoint protection
- Ability to perform red team assessments
- Deep understanding of CI/CD pipelines
- Strong collaboration skills
Good to Have
- Python/Bash scripting
- Terraform
Perks & Benefits
- Competitive salaries
- Benefits
- Professional Development Opportunities
- Flexibility
Job Description
- Lead incident investigations across SaaS platforms including Okta, Google Workspace, Slack, Box as well as Cloud Computing & Infrastructure platforms such as GCP and AWS.
- Design and implement automated security workflows in Okta (e.g., contextual access, dynamic MFA, threat response automation).
- Design, implement and deploy SIEM tooling and develop detection rules/playbooks.
- Maintain and execute User Access Reviews (UARs), vulnerability scans & remediations, and threat response.
- Perform red teaming exercises and annual penetration testing campaigns.
- Configure, test, and optimize endpoint, browser, and SaaS security controls.
- Collaborate with DevOps and Engineering to ensure secrets and API keys are securely managed.
- Monitor and triage alerts from EDR, DLP, and code scanning systems.
- Participate in security awareness programs and phishing simulations.
- Assist with compliance audits and security documentation including Business Continuity, DR/backup policies.
- Deep understanding of authentication protocols (SAML, OIDC, OAuth, Kerberos).
- Experience with SIEM platforms and detection engineering (rule creation, log correlation).
- Strong automation experience with Okta Workflows, scripting (Python/Bash), and APIs.
- Familiarity with endpoint protection, browser session security, and DLP tools.
- Ability to perform and lead internal red team assessments and penetration testing.
- Deep understanding of CI/CD pipelines and secure development knowledge (secrets management, hardcoded credential detection etc..).
- Strong documentation and cross-team collaboration skills.
- Okta, Google Workspace Admin, GitHub Security, CrowdStrike, Nessus/Tenable, AWS/GCP IAM, AWS Security Tools (Guard Duty, Security Hub, CloudTrail, CloudWatch), GCP SCC
- Scripting languages (Python, Bash), Terraform (optional), Okta Workflows/Workforce Identity Cloud.
- Jira, Confluence, Google Drive for documentation.