At a Glance
- Tasks: Design and implement security controls for a fast-paced, cloud-native environment.
- Company: Join CoreWeave's innovative Enterprise Security team focused on modern security solutions.
- Benefits: Enjoy competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Collaborative culture with a focus on zero trust and cutting-edge security technologies.
- Why this job: Make a real impact by enhancing security measures that empower productivity.
- Qualifications: 5+ years in enterprise security with hands-on experience in identity and access management.
The predicted salary is between 63000 - 77000 £ per year.
The Enterprise Security team at CoreWeave is responsible for securing how our people work every day—identity, endpoints, networks, and SaaS—so the company can move fast without compromising safety. This team owns the controls, guardrails, and automation that keep our workforce, contractors, and critical business applications protected in a modern, cloud-native environment.
As a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls that underpin CoreWeave’s workforce and enterprise stack. You’ll lead initiatives across identity, access management, device and endpoint security, and SaaS security—partnering closely with IT Engineering, Endpoint, Network, and other security teams. Your day-to-day will blend hands-on engineering (writing code, building integrations, tuning controls) with architecture and program ownership (setting standards, defining patterns, and driving adoption across teams).
You’ll be responsible for turning high-level objectives—like “implement zero trust for workforce access” or “deploy phishing-resistant MFA at scale”—into concrete designs, automation, and measurable risk reduction.
- Design, implement, and operate workforce identity solutions (e.g., Okta/Entra and other IdPs) including SSO, MFA, conditional access, and lifecycle automation via SCIM.
- Develop and roll out phishing-resistant MFA for high-value accounts and critical access paths (e.g., FIDO2/WebAuthn, hardware keys, device-bound authenticators).
- Define and maintain RBAC/IAM patterns for enterprise applications (role models, groups, entitlements, JIT access, and approvals).
- Design and deploy controls that combine user identity, device posture, network context, and application sensitivity to enforce least-privilege access.
- Partner with Network and Infrastructure teams to integrate mTLS, service identity, and policy-based access into internal services and admin interfaces.
- Help transition from legacy perimeter models to zero trust network access (ZTNA) patterns for employees, contractors, and third parties.
- Evaluate, onboard, and harden SaaS applications (Google Workspace, Microsoft 365, Slack, HRIS, ticketing, and other business apps) to align with enterprise security policies.
- Implement and tune controls such as SCIM provisioning, data access policies, DLP, sharing controls, and audit logging across the SaaS estate.
- Partner with business and IT owners to ensure new SaaS applications meet baseline security standards before adoption.
- Collaborate with Endpoint/IT teams to define and enforce baseline configurations for laptops, workstations, and other managed devices via MDM and EDR.
- Design secure patterns for contractor and vendor access, including device requirements, identity separation, and time-bound access.
- Support investigations and incident response related to identity, endpoint, and SaaS domains.
- Build automation and self-service experiences for access requests, approvals, access reviews, and break-glass workflows.
- Develop integrations between IdPs, HRIS, ticketing, and other systems to minimize manual toil and reduce identity-related error rates.
- Define and instrument metrics for enterprise security (e.g., MFA coverage, zero trust policy enforcement, joiner/mover/leaver SLA adherence, SaaS posture).
- Work with Security Operations and SIEM teams to ensure robust visibility into identity, device, and SaaS activity, and to build high-signal detections.
- Contribute to policies, standards, and reference architectures that encode enterprise security expectations.
- Author clear documentation and runbooks that make it easy for teams to consume and operate the controls you build.
If you’re excited about zero trust, phishing-resistant MFA, and building secure-by-default experiences that actually make people more productive, this is the team to join.
Demonstrated experience designing and rolling out MFA, ideally including phishing-resistant approaches (FIDO2/WebAuthn, hardware security keys, device-bound authenticators, step-up authentication).
Exposure to SIEM/detection ecosystems (e.g., Elastic) and experience collaborating with detection & response teams on identity/endpoint/SaaS detections.
Deep familiarity with SAML, OAuth 2.0/OIDC, and SCIM, including real-world experience integrating these protocols with third-party SaaS and internal apps.
Strong, practical understanding of modern IAM concepts: SSO, federation, RBAC/ABAC, JIT access, least privilege, and separation of duties.
Experience designing and deploying zero trust or context-aware access controls (e.g., device trust, network segmentation, mTLS, ZTNA) in hybrid or remote-friendly environments.
Familiarity with MDM and endpoint security tooling (e.g., Jamf, Intune, EDR platforms) and how they tie into identity and access decisions.
A track record of owning cross-functional projects from design through adoption, with an emphasis on measurable risk reduction and user experience.
Proficiency in at least one modern scripting or programming language (e.g., Python, Go) used to build automations, integrations, or internal tooling.
Experience securing and integrating business-critical SaaS (e.g., Google Workspace, Microsoft 365, Slack, Atlassian, HRIS, ticketing) including SCIM provisioning, access reviews, and audit log ingestion.
5+ years of experience in enterprise security, identity and access management, or closely related security engineering roles.
Hands-on experience implementing and operating SSO and workforce identity with platforms such as Okta, Entra ID, or equivalent IdPs.
Experience working in high-growth or hyperscale environments where security must keep pace with rapid headcount and tooling expansion.
Hands-on experience with zero trust network access or secure access products (e.g., ZTNA, secure web gateways, or identity-aware proxies).
Experience with SaaS security posture management (SSPM), CASB, DLP, or insider risk tooling focused on collaboration platforms and data access.
Familiarity with enterprise security standards and frameworks (e.g., SOC 2, ISO 27001, NIST 800-53) and mapping enterprise controls to these requirements.
Experience building or contributing to internal security tooling (e.g., access review automation, JML workflows, policy-as-code).
Participation in security communities, standards groups, or open-source contributions in IAM, zero trust, or enterprise security.
Senior Security Engineer (Enterprise Security) employer: CoreWeave
CoreWeave is an exceptional employer that thrives on innovation and collaboration, making it an ideal place for the Senior Community Affairs & Partnerships Manager to make a meaningful impact. With a strong emphasis on employee growth, a dynamic work culture, and comprehensive benefits including flexible PTO and tuition reimbursement, CoreWeave fosters an environment where creativity and independent thinking are encouraged. Located in a fast-paced industry, employees are surrounded by top talent and have the opportunity to contribute to groundbreaking advancements in AI technology while building trusted relationships within the community.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Security Engineer (Enterprise Security)
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including CoreWeave, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through CoreWeave
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at CoreWeave. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Security Engineer (Enterprise Security)
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at CoreWeave insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to CoreWeave that you’re committed to staying ahead in the game.
How to prepare for a job interview at CoreWeave
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at CoreWeave to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at CoreWeave.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.