
Enterprise Security Engineer
Build a Safer World.
TRM Labs provides blockchain analytics and AI solutions to help law enforcement and national security agencies, financial institutions, and cryptocurrency businesses detect, investigate, and disrupt crypto-related fraud and financial crime. TRM’s blockchain intelligence and AI platforms include solutions to trace the source and destination of funds, identify illicit activity, build cases, and construct an operating picture of threats. TRM is trusted by leading agencies and businesses worldwide who rely on TRM to enable a safer, more secure world for all.
At TRM, we're on a mission to build a safer financial system for billions of people around the globe. Our next-generation platform, which combines threat intelligence with machine learning, enables financial institutions and governments to detect cryptocurrency fraud and financial crime on an unprecedented scale.
The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Enterprise Security Engineer to join our growing team, laying the foundation for all things enterprise security. You’ll work on securing our corporate software, services, tooling, and infrastructure, having a critical part in our security posture at TRM.
Job Summary:
- TRM’s Enterprise Security Team secures the identities, endpoints, and core SaaS infrastructure used by every employee and contractor, so the company can move fast without taking unnecessary risk. We operate at the intersection of IT and Security: building secure-by-default systems, automating controls, and reducing operational toil through engineering.
- We’re looking for an Enterprise IT & Security Engineer to help harden and scale our corporate environment. You’ll design and ship identity, endpoint, and SaaS security improvements; codify controls using automation and infrastructure-as-code; and partner closely with Security, Compliance, and engineering teams to continuously raise the security baseline while preserving a great employee experience.
The impact you will have here:
- Engineer secure-by-default endpoint baselines for macOS and Windows Endpoints, including encryption, firewall, application controls, device compliance, and configuration standards.
- Automate and scale identity and access controls in Entra ID and Google Workspace (SSO, SCIM, conditional access, privileged access workflows, access reviews, joiner/mover/leaver).
- Codify security controls as code (Terraform/configuration profiles/policy-as-code), with peer review, change history, testing/rollback, and measurable outcomes.
- Build and maintain automations and integrations (e.g., n8n/SlackOps/APIs/scripts) that reduce manual access grants, speed up control changes, and eliminate repetitive workflows.
- Harden SaaS and collaboration platforms by reducing unmanaged apps and enforcing strong authentication, least privilege, sharing controls, and data protection guardrails.
- Improve visibility and detection by ensuring logging coverage and telemetry for endpoint, identity, and key SaaS applications (e.g., Defender/Sentinel and vendor logs where relevant).
- Drive vulnerability and configuration drift reduction through patch compliance targets, remediation pipelines, and reporting that leadership can act on.
- Partner with compliance and risk stakeholders to produce evidence, document controls, and operationalize requirements without creating brittle, manual processes.
- Participate in an on-call rotation (every ~3 weeks) for escalations related to identity, endpoint security, and critical enterprise systems.
What we’re looking for:
- Demonstrated experience engineering and scaling endpoint management (Jamf and/or Intune) and endpoint security controls for macOS and Windows.
- Strong IAM foundation: hands-on experience with Entra ID (conditional access, SSO, access governance) and Google Workspace and/or Microsoft 365 administration.
- Proven ability to automate real operational workflows using scripting and APIs (Bash, PowerShell, Python, etc.).
- Strong troubleshooting and systems thinking: able to diagnose issues across identity, endpoint, network controls, and SaaS integrations.
- Comfort balancing security and usability using a risk-based approach, communicating tradeoffs clearly to technical and non-technical stakeholders.
Strong Plus:
- Working knowledge of operating Infrastructure-as-Code / configuration-as-code (Terraform preferred; policy-as-code/config profiles acceptable)
- Security Incident Response & Countermeasures experience
- Security Operation Center experience
- Individual pay is determined by skills, qualifications, experience, and location. The compensation details listed in this posting reflect the US base salary only
- The estimated base salary range for this role is $120,000 - $140,000
- Additionally, this role may be eligible to participate in TRM’s equity plan.
- Please note – we factor in the different costs for geographies outside the United States.
Life at TRM
We are building a safer world. That promise shows up in how we work every day.
TRM runs fast. Really fast. We’re a high‑velocity, high‑ownership team that expects clarity, follow‑through, and impact. People who thrive here are energized by hard problems, experimentation, and direct feedback. If something takes months elsewhere, it often ships here in days.
That pace isn’t for everyone. If you are optimizing primarily for consistent work-life balance, use the interview process to pressure-test fit. We want teammates who thrive here, not just survive here.
Leadership Principles
We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.
- Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.
- Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday.
- Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one‑team mindset — giving and receiving feedback to make the team stronger.
Learn more: Interviewing at TRM: How We Hire and What Success Looks Like
The impact you will have
This work has real stakes. Depending on your role at TRM, your week might look like:
- Driving critical investigations that can’t wait for typical business hours.
- Shipping products in days when others would schedule quarters.
- Partnering with teams across time zones to deliver insights while the story is still unfolding.
- Building new solutions from first principles when the playbook doesn’t yet exist.
- Protecting victims and customers by tracing illicit activity and disrupting criminal networks.
Join our Mission
At TRM we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.
TRM is a Series C company with $220M in total funding, backed by Blockchain Capital, Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.
Recruitment agencies
TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.
Privacy Policy
By submitting your application, you are agreeing to allow TRM to process your personal information in accordance with the TRM Privacy Policy
Learn More: Company Values | Interviewing | FAQs
Create a Job Alert
Interested in building your career at TRM Labs? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field
.png?1722463952)