Staff/Lead Enterprise Security Engineer
Indexed description
At its core, the job is preventing, detecting, and responding to threats across Beacon's corporate and cloud environments and its portfolio companies, and owning the security stack that makes that possible. You will develop, maintain, and scale that stack across a complex multi-cloud, multi-SaaS environment, shape its architecture, and own the technical roadmap as Beacon grows.
We run lean, so automation is the point, not a nice-to-have. This role is proactive and engineering-driven, not alert-babysitting. You automate the repetitive work and keep tightening the playbooks and levers as new patterns and information emerge, so the systems get sharper over time instead of just louder. You experiment, iterate, and build creatively.
You will report to the VP of IT and Integration and work with everyone from Beacon engineering to portfolio company team members.
What Enterprise Security Owns
This is the full remit of Enterprise Security at Beacon, and it is deliberately broad. It is more than one person does at once, and we know that. As the first member of the team, you start the program: you stand up the essentials, build the highest-leverage pieces first, and shape the rest into the roadmap. You are not expected to do all of it at once.
- Own prevention, detection, and response across corporate and cloud: tune the detection stack, write detection logic, own triage, and get telemetry into the SIEM
- Own the endpoint security stack (EDR, DLP, secure browser, hardening) and the technical roadmap for security tooling.
- Lead incident response: own readiness (playbooks and tabletops) and drive the response when something fires, pulling in IT, engineering, and portfolio teams as needed.
- Set and confirm the security standards for identity and access (MFA, SSO, SCIM lifecycle, least-privilege), and build the monitoring and reporting on top.
- Run security across the portfolio: baseline audits at onboarding, ongoing monitoring, and SaaS risk at scale (SSPM, OAuth, shadow IT, drift).
- Own the email security and phishing awareness program.
- Run vendor security review for new tools.
- Highly independent. You set priorities against a broad surface and a fast M&A cadence without being told what matters.
- Confident and credible with people outside your team. You can represent security to portfolio founders and engineering leads and bring them along.
- Deep, hands-on security engineering across endpoint, detection and response, identity, cloud, SaaS, and email, and the ability to build tooling and automation from scratch.
- A high bar for the craft: threat modeling, secure design, detection quality, and IR rigor.
- Comfortable in greenfield and ambiguity. You would rather define a program than inherit one.
- Humility: We acknowledge that the path to getting to the right answer involves being wrong along the way. We have strong beliefs which are weakly held. We actively seek new ideas and believe we can learn from anyone at any time.
- Honesty: We are truth seeking in our approach to business problems. Business is a repeat game and we believe that human relationships generate alpha. We understand that trust is earned over a lifetime and can be lost in an instant.
- Hunger: We play to win. We hold ourselves to high standards and will not be outworked. We take pride in having a deep sense of responsibility to ourselves, each other, our partners, and our customers. We believe to whom much is given much is expected.
- Horizon: We seek to build a generational software company. This will take decades. We manage our expectations and those of our partners to take advantage of the 8th wonder of the world - compounding growth.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search