Skip to content

DepthFirst

Senior Software Engineer, Corporate Security

Location
San Francisco, CA, US
Arrangement
On-site
Employment type
Full-time
Level
Senior
Posted
23 September 2026 (7 days ago)

Checked 7 days agoApplications go to the employer, never to RoleSprint

About this role

About depthfirst

We believe that software is the foundation of modern civilization. Yet vulnerabilities threaten its integrity, security, and resilience. We are on a mission to secure the world's software.

depthfirst is building intelligence to detect and remediate critical software vulnerabilities. We are training and scaling security AI agents to discover zero-day vulnerabilities across large customer codebases and popular open source software.

Our founding team brings deep expertise in data, infrastructure, security and AI, with leaders from DeepMind, Databricks, Square, and Faire. We're looking for thoughtful, driven people excited to work at the intersection of AI, Security, and Infrastructure.

About This Role

As one of our first security engineers, you'll own corporate security at depthfirst, protecting the identities, devices, and applications our team relies on every day. You'll build the tooling, integrations, and automation that keep workforce access, endpoints, and enterprise apps secure by default as we grow.

You're excited about this role because you will...

- Shape our corporate security foundations as one of our first security engineers, protecting the devices, identities, and applications our team relies on every day.

- Strengthen workforce identity and access management through Okta and SSO, including phishing-resistant authentication, least privilege, and automated access provisioning and removal.

- Build and maintain endpoint security controls through mobile device management (MDM) and endpoint detection and response (EDR), improving device configurations, patching, and visibility across our fleet.

- Establish secure configurations for enterprise applications such as Google Workspace, Claude Cowork, and Codex, with appropriate controls for administrative access, data sharing, and integrations.

- Write and maintain software, integrations, and automation that enforce security policies, identify configuration gaps, and reduce manual work across identity, device, and application management.

Qualifications

- Strong software engineering skills and experience building reliable internal tools, API integrations, and automation to solve security or infrastructure problems.

- Hands-on experience with Okta or similar identity platforms, including SSO, MFA, access policies, and identity lifecycle management; familiarity with SAML, OIDC, and SCIM.

- Experience securing employee devices through MDM, including configuration enforcement, disk encryption, patch management, and policies that use device security posture to control access.

- Familiarity with EDR platforms, including deploying and maintaining coverage, investigating endpoint activity, and supporting containment and remediation.

- Experience securing enterprise SaaS applications and an understanding of the risks introduced by OAuth integrations, excessive permissions, external sharing, and AI tools with access to company data.

- Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences.

Bonus Points For

- Experience at a high-growth startup or early-stage company

- Familiarity with security, infrastructure, or developer tooling markets

What We Offer

- Competitive salary with meaningful equity

- Health, vision, and dental insurance

- Office lunch and dinner (SF office)

- Ownership and significant room to grow as the company scales

—-

depthfirst is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

To all recruitment agencies: depthfirst does not accept agency resumes. Please do not forward resumes to depthfirst employees. depthfirst is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company.

Work location

  • San Francisco, CA, US

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Ashby under the board identifier Depthfirst, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 23 September 2026, last checked 7 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

More searches like this one

Browse all current openings

No credit card requiredStart free