Senior Enterprise Security Engineer
Job description
About the role
Faire is actively seeking a security professional to manage corporate environments and provide strategic leadership in the governance of artificial intelligence usage across the organization. The successful candidate will serve as the primary owner for implementing zero trust principles and establishing secure-by-default standards that govern how technology is used within the business. You will act as a critical bridge between technical teams and business stakeholders, working closely with IT, Engineering, Legal, and Finance to design and build practical, enforceable security controls. This role requires a balance of technical depth and strategic thinking to navigate the evolving landscape of enterprise security and emerging AI technologies. You will own the policies, procedures, and technical baselines that ensure the organization operates securely while enabling innovation. The position demands a proactive mindset to identify gaps before they become incidents and to translate complex security concepts into actionable guidance for non-technical teams. Ultimately, you will be responsible for fostering a security culture that is collaborative, pragmatic, and aligned with the company's growth objectives.
Key facts
What you'll do
- Develop and manage the enterprise AI governance program, overseeing risk reviews for models and third-party vendors while ensuring data protection and defining secure integration patterns.
- Strengthen corporate infrastructure by collaborating with IT on identity services, network architecture, and endpoint management to reduce the overall attack surface.
- Design, implement, and maintain security controls that prevent unauthorized access and mitigate the risk of data misuse across cloud and on-premises environments.
- Operate and optimize the email security stack, including configurations for advanced threat protection, while running phishing awareness programs and monitoring endpoint detection and response tools.
- Create and enforce security guardrails that enable teams to experiment with AI tools safely, balancing innovation velocity with risk management.
- Provide clear, actionable security guidance to staff regarding the proper use of office hardware and the configuration of endpoint protection agents.
- Conduct regular security training sessions for employees and stakeholders, maintaining awareness of emerging threats, with a specific focus on AI-specific risks such as adversarial attacks and data leakage.
- Partner with legal and compliance stakeholders to ensure that security practices meet regulatory expectations and industry standards.
- Analyze security incidents and near misses to identify root causes and recommend improvements to policies, tools, and training.
- Collaborate with engineering teams to embed security into the software development lifecycle through secure coding practices and code reviews.
- Monitor the threat landscape and intelligence feeds to proactively adjust defenses and prioritize remediation efforts based on risk.
- Manage relationships with security vendors and evaluate new technologies that can enhance the organization's security posture.
- Document security architectures, controls, and procedures to ensure clarity, consistency, and audit readiness.
- Support the collection and analysis of security metrics to measure program effectiveness and drive data-informed decisions.
Requirements
- Bring 5+ years of professional experience in enterprise security, demonstrating a consistent track record of managing complex security initiatives.
- Show proficiency in at least two of the following domains: threat management, security operations, data security, network security, endpoint security, or AI governance.
- Possess hands-on experience with enterprise AI security, including the implementation of prompt guardrailing and the management of AI platforms in production environments.
- Have a background in supporting audits and drafting the necessary documentation to achieve SOC 2 Type II, SOX, or ISO 27001 compliance.
- Demonstrate the ability to write code in Python, Ruby, or Go to develop scripts and tools that solve real-world security problems.
- Exhibit strong verbal and written communication skills, with an outcomes-oriented mindset that drives execution and accountability.
- Understand the fundamentals of identity and access management, including the implementation of least privilege principles and role-based access controls.
- Are comfortable working in ambiguous situations and making reasoned decisions with incomplete information while maintaining a high level of integrity.
Nice to have
- Preferred experience with cloud security platforms and infrastructure as code tools.
- Familiarity with security frameworks such as NIST, CIS, or MITRE ATT&CK.
- Knowledge of secure software development practices and DevSecOps pipelines.
Practical notes
Employees are permitted to work remotely for up to 4 weeks per year. Some IT and Workplace roles may require 5 days of onsite attendance. Applicants requiring reasonable accommodation during the hiring process should use the form linked on the Faire careers page.