- Harden and manage endpoints across the fleet (macOS, and others as needed) including baseline hardening, device posture, EDR coverage, and tuning.
- Own corporate identity and access management, including SSO/MFA, least-privilege access, and identity hygiene across the SaaS stack.
- Secure and standardize enterprise systems and SaaS environment while driving Zero Trust and device-trust patterns.
- Build automation and tooling to enforce security configuration and scale controls without slowing the team down.
- Handle enterprise security operations including detection, monitoring, and response for corporate systems.
- Serve as the internal security SME on corporate systems and workflow decisions.