RefolkCandidates
Open nowEngineeringSecurity

Security Engineer, Enterprise

Persona · San Francisco, California

Location
San Francisco, California, United States
Workplace
Hybrid
Employment
Full time
Level
Mid level
Posted
3 months ago

About this role

About Persona

Persona is the configurable identity platform built for businesses in a digital-first world. Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly.

We’ve built Persona to support practically every use case and industry - that’s why we’re able to serve a wide range of leading companies. For example, Reddit relies on Persona for age assurance and verification to comply with online safety regulations, protecting younger users while maintaining a seamless experience. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world’s most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live.

We’re growing rapidly and looking for exceptional people to join us!

About the Role

Persona builds identity verification infrastructure where security isn't a layer we add later, it's core to everything we ship. When security fails at most companies, systems go down. At an identity verification company, real people's identities are compromised.

This is an enterprise security role embedded in a generalist security team. You'll work alongside experienced security engineers to defend Persona's people, devices, and systems against evolving threats - and build the tooling and automation that lets us do it at scale.

What you’ll work on

  • Develop, tune, and operate endpoint detection and response (EDR) rules and tooling across our macOS environment

  • Partner with TechOps to implement security best practices across SaaS and endpoint environments, including 2FA enforcement, automated device encryption, and DLP. You will develop and deploy these controls - not ask other teams to do so for you

  • Build tools and automation to scale security controls and monitoring without scaling headcount

  • Harden corporate infrastructure and SaaS applications against attack

  • Translate endpoint and SaaS telemetry into actionable mitigations and control recommendations

  • Build and operate insider threat detection and response programs

Must-haves

  • 3+ years of experience in IT security, corporate/enterprise security, or a related technical role. We'll flex on years of experience and specific tool background for candidates who demonstrate strong fundamentals, high aptitude, and a track record of figuring things out fast

  • Hands-on experience with macOS endpoints, MDM platforms, and EDR tooling

  • Experience with endpoint hardening. You’ve hardened endpoints, not written requirements asking someone else to do it

  • Experience with DLP concepts and insider threat scenarios

  • Experience with email security fundamentals and social engineering defense

  • Ability to write scripts and automate workflows in Python, Ruby, Bash, or similar; comfortable with SQL

  • Communicates clearly about security topics with non-technical stakeholders

  • Experience in a high-growth startup or other fast-moving, resource-constrained environment

Nice to have

  • Familiarity with identity and access management tooling (Okta, SCIM provisioning, SSO)

  • Experience with Zero Trust or network access tools (Twingate, Cloudflare Access, or similar)

  • Exposure to SIEM platforms, log aggregation, or detection engineering

  • Familiarity with SaaS security posture management (SSPM) or CASB concepts

  • You've worked somewhere where PII or sensitive data was the core product

The team

Small and senior by design. High ownership from day one - this isn't a team where your work disappears into a large org.

Based in SF. Relocation assistance available. Our in-office days are Tuesday - Thursday, with the option to work from home on Monday and Friday.

Benefits and Perks

For full-time US-based employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others.


For full-time UK employees, Persona offers a wide range of benefits, including private medical insurance, dental insurance, a 6% employer pension contribution, unlimited PTO, a monthly wellness stipend, professional development stipend, co-working stipend, and more.


As part of our interview process, all candidates will be asked to verify their identity with Persona. This step is used solely to confirm that candidates are who they say they are, and will have no impact on hiring decisions.

As published by Persona. Applications are handled on their site.

Skills this posting mentions

BashArtificial IntelligenceRuby

About Persona

Persona helps businesses manage KYC/AML/KYB programs, fight fraud, and build trust by automating any identity-related use case with our flexible identity infrastructure. For example, we help Coursera verify learners’ identities before delivering course credentials and Brex comply with strict international KYC/AML regulations. Beyond securely collecting and verifying user information such as PII, government IDs, and selfies, our platform also provides flexible case review and orchestration tools to help businesses streamline and automate all their identity operations - from setting custom rules to ingesting third-party data and triggering external actions. In short, Persona handles the complexities of securely collecting, verifying, and managing sensitive personal information, so you can stay focused on building your product.

All 19 openings at Persona

One click, then it is written

Apply to Persona with a resume written for this role.

Queue Security Engineer, Enterprise and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Persona’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Persona

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Persona publishes. Refolk is not the employer and does not handle their hiring. Applications go to Persona directly.