Navan Logo

Navan

Senior Security Engineer

Posted 3 Days Ago
Be an Early Applicant
Easy Apply
Hybrid
2 Locations
128K-230K Annually
Senior level
Easy Apply
Hybrid
2 Locations
128K-230K Annually
Senior level
The Senior Corporate Security Engineer will manage IAM systems, secure corporate devices, implement Zero Trust models, and develop security solutions to enhance organizational security.
The summary above was generated by AI

About Us

Navan is a modern, dynamic SaaS company revolutionizing the way businesses manage travel and expenses. With offices around the world, we are committed to creating seamless and innovative solutions for our clients. Our team is dedicated to fostering a collaborative and inclusive environment where everyone's contributions are valued.

Role Overview

We are seeking a Senior Corporate Security Engineer to join our team. This role is integral to ensuring the security of our corporate environment across all devices, applications, and networks. The ideal candidate will have a deep understanding of enterprise IT security within a modern SaaS company and will be passionate about automating and scaling security processes. You will work on securing our corporate infrastructure, implementing cutting-edge security solutions, and collaborating with various teams to enhance our overall security posture.

What You'll Do
  • Manage Workforce IAM and Identity Governance: Lead the management and optimization of our Workforce IAM and Identity Governance systems, demonstrating deep, hands-on knowledge across the entire Okta platform. You will be responsible for designing and enforcing granular authentication policies, managing the full lifecycle of application access through Okta Access Requests and Entitlements, and leveraging Okta Device Trust to establish a zero-trust security posture for all corporate resources.
  • Federate and Configure Application Access: Integrate a wide range of SaaS and custom applications into our identity platforms, Okta and Microsoft Entra ID, for single sign-on. This requires a strong technical understanding of modern federation protocols including SAML 2.0, OpenID Connect, and SCIM for automated user provisioning.
  • Secure Devices and Endpoints: Develop and implement comprehensive security strategies for a diverse fleet of corporate devices. This includes managing Windows endpoints with Microsoft Intune, macOS devices with Jamf, and ChromeOS devices via the Google Admin console, ensuring all endpoints are protected against unauthorized access and threats.
  • Manage Endpoint Detection and Response (EDR): Lead the deployment, administration, and tuning of our EDR platform, specifically the CrowdStrike Falcon suite. Your responsibilities will include leveraging products like Falcon Insight for incident investigation, Falcon Prevent for next-gen antivirus, and proactive threat hunting to identify and neutralize advanced threats on corporate endpoints.
  • Implement Zero Trust Network Access: Design and deploy Zero Trust security models to enhance network security and safeguard company resources.
  • Deploy Data Loss Prevention Solutions: Implement DLP strategies focusing on protecting PII and PCI data within SaaS applications like Google Workspace, Salesforce, and Box.
  • Enable Large-Scale Endpoint Management: Oversee the deployment and maintenance of secure operating systems and platforms at scale. A key responsibility is to implement and manage a robust patch management strategy across all corporate operating systems (Windows, macOS, ChromeOS), ensuring timely remediation of vulnerabilities to reduce the company's attack surface.
  • Orchestrate Security Posture Checks: Automate security checks for all new infrastructure deployments to ensure compliance with security standards.
  • Implement Endpoint State Attestation: Deploy tooling, such as Microsoft Entra Conditional Access and Intune compliance policies, to continuously validate the security state of endpoints.
  • Scale Proactive Security Controls: Extend security measures to new environments, including those acquired through mergers or acquisitions.
  • Stay Current with Industry Trends: Keep abreast of the latest security threats, technologies, and trends to proactively address potential vulnerabilities.
  • Develop Custom Security Solutions: Contribute to the development of custom and open-source security tools tailored to our needs.
What We're Looking For
  • Experience: Minimum of 5 years of experience in corporate security engineering within a SaaS or similar environment.
  • Technical Expertise:
    • Expert-level proficiency with the Okta platform for workforce Identity and Access Management (SSO, MFA, IGA) Okta Certification is a strong plus.
    • Demonstrated experience designing and implementing complex access management automation and workflows, with a strong preference for candidates skilled in Okta Access Requests and Okta Workflows.
    • Strong knowledge of securing devices and endpoints, including hands-on experience with Mobile Device Management platforms like Microsoft Intune.
    • Familiarity with Microsoft Entra ID in hybrid or multi-cloud environments.
    • Experience with securing Google Workspace and Microsoft 365/Enterprise Suite.
    • Hands-on experience implementing an enterprise zero trust network access solution such as ZScaler is a strong plus.
    • Understanding of Zero Trust Network Access models.
    • Experience with infrastructure management tools (Puppet, Chef, Ansible, Terraform).
    • Knowledge of Data Loss Prevention strategies in SaaS applications.
    • Experience with vulnerability management tools and methodologies.
    • Automation Mindset: Passion for automating processes to improve efficiency and scalability.
    • Communication Skills: Ability to effectively communicate complex security concepts to technical and non-technical stakeholders, including collaboration with the physical security team.
    • Problem-Solving Abilities: Demonstrated ability to identify security risks and develop effective mitigation strategies.
  • Certifications:
    • Highly Desirable: Okta Certified Professional or Higher, Microsoft Security Certifications
    • Nice to Have: CISSP, CISM, or similar security certifications.
  • Education: Bachelor's degree in Computer Science, Information Security, or a related field preferred.

Why Navan?

  • Innovative Environment: Be part of a team that's shaping the future of business travel and expense management.
  • Global Impact: Work on projects that have a worldwide reach and influence.
  • Collaborative Culture: Join a diverse team where your ideas and contributions make a difference.
  • Professional Growth: Opportunities for learning and development to advance your career.
  • Comprehensive Benefits: Competitive salary, health benefits, and other perks.


The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.
For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.

Pay Range
$127,500$230,000 USD

Top Skills

Ansible
Chef
Crowdstrike Falcon
Data Loss Prevention
Google Admin Console
JAMF
Microsoft Entra Id
Microsoft Intune
Okta
Openid Connect
Puppet
Saml 2.0
Scim
Terraform
HQ

Navan Palo Alto, California, USA Office

3045 Park Blvd, Palo Alto, CA, United States, 94304

Navan San Francisco, California, USA Office

181 Fremont St. 23rd Floor , San Francisco, CA, United States, 94105

Similar Jobs at Navan

7 Hours Ago
Easy Apply
Hybrid
Palo Alto, CA, USA
Easy Apply
101K-175K Annually
Mid level
101K-175K Annually
Mid level
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Join our team as a Frontend Engineer, designing and developing features for our platform. Collaborate with teams, write high-quality code, and resolve production issues.
Top Skills: AngularClaudeCodegptCursorGithub CopilotNxReactTypescriptVueWebpack
7 Hours Ago
Easy Apply
Hybrid
San Francisco, CA, USA
Easy Apply
105K-209K Annually
Senior level
105K-209K Annually
Senior level
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
The Senior Social Media Manager will create and execute social media strategies, manage content, oversee budgets, and analyze performance to enhance brand presence and customer engagement.
Top Skills: Adobe Creative SuiteBrandwatchCanvaCapcutLinkedInRedditSprinklrSprout SocialX
7 Hours Ago
Easy Apply
Hybrid
2 Locations
Easy Apply
134K-168K Annually
Mid level
134K-168K Annually
Mid level
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
The Account Manager will drive revenue by enhancing client relationships, managing T&E programs, executing renewals, and identifying growth opportunities.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account