
Paranoids Endpoint Security Engineer
- 🇺🇸 United States
- On-site
- 1 day ago
- AI
- Claude
- triage
- Zero Trust
- MacOS
- Windows
- Jamf
- Intune
- Google Workspace
- Okta
- SAML
- Gemini
- Databricks
- AWS
- GCP
- Kubernetes
- Pension
A Little About Us
Yahoo reaches hundreds of millions of people every day, and that scale makes us a constant target for attackers of every kind, at every layer of our systems. Our job is to protect our users and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo, known asThe Paranoids.
Within Cyber Resilience, our team is responsible for the security of the laptops and browsers Yahoo employees use every day, and we’re growing the team to take that program further.
A Lot About You
We’re looking for someone who wants to own a security program end to end. You’ll lead the rollout of a new browser security platform, running the proof of concept with our device management partners and carrying it through to full production. From there, you’ll become our source of truth for endpoint security: owning the program in steady state, building the policies the platform runs on, and taking on each new milestone as our endpoint hardening roadmap grows. You’ll build relationships across teams to get security work prioritized and delivered, make pragmatic calls that balance security with how people actually get work done, and stay curious about the browser and endpoint threat landscape with a bias toward fixing root causes.
- Building and tuning the policies our browser security platform runs on, and partnering with our device management team to move a rollout from pilot devices to the full fleet
- Automating and refining how we review and score browser extension requests, using AI tools to make that process automated over time
- Reviewing and validating AI-generated policy logic, scripts, and rule changes before deployment, to make sure the output is accurate and doesn’t introduce a policy bypass
- Partnering with identity, legal, and communications teams to take the next milestone on our security roadmap from design to launch
- Triaging exceptions from employees and business stakeholders, and updating the underlying policy so the same issue doesn’t keep coming back as a one-off request
- Partnering with IT across the full laptop lifecycle, from secure provisioning and hardware-backed encryption to application blocking and secure data sanitization when devices or drives are retired or reused
- Reporting on fleet risk posture and program progress to security leadership
- AI-Augmented Automating: Develop and refine AI-assisted workflows using enterprise AI tools (e.g., Claude) to automate the review, risk-scoring, and triage of browser extension requests and endpoint policy exceptions.
- Triage incoming requests for endpoint security related exceptions and reviews
- Support team initiatives for Container Security and Cloud Security
This role is what you make of it. Our endpoint hardening program has a multi-year roadmap ahead of it, and you will have real ownership over how it evolves and where it goes next.
Basic Qualifications
- Bachelor’s degree in a technical discipline (i.e., Computer Science, Engineering, Information Security) or equivalent practical experience.
- Direct experience with one or more enterprise browser security or zero-trust access platforms, such as LayerX, Spin.AI, Island, Talon, NordLayer, or similar
- 4+ years of experience in information security, specifically within endpoint security or security engineering.
- Hands-on experience hardening and managing macOS and Windows endpoints at enterprise scale, with an emphasis on security best practices and policy requirements, using MDM platforms such as Jamf or InTune, and administering browser policy through consoles like Google Workspace or Chrome Enterprise
- Solid understanding of laptop hardware and the operating systems that run on it, including hardware security features such as TPM 2.0, the Apple Secure Enclave, Secure Boot, and firmware protections, and full-disk encryption with FileVault or BitLocker, including recovery key escrow
- Experience with application control on macOS and Windows, such as allowlisting or blocklisting with Santa, Microsoft App Control for Business (formerly WDAC), or AppLocker, including running policies in audit mode before moving to enforcement
- Working knowledge of media sanitization and device disposal best practices, such as NIST SP 800-88, including when cryptographic erase is sufficient and when physical destruction is required for retired laptops and drives
- Working knowledge of how browser extensions actually work, including manifest permissions and content scripts, and how the security model differs across Chrome, Firefox, Safari, and Edge
- Experience with enterprise identity providers such as Okta or SAML, and how they intersect with device and browser management
- Experience defining and enforcing policies for removable media and data transfer paths, including USB device control, to reduce unauthorized data movement.
- Experience with endpoint or browser-based data loss prevention: what it can and cannot catch, and how to tune policy without breaking legitimate work
- Strong communication skills, with the ability to work through security tradeoffs with engineers and non-technical stakeholders alike
- Experience using enterprise AI tools such as Claude to automate repetitive work and speed up investigations
- Practical experience utilizing enterprise AI platforms (e.g., Claude, Gemini) for structured prompting, log analysis, policy generation, or administrative workflow automation.
Preferred Qualifications
- A certification specific to endpoint or device management, such as Jamf Certified Admin, Microsoft Certified: Endpoint Administrator Associate, or GIAC GCWN (Certified Windows Security Administrator), or equivalent hands-on experience
- Comfort working with large-scale data platforms such as Databricks or similar to build reporting and track program metrics
- Experience with cloud based security infrastructure, with prior experience working in both AWS and GCP
- Familiarity with container security, kubernetes and how the container lifecycle works
- Experience with device provisioning and lifecycle programs such as Apple Business Manager, Windows Autopilot, and Activation Lock management, and working with IT asset disposition (ITAD) vendors that provide certificates of sanitization
- Demonstrated experience engineering prompts or scripting automated workflows that integrate AI capabilities into security operation pipelines.
The material job duties and responsibilities of this role include those listed above as well as adhering toYahoopolicies;exercising sound judgment;working effectively, safely and inclusively with others;exhibitingtrustworthinessandmeeting expectations;and safeguarding business operations and brand integrity.
At Yahoo, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a Yahoo office or facility. If you have any questions about how this applies to the role, just ask the recruiter!
Yahoo is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category.Yahoo will consider for employment qualified applicants withcriminal histories in a manner consistent with applicable law.Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment. If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call+1.866.772.3182. Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response.
We believe that a diverse and inclusive workplace strengthens Yahoo and deepens our relationships. When you support everyone to be their best selves, they spark discovery, innovation and creativity. Among other efforts, our 11 employee resource groups (ERGs) enhance a culture of belonging with programs, events and fellowship that help educate, support and create a workplace where all feel welcome.
The compensation for this position ranges from $111,000.00 - $231,250.00/yr and will vary depending on factors such as your location, skills and experience.The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions. Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.Currently work for Yahoo? Please apply on our internal career site.
Paranoids Endpoint Security Engineer · Yahoo EMEA Ltd (Ad Tech)