Branch - Corporate Security Engineer
Requirements
• 3–5 years of experience in a corporate security, endpoint security, security operations, or insider risk role with increasing responsibility. • Hands-on experience with EDR — ideally CrowdStrike Falcon — including detection tuning, custom IOAs/IOCs, and Real Time Response investigations. • Working experience with application control or zero-trust endpoint tooling (ThreatLocker, Airlock, AppLocker, or equivalents) — you understand the operational reality of allowlisting at scale. • Familiarity with enterprise / managed browsers (Island, Talon, Chrome Enterprise) and the data-egress and SaaS access controls they enable; comfort designing browser policy is a strong plus. • Strong Google Workspace security background — admin console controls, context-aware access, OAuth governance, and DLP. • Demonstrated ability to investigate incidents end-to-end — phishing, malware, account compromise, DLP events, and insider risk cases — with disciplined documentation. • Solid fundamentals in identity and access management, endpoint hardening, MDM, logging, and SIEM-based detection. • Scripting proficiency in Python and/or Bash for automation and tooling; experience with security orchestration platforms (Tines, Torq, XSOAR) is a plus. • Strong written and verbal communication — able to explain endpoint and insider risk concepts to non-security partners in HR, Legal, and the executive team. • Strong ethics and discretion — this role regularly handles confidential personnel and investigative information. • Familiarity with security frameworks such as ISO 27001, SOC 2, PCI-DSS, NIST CSF, and CIS Benchmarks.
Responsibilities
• Endpoint Security & Engineering • Own the day-to-day administration of CrowdStrike Falcon — prevention policies, detection tuning, custom IOAs, USB device control, and Real Time Response runbooks across the entire Branch endpoint fleet. • Own the day-to-day administration of CrowdStrike Falcon • Operate and mature ThreatLocker — build and maintain application allowlisting, ringfencing, storage control, and elevation policies; reduce learning-mode exceptions over time and drive measurable hardening progress. • Operate and mature ThreatLocker • Administer Island Enterprise Browser — define and enforce browser-level policies for SaaS access, copy/paste, downloads, screenshot, and extension governance; align browser controls with insider risk and DLP objectives. • Administer Island Enterprise Browser • Drive endpoint hardening and configuration baselines for macOS and Windows. MDM (Jamf / Intune), patch SLAs, FileVault/BitLocker, and CIS-aligned benchmarks. • Drive endpoint hardening and configuration baselines • Maintain a defensible inventory of endpoints, agents, and coverage gaps, and drive remediation when devices fall out of compliance. • Maintain a defensible inventory • Own corporate-side incident response for endpoint, identity, email, and insider events — from initial triage through containment, eradication, recovery, and post-incident review. • Own corporate-side incident response • Insider Risk & Data Protection • Build and run Branch’s insider risk program — from defining risk indicators (data exfiltration, anomalous access, departing employee behavior) to building detections and response playbooks across endpoint, browser, and SaaS telemetry. • Build and run Branch’s insider risk program • Operate Data Loss Prevention controls across Google Workspace (Drive, Gmail), Island Browser, and endpoint channels; investigate DLP events end-to-end, balancing user friction against data-protection outcomes. • Operate Data Loss Prevention controls • Lead onboarding, offboarding, transitions security workflows in partnership with People Operations — enforce least-privilege access, data return at offboarding, and time-bounded monitoring of high-risk departures, ultimately skilling up our IAM team • Lead onboarding, offboarding, transitions security workflows • Triage and investigate insider risk cases with discretion, partnering with Legal, HR, and GRC on documentation, evidence handling, and outcomes; preserve chain-of-custody on every case. • Triage and investigate insider risk cases • Develop user-facing guidance and training that reduces accidental risk — phishing reporting, secure handling of customer data, and acceptable use of AI and SaaS tools. • Develop user-facing guidance and training • Security Operations & Engineering • Harden Google Workspace — admin role hygiene, context-aware access, OAuth third-party app governance, advanced phishing/malware protection, and audit logging into the SIEM. • Harden Google Workspace • Automate repetitive corporate security work using Python or Bash and orchestration platforms (e.g., Tines, Torq, XSOAR) — alert enrichment, user notifications, evidence collection, and offboarding checks. • Automate repetitive corporate security work • Contribute to the corporate vulnerability management program for endpoints and SaaS — prioritization, SLA tracking, and cross-functional remediation. • Contribute to the corporate vulnerability management program • Serve as a security consultant and escalation point for the broader business on secure configurations, patching, exception requests, and acceptable-use questions. • Serve as a security consultant and escalation point
Benefits
• The base salary range for this role is $125-135k. The salary range displayed reflects an average base salary range for the position across all the U.S. The base salary offered to an applicant could be higher or lower based on each applicant's specific skill set, depth of experience, relevant education or training, etc. • Location: • This position is classified as REMOTE within the United States of America. • We are unable to hire candidates located outside of the domestic U.S. • Market-leading medical, dental, and vision insurance • Free Premium-Tier Origin Financial Wellness subscription • Monthly home-office stipend • 401k (TransAmerica) • 12-weeks paid parental leave for birthing and non-birthing parents • Flexible time off + sick and safe time • 11 paid company holidays • Branch@Branch Same Day Pay Option • Working at Branch • Working at Branch • A remote-first company with employees located throughout the U.S., Branch emphasizes transparency, accountability, and trust to create a collaborative environment where our product, engineering, marketing, customer support, customer success, and sales teams can all thrive together. Learn more about what we do in this video! • Our collaborative spirit has helped us become an award-winning FinTech company, with Branch’s innovation and workplace recognized across industries. Branch has been honored by Inc., the Webby Awards, Benzinga FinTech Awards, FinTech Breakthrough Awards, Top Workplaces USA, Great Places to Work, and EY Entrepreneur of the Year, Heartland, among others. • Learn more about our culture, approach, technology, and people here: https://www.branchapp.com/about
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT