About this role
ABOUT US
At Sierra, we’re creating a platform to help businesses build better, more human customer experiences with AI. We are primarily an in-person company based in San Francisco, with growing offices in Atlanta, New York, London, Paris, Madrid, Munich, Singapore, Tokyo, and Sydney.
We are guided by a set of values that are at the core of our actions and define our culture: Trust, Customer Obsession, Craftsmanship, Intensity, and Family. These values are the foundation of our work, and we are committed to upholding them in everything we do.
Our co-founders are Bret Taylor https://www.linkedin.com/in/brettaylor/ and Clay Bavor https://www.linkedin.com/in/claybavor/. Bret currently serves as Board Chair of OpenAI. Previously, he was co-CEO of Salesforce (which had acquired the company he founded, Quip) and CTO of Facebook. Bret was also one of Google's earliest product managers and co-creator of Google Maps. Before founding Sierra, Clay spent 18 years at Google, where he most recently led Google Labs. Earlier, he started and led Google’s AR/VR effort, Project Starline, and Google Lens. Before that, Clay led the product and design teams for Google Workspace.
WHAT YOU’LL DO
- As the founding Corporate Security Engineer, Lead at Sierra, you will define and build our Corporate Security capability within IT — establishing the operating model, executing the initial roadmap, and shaping the function as it grows over time.
- Own the centralized risk register and drive remediation across SaaS applications, integrations, endpoints, identity, and access paths.
- Secure our SaaS and integration landscape by auditing and governing OAuth applications, Slack integrations, and third-party connections, and by establishing authorization controls and ongoing review processes.
- Design and implement enforcement systems — automation and integrations that continuously enforce controls, detect and revoke unauthorized access, govern OAuth scopes, and monitor integration activity.
- Improve endpoint and user-level visibility, working with existing endpoint management tooling to manage risk from user-installed applications and browser extensions.
- Sequence a broader security roadmap across adjacent domains (DLP, IAM, Zero Trust, vendor security, detection and response, and more), and shape how the team grows over time.
WHAT YOU’LL BRING
- Significant experience in corporate security, IT security, or security engineering, with a track record of building programs or capabilities rather than operating within established ones.
- Strong technical depth across several of the following: identity and access management, SaaS security, endpoint management, DLP, network security, detection and response.
- Demonstrated ability to build tooling and automation that enforce controls, not just define them. You've written code, built integrations, or implemented systems that actively reduce risk in a production environment.
- Experience working within or close