Sr. Security Engineer, Corporate SecurityActive

The opportunity

At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.

What you'll do

  • Collaborate with teams across Lyft to ensure security best practices are: leveraged as we roll out new features and expand our service offerings

  • Own the security posture of Lyft's SSO/MFA platform: authentication policies, device trust and posture checks, MFA factor strategy, and phishing-resistant authentication rollout.

  • Proactively research new attack vectors that may affect Lyft

  • Develop detections for identity-based attacks: MFA fatigue, session token theft, phishing-driven account takeover, and abuse of privileged admin roles

  • Deploy, tune, and operate Lyft's EDR platform across macOS and Windows: fleets, balancing detection efficacy against user experience and endpoint performance

  • Own the operational health of the agent fleet: coverage gaps, version and policy drift, check-in failures, and remediation workflows with IT

What they're looking for

  • Operate and tune Lyft's DLP tooling to detect and prevent unsanctioned movement of company data
  • Write code to integrate corporate security tooling, pushing telemetry into: the data platform, enriching alerts, and automating response so that detection and remediation scale without headcount
  • Build and maintain relationships with key partners both internally and externally
  • Define and report metrics on control coverage, detection efficacy, and mean: time to remediate; present findings and recommendations to engineering and leadership