The opportunity
Crusoe is on a mission to accelerate the abundance of energy and intelligence . As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads.
What you'll do
Leading the design and implementation of Zero Trust Network Access (ZTNA) and: Secure Access Service Edge (SASE) architectures, replacing legacy VPNs with identity-aware, perimeter-less access models
Architecting preventative SaaS security across platforms such as Google: Workspace, Slack, and Okta, including CASB controls to enforce data protection and monitor unauthorized applications or extensions
Implementing Binary Authorization and device trust mechanisms, leveraging: hardware-backed identity (e.g., TPM, Secure Enclave) to ensure only compliant devices can access corporate systems
Designing and tuning Data Loss Prevention (DLP) controls across endpoints and: SaaS platforms to protect intellectual property
Strengthening email security posture, including MFA enforcement and session: controls to mitigate phishing and session hijacking risks
Architecting AI-native security frameworks, including governance and secure: gateways for agent-based systems (e.g., MCP), ensuring all AI-driven actions are auditable and aligned with zero-trust principles
What they're looking for
- Scaling identity and access management systems, including SSO, SAML, OAuth,: SCIM, and designing Just-In-Time (JIT) access workflows to eliminate standing privileges
- Defining and executing a “Crown Jewels” security methodology, identifying and: remediating high-risk vulnerabilities (e.g., IDOR, role-bypass) across critical systems
- + years of experience designing and implementing Zero Trust, SASE, and modern: identity-based security architectures
- Strong expertise in SaaS security, including CASB, DLP, and governance across: platforms like Google Workspace, Okta, and Slack