Join Gecko Robotics: Secure the Future of Critical Infrastructure
At Gecko Robotics, we're not just building technology; we're fortifying the backbone of civilization. Our mission is to ensure the availability, reliability, and sustainability of the world's most critical infrastructure. We achieve this through a revolutionary blend of wall-climbing robots, cutting-edge sensors, and an AI-powered data platform, giving our customers an unparalleled view into the health of their physical assets. This empowers real-time decision-making, significantly boosting operational efficiency and safety, guaranteeing mission readiness, and safeguarding our planet from the profound impact of infrastructure failure.
Your Mission as an Enterprise Security Engineer
Are you a proactive cybersecurity professional passionate about building robust defenses and enabling innovation? Gecko Robotics is seeking an **Enterprise Security Engineer** to join our InfoSec Engineering team. You'll play a pivotal role in designing, implementing, and operating the shared security systems that protect our people, devices, applications, and highly sensitive data.
Working closely with IT Engineering, your primary focus will span workforce endpoint and device security, identity security, comprehensive SaaS and OAuth governance, advanced enterprise detections, and the stringent protection of regulated data. Our philosophy is clear: security should be an enabler, not a roadblock. We strive to create trustworthy, secure pathways that accelerate the company's growth and maintain compliance, eliminating unnecessary barriers.
A critical aspect of this role involves spearheading the responsible adoption of AI tools. You will be instrumental in establishing the systems, guardrails, and guidance necessary for Gecko to fully leverage emerging technologies without compromising sensitive data or introducing unacceptable security, privacy, contractual, or compliance risks.
What You'll Achieve: Key Responsibilities
Fortify Endpoints & Devices: Architect, configure, and manage advanced endpoint-management, device-compliance, browser-security, and endpoint detection and response (EDR) controls to harden workforce devices and shared enterprise systems.
Elevate Identity Security: Own and continuously enhance our identity security posture, including Okta policies, Multi-Factor Authentication (MFA), Conditional Access, and lifecycle management. Establish practical governance for SaaS applications, OAuth access, browser extensions, and other third-party technologies.
Enable Secure Innovation: Develop clear, secure, and user-friendly pathways that empower employees to adopt approved AI tooling and other emerging technologies, all while meticulously protecting regulated and sensitive data and adhering to security, privacy, contractual, and compliance obligations.
Streamline Security Workflows: Translate complex security requirements into effective configurations and automated workflows. Partner strategically with IT Engineering to solve shared challenges, reduce recurring friction, and ensure security controls are efficient and easy to operate.
Drive Threat Detection & Response: Build and fine-tune enterprise-wide detection rules, proactively evaluate alerts and control gaps, and lead corporate-side incident response. Make proportionate risk decisions and coordinate swift remediation with affected system owners.
Collaborate Across Domains: Engage and partner with Product Security, Cloud Infrastructure, IT, and Facilities teams when enterprise security concerns intersect with applications, cloud services, engineering systems, or physical security.
Govern Emerging Tech: Establish and maintain robust governance frameworks for the secure adoption and use of AI tools and other rapidly evolving workplace technologies, ensuring all security, privacy, and compliance requirements are met.
Travel & Engage: Be prepared for occasional travel (up to 20%) to Gecko offices and other locations to support critical enterprise security initiatives, physical security projects, incident response efforts, and cross-functional collaboration.
Your Technical Toolkit & Framework Expertise
While experience with every technology or framework isn't required, familiarity with the following will be highly beneficial:
Identity Management: Okta, Onelogin, Active Directory
MDM Systems: Jamf, Intune, NinjaOne
EDR/MDR Tools: CrowdStrike, TrendMicro, SentinelOne
AI Management: Claude, ChatGPT, Cursor, Grok (and related governance strategies)
Government Security Frameworks: FedRAMP, CMMC, NIST 800-171, NIST 800-53, CUI handling
Commercial Security Frameworks: SOC2 Type II, ISO 27001, ISO 42001
Who You Are: Bringing Your Expertise to Gecko
Required Skills
Experience: 3+ years of hands-on experience in Enterprise Security Engineering, Security Engineering, IT Security, or a closely related role.
Endpoint Management: Proven expertise in administering endpoint management and endpoint detection and response (EDR) solutions within production environments.
IAM Proficiency: Extensive experience administering or securing Identity and Access Management (IAM) platforms, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and lifecycle management.
SaaS & OAuth Governance: Demonstrated experience evaluating, governing, or administering SaaS applications, OAuth integrations, and enterprise security controls.
Regulated Data: Experience working with regulated, customer-protected, or other sensitive data (e.g., CUI, HIPAA, PCI, SOC 2).
Technical Acumen: Strong systems configuration, troubleshooting, workflow design, and operational ownership skills.
Strategic Balance: A proven ability to balance stringent security and compliance requirements with critical business needs and a positive user experience.
Communication: Excellent written and verbal communication skills, with a track record of effective partnership across Security, IT, Engineering, Compliance, Legal, and other cross-functional teams.
Preferred Skills (Bonus Points!)
AI Governance: Experience governing AI tools or other rapidly adopted workplace technologies.
Industry Experience: Background in government, defense, critical infrastructure, or another highly regulated industry, including familiarity with CUI, CMMC, FedRAMP, NIST, SOC 2, or ISO 27001.
EDR Platform Expertise: Hands-on experience administering CrowdStrike Falcon, Microsoft Defender, SentinelOne, or another leading enterprise EDR platform.
IAM/MDM Platform Expertise: Experience administering Okta, Microsoft Intune, Jamf, or comparable identity and endpoint management platforms.
Advanced Security Tech: Familiarity with DLP, CASB, browser security, or SaaS/OAuth governance technologies.
Automation Skills: Experience automating security or IT workflows using Python, PowerShell, Bash, or similar scripting languages.
Startup Environment: Experience working on a small, high-growth, or startup team where security processes, tooling, and ownership were built from the ground up.
Life at Gecko: Innovation, Impact & Growth
At Gecko, our people are our most valuable asset. We invest in your success with competitive compensation packages, company equity, 401(k) matching, gender-neutral parental leave, comprehensive medical, dental, and vision insurance, mental health support, ongoing professional development, family planning assistance, and flexible paid time off.
We thrive on collaboration, innovation, and partnership, believing that our best work happens when we're together in person. While we cherish our office-first culture, we also understand the need for flexibility. Many team members are in the office five days a week, while others appreciate a more hybrid approach. Ultimately, we are driven by the outcomes we achieve and foster a culture of autonomy and trust that empowers significant impact.
Gecko is deeply committed to cultivating a culture of inclusion and belonging, and we are proud to be an equal opportunity employer. We believe it is our collective responsibility to uphold these values and actively encourage candidates from all backgrounds to join us in our critical mission: to protect today’s infrastructure and give form to tomorrow’s. All qualified applicants will be treated with respect and receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, veteran status, age, or any other protected characteristic per federal, state, or local law. If you are passionate about what you do and aspire to use your talents to support our vital mission, we would be thrilled to hear from you.