Paranoids Corporate System Security Engineer II
Yahoo · United States · 1d ago
A Little About Us
When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as "The Paranoids".
A Lot About You
As a Paranoids Corporate System Security Engineer, you help run the review function for everything employees use to get their work done - third-party SaaS, vendor integrations, employee-facing tools, AI/LLM products, and agentic connections entering the corporate environment. You will carry real reviews from day one, with senior reviewers backing you on the harder architecture calls.
Responsibilities
- Perform hands-on security reviews of corporate systems - third-party SaaS, vendor integrations, employee-facing tools, and AI/LLM products - identifying risks, recommending controls, and escalating higher-risk architecture decisions to senior reviewers.
- Own the high-volume tiers of the review queue: intake triage, Okta onboarding, access and support requests, and baseline configuration checks, closing each to a documented disposition.
- Use AI-assisted tooling as a standard part of review work - triaging intake, digesting vendor documentation, and drafting first-pass dispositions - and verify the output before it goes on the record.
- Assist with MCP and agentic connection reviews - checking authentication and authorization, scope and consent, credential handling, and audit coverage against the established review rubric.
- Contribute to internal review tooling, rubrics, runbooks, and documentation, including the precedent library that makes future reviews faster.
- Support the annual corporate-product check-in program and help reconcile the SaaS inventory against review history to surface products that have fallen out of spec.
- Participate in ongoing learning, staying current with emerging threats across corporate SaaS, identity, and AI/agentic tooling.
Basic Qualifications
- 3 years of experience in security review, IT or corporate security, or a related engineering or systems discipline with a focus on secure design or technical solutioning.
- Experience assessing third-party or SaaS products OR internal products - reviewing how a system authenticates, where its data flows, how it works, and what access it is granted.
- Understanding of security fundamentals - authentication, authorization, encryption in transit and at rest, logging, and secure communications.
- Working knowledge of SSO and of MFA enforcement in an identity provider such as Okta.
- Familiarity with AI/LLM application security basics such as sensitive data exposure through model inputs and outputs.
- Awareness of agentic and tool-use patterns (e.g., Model Context Protocol) and the questions they raise about scope, credentials, and audit.
- Hands-on use of AI tools in day-to-day analysis work (summarizing documentation, drafting findings, triage), and the judgment to recognize where they get things wrong.
- Ability to work with product and business owners to explain a requirement, gather what is missing at intake, and validate that a control is actually in place.
- Strong written communication - able to document a review decision so the requester knows whether it blocks, who owns it, and what closes it.
- Ability to manage a queue: prioritize, keep tickets moving, and escalate before something ages out.
Preferred Qualifications
- Demonstrated capability of working with a variety of non-technical experts and resolving queries against standard patterns or runbooks
- Exposure to industry security frameworks (NIST CSF, OWASP, CIS Benchmarks) and to applying them in a real product review.
- Experience with vendor security questionnaires or third-party risk assessment cycles.
- Experience building small automations that reduce repetitive review, reporting, or reconciliation work.
- Industry certifications such as Security+, GWAPT, GCIH, or CCSK a plus, but not required.
The material job duties and responsibilities of this role include those listed above as well as adhering to Yahoopolicies;exercising sound judgment;working effectively, safely and inclusively with others;exhibiting trustworthinessandmeeting expectations;and safeguarding business operations and brand integrity.
At Yahoo, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a Yahoo office or facility. If you have any questions about how this applies to the role, just ask the recruiter!
Yahoo is proud to be an equal opportunity workplace. All qualified applicants will receive consideration for employment without regard to, and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. Yahoo will consider for employment qualified applicants with criminal histories in a manner consistent with applicable law. Yahoo is dedicated to providing an accessible environment for all candidates during the application process and for employees during their employment. If you need accessibility assistance and/or a reasonable accommodation due to a disability, please submit a request via the Accommodation Request Form (www.yahooinc.com/careers/contact-us.html) or call +1.866.772.3182. Requests and calls received for non-disability related issues, such as following up on an application, will not receive a response.
We believe that a diverse and inclusive workplace strengthens Yahoo and deepens our relationships. When you support everyone to be their best selves, they spark discovery, innovation and creativity. Among other efforts, our 11 employee resource groups (ERGs) enhance a culture of belonging with programs, events and fellowship that help educate, support and create a workplace where all feel welcome.
The compensation for this position ranges from $111,000.00 - $231,250.00/yr and will vary depending on factors such as your location, skills and experience.The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions. Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.Currently work for Yahoo? Please apply on our internal career site.