Senior Corporate Security Engineer

Posted 5 days ago

This is a fully remote position, open to applicants in Kazakhstan.

📋 Description

• Establish and take responsibility for security policies, hardening standards, and compliance framework for EDR and MDM throughout the organization.

• Lead endpoint threat response initiatives and collaborate with IT on device enrollment, compliance, and protection measures.

• Manage and enhance IAM/SSO, MFA, provisioning and deprovisioning processes, along with conducting least-privilege access reviews.

• Operate SIEM and detection tools by fine-tuning rules, triaging alerts, and investigating any suspicious activities.

• Coordinate monitoring and escalation processes with the external Security Operations Center (SOC).

• Engage in incident response activities from investigation through containment, remediation, and root cause analysis.

• Contribute to post-incident evaluations and the development of runbooks.

• Operate, integrate, and enhance the corporate security toolkit.

• Proactively strengthen the environment through configuration baselines, access controls, and reduction of attack surfaces.

• Assist with ISO 27001, SOC 2, and related compliance initiatives by managing controls and collecting evidence.

• Collaborate with Compliance on audits and control mapping efforts.

• Track and assist in the remediation of vulnerabilities across endpoints and corporate systems.

• Monitor emerging threats and translate them into actionable security improvements.

• Implement and enhance security awareness training, phishing simulations, and guidance for employees.

• Work in partnership with IT, Product Security, and Compliance within a distributed team structure.

• Extend security operations coverage to US time zones and ensure seamless handoffs with EU counterparts.


⛳️ Requirements

• A minimum of 4 years of experience in corporate/enterprise security, security operations, or IT security engineering roles.

• Practical experience with endpoint security (EDR) on both macOS and Windows platforms.

• Familiarity with device management (MDM); experience managing Linux endpoints is advantageous.

• Solid understanding of IAM/SSO, MFA, modern IAM solutions, and least-privilege access methodologies.

• Proven experience operating SIEM and detection tools, including rule writing, tuning, alert triaging, and investigating suspicious activities.

• Experience with Splunk is preferred.

• Hands-on incident response experience covering investigation, containment, remediation, and root cause analysis.

• Experience collaborating with an external SOC/MSSP.

• Knowledge of network and host hardening techniques, common attack methods, and strategies for reducing attack surfaces.

• Familiarity with ISO 27001 and SOC 2, along with experience in operating or evidencing security controls.

• Experience in vulnerability management and remediation processes.

• Availability to provide security operations coverage during US business hours.

• Proficiency in scripting/automation using Python, Bash, or PowerShell is a strong advantage, or a demonstrated eagerness to learn quickly.

• Experience in conducting security awareness and phishing-simulation programs is a plus.

• Relevant certifications such as Security+, GIAC/GCIH/GCIA, CISSP, or specific EDR/SIEM/IAM certifications are advantageous.

• Exposure to cloud and SaaS security postures, including AWS, Google Workspace, and M365, is a plus.

• A collaborative working style suited for a distributed team environment.

• Strong written communication skills and the ability to ensure reliable handoffs across time zones.

• Must be located in the United States.


🏝️ Benefits

• Opportunities for professional development and training.

• Participation in conferences and working groups.

• Company outings, happy hours, hackathons, and tech talks.

• Competitive salary package accompanied by a robust benefits plan.

• Collaborate with passionate, talented, and engaging colleagues.

• Be part of innovative, cutting-edge open-source initiatives.

• Experience a high-energy environment that values openness, collaboration, risk-taking, and continuous growth.

People also viewed

EXL1 day ago

AVP, Cyber Application Security Architect

US flagNew Jersey OnlyFull-timeCybersecurity / Security Engineer$160k – $195.1k/year
ApplyView job
Reli Group2 days ago

Senior Cybersecurity Disaster Recovery, Contingency Planning SME

US flagMaryland OnlyFull-timeCybersecurity / Security Engineer$140k – $150k/year
ApplyView job
Second Nature2 days ago

Cloud Specialist – Security SSR

AR flagArgentina OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
ASRC Federal2 days ago

Information Security Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Kyndryl2 days ago

Lead, Application Consulting – Workday Security

US flagIllinois, +1 more stateFull-timeCybersecurity / Security Engineer$92k – $174.8k/year
ApplyView job
HomeServe USA2 days ago

Senior Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$114.5k – $167.9k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers