
Senior Corporate Security Engineer
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Kazakhstan.
• Establish and take responsibility for security policies, hardening standards, and compliance framework for EDR and MDM throughout the organization.
• Lead endpoint threat response initiatives and collaborate with IT on device enrollment, compliance, and protection measures.
• Manage and enhance IAM/SSO, MFA, provisioning and deprovisioning processes, along with conducting least-privilege access reviews.
• Operate SIEM and detection tools by fine-tuning rules, triaging alerts, and investigating any suspicious activities.
• Coordinate monitoring and escalation processes with the external Security Operations Center (SOC).
• Engage in incident response activities from investigation through containment, remediation, and root cause analysis.
• Contribute to post-incident evaluations and the development of runbooks.
• Operate, integrate, and enhance the corporate security toolkit.
• Proactively strengthen the environment through configuration baselines, access controls, and reduction of attack surfaces.
• Assist with ISO 27001, SOC 2, and related compliance initiatives by managing controls and collecting evidence.
• Collaborate with Compliance on audits and control mapping efforts.
• Track and assist in the remediation of vulnerabilities across endpoints and corporate systems.
• Monitor emerging threats and translate them into actionable security improvements.
• Implement and enhance security awareness training, phishing simulations, and guidance for employees.
• Work in partnership with IT, Product Security, and Compliance within a distributed team structure.
• Extend security operations coverage to US time zones and ensure seamless handoffs with EU counterparts.
• A minimum of 4 years of experience in corporate/enterprise security, security operations, or IT security engineering roles.
• Practical experience with endpoint security (EDR) on both macOS and Windows platforms.
• Familiarity with device management (MDM); experience managing Linux endpoints is advantageous.
• Solid understanding of IAM/SSO, MFA, modern IAM solutions, and least-privilege access methodologies.
• Proven experience operating SIEM and detection tools, including rule writing, tuning, alert triaging, and investigating suspicious activities.
• Experience with Splunk is preferred.
• Hands-on incident response experience covering investigation, containment, remediation, and root cause analysis.
• Experience collaborating with an external SOC/MSSP.
• Knowledge of network and host hardening techniques, common attack methods, and strategies for reducing attack surfaces.
• Familiarity with ISO 27001 and SOC 2, along with experience in operating or evidencing security controls.
• Experience in vulnerability management and remediation processes.
• Availability to provide security operations coverage during US business hours.
• Proficiency in scripting/automation using Python, Bash, or PowerShell is a strong advantage, or a demonstrated eagerness to learn quickly.
• Experience in conducting security awareness and phishing-simulation programs is a plus.
• Relevant certifications such as Security+, GIAC/GCIH/GCIA, CISSP, or specific EDR/SIEM/IAM certifications are advantageous.
• Exposure to cloud and SaaS security postures, including AWS, Google Workspace, and M365, is a plus.
• A collaborative working style suited for a distributed team environment.
• Strong written communication skills and the ability to ensure reliable handoffs across time zones.
• Must be located in the United States.
• Opportunities for professional development and training.
• Participation in conferences and working groups.
• Company outings, happy hours, hackathons, and tech talks.
• Competitive salary package accompanied by a robust benefits plan.
• Collaborate with passionate, talented, and engaging colleagues.
• Be part of innovative, cutting-edge open-source initiatives.
• Experience a high-energy environment that values openness, collaboration, risk-taking, and continuous growth.
EXL
Reli Group
Second Nature
ASRC Federal
Get handpicked remote jobs straight to your inbox weekly.