SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 150,200 - 180,100 / annual
MISUMI Americas, a division of MISUMI Group, combines Fictiv's digital manufacturing platform with MISUMI's 60+ year legacy of industrial precision. The company serves engineers and manufacturers across the Americas with standard, configurable, and custom fabricated parts.
You will own the full range of security engineering work across MISUMI Americas as a hands-on Lead Security Engineer. This is a senior individual contributor role with significant influence over security strategy and policy, though you will not manage a team. You'll secure infrastructure, run access audits, build and enforce controls, review systems and code, investigate incidents, and have a real voice in company-wide security priorities.
Key responsibilities include:
**Security Decisions & Prioritization**: Act as the hands-on security lead across IT and engineering, serving as the main point of execution for security work. Help decide which security projects and initiatives to tackle first across global operations. Help write, shape, and enforce security policies, standards, and governance alongside security leadership.
**Incident Response & Escalation**: Serve on the cross-departmental threat detection and incident response team, investigating incidents hands-on and coordinating responses. Act as the escalation point for IT when issues exceed routine scope. Dig into root cause on complex problems and implement fixes to prevent recurrence.
**Infrastructure Security**: Secure infrastructure across physical networking and cloud environments—firewalls, segmentation, wireless, and cloud account/workload configuration. Design and manage IAM at the infrastructure level: roles, security groups, and permission policies scoped to least privilege. Review and tighten application permissions and access policies; catch misconfigurations and permission drift early.
**Identity, Access & User Audits**: Run user access audits and regular access reviews across identity and application layers. Determine what user groups and roles are needed to manage system access. Handle access changes as people join, move, and leave, keeping permissions aligned with policy.
**AI Security**: Manage enterprise AI tools such as Claude, keeping configurations, roles, and access current. Evaluate new AI capabilities and decide whether to enable them and what guardrails they need. Vet new AI integrations before launch, including automated scans and manual review of new local MCP servers. Turn AI security decisions into reusable policies and practices.
**Application & Engineering Security**: Review systems for security issues, including running automated scans. Vet third-party and open-source components before adoption. Partner with engineering to build security into how the company ships software and infrastructure.
**Compliance & Audit Support**: Gather and maintain audit evidence for J-SOX, NIST 800-171, CMMC 2.0, and SOC 2. Run recurring compliance checks and validate controls across the global footprint. Map controls and evidence to audit requirements and support audits from start to finish, with a focus on evidence and remediation.
**Policy, Process & Automation**: Turn manual security work into documented practices, runbooks, and repeatable processes. Automate access reviews, monitoring, alerting, and reporting. Keep security documentation and the internal knowledge base current.
**Requirements**:
- Senior-level, hands-on expertise across identity and access management, infrastructure/cloud security, governance and compliance, incident response, application/integration security, and AI/LLM security
- Hands-on incident investigation experience and judgment to serve as an escalation point on user-facing threats like phishing and spam
- Strong experience securing infrastructure across networking and cloud—firewalls and segmentation on the network side; IAM, security groups, permission policies, and application permissions on the cloud side
- Cloud security experience (AWS, Azure, or similar) and comfort designing roles/RBAC in platforms like Microsoft Entra ID, Okta, or AWS IAM
- Familiarity with security monitoring and detection tools sufficient to support investigations
- Real experience running user access audits, access reviews, and compliance checks
- Experience supporting audit/compliance programs such as SOC 2, NIST 800-53/800-171, CMMC 2.0, and J-SOX, including evidence gathering and control validation
- Solid application security skills: automation tooling, secure code review, and secure integration practices
- Confidence to make independent security decisions and sort competing priorities
- Working understanding of AI/LLM security—administering AI tools, weighing new capabilities for risk, and evaluating integrations like MCP servers
- Habit of converting manual security work into repeatable process and automation
- Clear communication and ability to work across a distributed, multi-site, global organization
- Must be a US citizen or green card holder