SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 180,240 - 216,120 / annual
MISUMI Americas, a division of MISUMI Group, is a leading provider of standard, configurable, and custom manufacturing solutions. They operate in the San Francisco Bay Area and Chicago, serving innovative companies across the Americas.
This is a hands-on senior security engineering role covering the full scope of security across MISUMI Americas. You will be the primary executor of security work day-to-day: securing infrastructure, running access audits, setting up controls, reviewing systems and code, investigating incidents, and shaping security policies and priorities company-wide.
Key responsibilities include:
**Security Decisions & Prioritization**: Act as the hands-on security lead across IT and engineering, making everyday security decisions and serving as the main point of execution. Assess security risk across the environment and help prioritize which security projects and initiatives to tackle first across global operations. Help write, shape, and enforce security policies, standards, and governance alongside security leadership.
**Incident Response & Escalation**: Serve as part of the threat detection and incident response group (cross-departmental), investigating incidents both hands-on and by coordinating responses. Act as the escalation point for the IT team when issues exceed routine security tasks. Dig into root cause on complex problems and implement fixes.
**Infrastructure Security**: Keep infrastructure secure across physical networking and cloud environments, including firewalls, segmentation, and wireless. Design and manage IAM at the infrastructure level with roles, security groups, and permission policies scoped to least privilege. Review and tighten application permissions and access policies as the environment grows.
**Identity, Access & User Audits**: Run user access audits and regular access reviews across identity and application layers. Determine what user groups and roles are needed. Handle access provisioning and deprovisioning as people join, move, and leave.
**AI Security**: Manage enterprise AI tools such as Claude, keeping configurations, roles, and access current. Evaluate new AI capabilities individually and decide whether to enable them and what guardrails are needed. Vet new AI integrations before deployment, including automated scans and manual review. Turn AI security decisions into reusable policies and practices.
**Application & Engineering Security**: Review systems for security problems, including running automated scans. Vet third-party and open-source components before adoption. Work with engineering to keep security built into software and infrastructure shipping practices.
**Compliance & Audit Support**: Gather and maintain evidence for J-SOX, NIST 800-171, CMMC 2.0, and SOC 2 audits. Run recurring compliance checks and validate controls across global operations. Match controls and evidence to audit requirements and support audits from start to finish, focusing on evidence and remediation.
**Policy, Process & Automation**: Convert manual security work into documented practices, runbooks, and repeatable processes. Automate access reviews, monitoring, alerting, and reporting. Keep security documentation and internal knowledge base current.
Travel expectations: 0-10%. Physical demands include sitting for extended periods working with computers.
**Requirements**:
- Senior-level proven expertise across security domains: identity and access management, infrastructure and cloud security, governance and compliance, incident response and investigation, application and integration security, and AI/LLM security
- Hands-on incident investigation experience and judgment to act as escalation point on user-facing threats like phishing and spam
- Strong hands-on experience securing infrastructure across networking and cloud, including firewalls, segmentation, IAM, security groups, permission policies, and application permissions
- Cloud security experience (AWS, Azure, or similar) and comfort designing roles and RBAC in platforms like Microsoft Entra ID, Okta, or AWS IAM
- Familiarity with security monitoring and detection tools to support investigations effectively
- Real experience running user access audits, access reviews, and compliance checks
- Experience supporting audit and compliance programs like SOC 2, NIST 800-53/800-171, CMMC 2.0, and J-SOX, including gathering evidence and validating controls
- Solid application security skills: automation tooling, reading code for security issues, and secure integration practices
- Confidence to make security decisions independently and help sort out competing priorities
- Working understanding of AI and LLM security, including administering AI tools, weighing new capabilities for risk, and understanding integrations like MCP servers
- Habit of turning manual security work into repeatable processes and automation
- Clear communication and ability to work across a spread-out, multi-site, global organization
- Must be a U.S. Citizen or Green Card holder
**Bonus qualifications**:
- Certifications like CISSP, CISM, Security+, or GIAC (GSEC, GCIH, etc.)
- Firsthand experience preparing for and going through a CMMC 2.0 assessment
- Experience with audit and controls at a global, Japanese-owned company (J-SOX exposure)
- Scripting and automation skills (Bash, Python, PowerShell)