SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Mirantis is seeking a Senior Corporate Security Engineer to join its security team on a fully remote basis in the United States. This is a hands-on engineering role focused on extending security operations coverage into US business hours and bringing additional capacity to the team for faster detection, triage, and response to security issues.
The role covers core corporate security functions: endpoint protection (EDR) and device management (MDM), identity and access management (IAM/SSO/MFA), and the detection-and-response stack (SIEM, alerting, and coordination with an external SOC). You will operate and improve the tooling that protects the workforce and corporate environment, participate in incident response, and partner closely with IT, Product Security, and Compliance teams.
Key responsibilities include:
- Define and own security policies, hardening baselines, and compliance posture for EDR and MDM stacks across the fleet; drive threat response on endpoints across macOS, Windows, and Linux.
- Administer and strengthen identity and access controls—IAM/SSO, MFA, provisioning/deprovisioning, and least-privilege access reviews.
- Operate SIEM and detection tooling: tune rules, triage alerts, investigate suspicious activity, and coordinate with the external SOC. Take an active part in incident response end-to-end: investigation, containment, remediation, and root cause analysis.
- Operate, integrate, and improve the corporate security toolset. Proactively harden the environment through configuration baselines, access controls, and attack surface reduction.
- Support the compliance program (ISO 27001, SOC 2) by operating and evidencing security controls required by these frameworks.
- Track and help remediate vulnerabilities across endpoints and corporate systems; stay current on relevant threats.
- Run and improve the security awareness program—training, phishing simulations, and employee-facing guidance.
- Work closely with IT, Product Security, and Compliance as part of a distributed team, extending security operations coverage into US time zones.
Mirantis is a Kubernetes-native AI infrastructure company enabling organizations to build and operate scalable, secure infrastructure for modern AI and machine learning applications. The company is recognized as a leader in container management and combines open-source innovation with deep Kubernetes expertise.
QUALIFICATIONS:
- 4+ years of experience in corporate/enterprise security, security operations, or IT security engineering.
- Hands-on experience with endpoint security (EDR) across macOS and Windows; MDM and Linux endpoint management experience is a plus.
- Strong working knowledge of identity and access management—SSO, MFA, and modern IAM platforms (Okta, Entra ID/Azure AD, Google Workspace)—and least-privilege access practices.
- Experience operating a SIEM and detection tooling: writing and tuning rules, triaging alerts, investigating suspicious activity. Splunk experience preferred.
- Practical incident response experience: investigation, containment, remediation, root cause analysis; comfort coordinating with external SOC/MSSP.
- Solid grasp of security fundamentals: network and host hardening, common attack techniques, attack surface reduction.
- Familiarity with compliance frameworks (ISO 27001, SOC 2) and experience operating or evidencing security controls.
- Experience with vulnerability management and translating findings into concrete remediation.
- Collaborative working style suited to distributed teams, with clear written communication and reliable cross-timezone handoffs.
- Based in the United States with ability to provide security operations coverage during US business hours.
- Scripting/automation ability (Python, Bash, PowerShell) to streamline security operations is a strong plus; alternatively, demonstrated ability and strong desire to learn quickly.
- Experience running security awareness and phishing-simulation programs is a plus.
- Relevant certifications (Security+, GIAC/GCIH/GCIA, CISSP, or vendor-specific EDR/SIEM/IAM certs) are a plus.
- Exposure to cloud and SaaS security posture (AWS, Google Workspace, M365) is a plus.