USA remote
Senior Corporate Security Engineer
About this role
About the Role Mirantis is seeking a Corporate Security Engineer to join our security team, based remotely in the United States. We're adding this role to extend our security operations coverage beyond EU hours and to bring additional hands-on capacity to the team — improving how quickly we detect, triage, and respond to issues across the working day. This is a broad, hands-on engineering role covering the core of corporate security: endpoint protection (EDR) and device management (MDM), identity and access (IAM/SSO, MFA), and the detection-and-response stack (SIEM, alerting, and coordination with our existing external SOC).
You will be part of the team that responds when something happens, and you'll help harden the environment so that fewer things do. Alongside this, you'll support our compliance program — ISO 27001, SOC 2, and related efforts — by operating and evidencing the controls these systems enforce. In this role, you will operate and improve the tooling that protects our workforce and corporate environment, take part in incident response, and partner closely with IT, Product Security, and Compliance.
You'll join a distributed team, bring US-hours ownership to work that currently leans on EU coverage, and have real latitude to raise the bar on how corporate security runs day to day. Key Responsibilities Endpoint Security & Device Management: Define and own the security policies, hardening baselines, and compliance posture for our EDR and MDM stack across the fleet, and drive threat response on endpoints. Partner with IT, who handle day-to-day enrollment and administration, so that devices are consistently enrolled, compliant, and protected across operating systems.
Identity & Access Management: Administer and strengthen identity and access — IAM/SSO, MFA, provisioning/deprovisioning, and least-privilege access reviews. Partner with IT to keep the identity layer both secure and workable for employees. Detection, Monitoring & Incident Response : Operate the SIEM and detection tooling — tuning rules, triaging alerts, and investigating suspicious activity — and coordinate with our existing external SOC on monitoring and escalations.
Take an active part in incident response end to end: investigation, containment, remediation, and root cause analysis. Contribute to post-incident reviews and runbooks, and bring US-hours ownership to work that currently leans on EU coverage. Security Tooling & Hardening : Operate, integrate, and improve the broader corporate security toolset. Proactively harden the environment — configuration baselines, access controls, and reducing attack surface — so that fewer incidents occur in the first place.