IT Security Engineer
Role details
Job location
Tech stack
Job description
You'll own corporate security: the devices, identities, and SaaS the company runs on. Sister role to theInfrastructure Security Engineer - they secure the cloud and ML platform; this role secures the people side., We are looking for someone with experience in scaling high-growth startups who can make an immediate impact in the following areas:
Endpoints:
- Own MDM across the fleet: enrollment, policy enforcement, compliance, device lifecycle.
- Run EDR/XDR: detection, triage, and response on employee devices.
- Set and maintain endpoint hardening standards with IT and Engineering.
Corporate identity & access
- Own corporate identity: Entra SSO, MFA, conditional access.
- Run joiner-mover-leaver: provisioning and same-day offboarding across all SaaS.
- Administer a Password Management solution and drive credential hygiene.
Awareness & response
-
Security-review new SaaS before adoption; own the approved-app list; hunt shadow IT.
-
Secure the collaboration stack: email, Slack, file sharing. AWARENESS & RESPONSE
-
Run phishing simulations and onboarding security training.
-
Partner with infrastructure security on centralized security monitoring: feed endpoint and identity signals into shared detection and response.
Requirements
- Hands-on experience running MDM and EDR at fleet scale.
- Production experience running an IdP: SSO/SAML/SCIM, MFA, and conditional access.
- Enough scripting to automate the repetitive parts (Python, PowerShell, or Bash).
- High agency.
- Working English.
Nice to have:
- Familiarity with SOC 2.
- High-growth startup experience.
Benefits & conditions
- Competitive base salary in USD
- Equity: participation in the company's stock option program, giving you the opportunity to share in the company's long-term growth.
- On-site role in our Almaty office (we will relocate you from anywhere).