Framework Engineer
Develop and maintain compliance frameworks, control libraries, automations, and product improvements that help customers meet security requirements efficiently. The role requires hands-on security program experience, knowledge of major compliance standards, and strong technical fluency with JSON and scripting.
About the job
Responsibilities
- Research new compliance frameworks and break them into requirements that map to the existing control library.
- Evaluate the control library for inefficiencies or unnecessary requirements and keep it focused.
- Build customer automations and documentation to help meet compliance requirements efficiently.
- Improve the compliance product to make compliance easier for customers.
Requirements
- Experience building security programs from scratch to meet compliance requirements.
- Strong working knowledge of major compliance frameworks, including ISO 27001, SOC 2, GDPR, HIPAA, and PCI DSS.
- Comfort editing structured configuration files such as JSON.
- Ability to write basic scripts for rule updates and validation checks.
- Strong logical and technical fluency.
- Self-starter mindset, adaptability, initiative, and comfort working in ambiguity.
Nice-to-haves
- Engineering or coding experience.
- Experience scaling an early-stage startup from Seed through Series A or beyond.
Compensation & Benefits
- Base salary range: $100,000–$150,000 annually for the U.S. national baseline.
- Competitive compensation and equity.
- Comprehensive health and wellness benefits.
- 20 days of paid time off per year plus 8 floating holidays.
- Remote work culture.
- Team off-sites.
Skills
ISO 27001, SOC 2, GDPR, HIPAA, Pci Dss, JSON, Scripting, Security Programs, Control Libraries
Similar jobs
Security Engineering jobsDevelop and operate global physical security systems, controls, and compliance processes across data centers and other facilities. The role manages investigations, risk mitigation, audits, vendor deployments, and cross-functional security initiatives, with approximately 35% travel required.
Security Engineer responsible for building detection and prevention controls, automating security operations, conducting threat hunts, and supporting incident response across a remote-first organization. Requires 3+ years of security or software development experience, cloud-native security expertise, and automation skills.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.