Skip to content
AurelianAurelianSeattle, WA

Security & Compliance Engineer

Security & Compliance Engineer owning end-to-end security posture and compliance programs (SOC 2, CJIS) for public safety AI tools. Blend of hands-on cloud security engineering (Azure, IAM, logging) and compliance ownership, including questionnaires, policies, and automation.

150k – 215k/yr
On-site5+ YOESecurity Engineering

About the role

Responsibilities

  • Own our security posture end-to-end: Be the single source of truth for how Aurelian handles sensitive data. Keep our security claims accurate, consistent, and defensible across every document, questionnaire, and contract.
  • Run the compliance program: Own SOC 2 and our alignment to the CJIS Security Policy (and FedRAMP/GovCloud as our gov pipeline grows). Own the artifacts that don't fully exist yet - subprocessor lists, data management and retention policies, incident response plans - and keep them current.
  • Turn security reviews from a bottleneck into a process: Own the customer security-questionnaire pipeline so deals don't wait on engineering. Work directly with our implementation and sales teams to get agencies the answers they need, quickly and accurately.
  • Do the engineering, not just the paperwork: Harden our cloud infrastructure (Azure), tighten IAM and tenant isolation, improve logging/audit and detection, and shore up our secure development practices.
  • Automate the compliance grind: Wire up and operate compliance-automation tooling so evidence collection, continuous controls monitoring, and questionnaire responses run as close to hands-off as possible. Treat compliance as code.
  • Operationalize personnel security: Run the processes CJIS requires across engineering - background checks / fingerprinting, security-awareness training, and access controls for anyone who touches criminal justice information.

Requirements

  • A builder who can also run the program: You have a real security-engineering foundation and you've owned a compliance program. You're not a spreadsheet-only GRC analyst, and you're not a strategy-only leader who won't get hands-on. ~5–8 years across security engineering and GRC is a good marker, but we care about the blend more than the number.
  • Fluent in the frameworks that matter to us: Direct experience with SOC 2 and hands-on familiarity with the CJIS Security Policy, NIST 800-53/800-171, or FedRAMP. Public-sector, GovCloud, or regulated-SaaS experience is a strong plus.
  • Comfortable in the cloud and in code: You can harden a cloud environment (Azure ideally), reason about IAM, encryption, network isolation, and logging, and automate controls and evidence with scripting and GRC tooling.
  • Credible in the room: You can face an auditor, a state CJIS Systems Officer, or a county CISO team and answer hard questions clearly — and translate the same material for our sales and implementation teams and our engineers.
  • High ownership, low ceremony: You see the gap, define the right thing to build, and drive it to done. You'd rather build a durable system than win an argument, and you're energized by being the person the whole company relies on for this.
  • Eligible for CJIS clearance: Because of the data we handle, this role requires passing a state and national fingerprint-based background check.

Nice-to-Haves

  • Public-sector, GovCloud, or regulated-SaaS experience.
  • Experience with FedRAMP.

Compensation and Benefits

  • For Full-Time roles, Aurelian offers a variety of benefits, including: Comprehensive Medical, Dental, Vision & Life insurance; 401(k); Unlimited PTO; Company-wide offsites; Equipment stipend; Relocation assistance; Daily delivered lunches (on us); Office in Seattle; Start-up Equity.

Skills

SOC 2cjisnist 800-53nist 800-171FedRAMPAzureIAMGRCcompliance automationIncident ResponseScripting
Baseten

GRC Manager

BasetenSan Francisco, CA +1

GRC Manager responsible for building and managing Baseten's security governance, risk assessment, compliance programs (SOC 2, ISO 27001, FedRAMP, HIPAA), audits, vendor risk, and customer assurance in a fast-growing AI infrastructure startup. Requires 5+ years in GRC or security compliance, preferably in SaaS/cloud environments.

150k – 250k/yr
Hybrid5+ YOESecurity Engineering
Mercor

Software Engineer, Identity

MercorSan Francisco, CA

Build and scale Mercor's novel identity and access management infrastructure across thousands of Slack workspaces and HR systems for a 100k+ expert network. Requires strong product engineering, large-scale distributed systems experience, and security-minded design instincts.

150k – 325k/yr
On-site5+ YOESecurity Engineering
AKASA

IT Security Operations Engineer

AKASASan Francisco, CA

IT Security Operations Engineer responsible for implementing DLP, email security, endpoint protection, Okta/Google Workspace hardening, automation, compliance evidence collection, and incident response in a hybrid healthcare AI startup.

150k – 190k/yr
Hybrid4+ YOESecurity Engineering
Novig

Security Engineer

NovigNew York, NY

Build and maintain security automation pipelines, AI agents, SOAR/SIEM integrations, vulnerability management, and IAM systems for a sports prediction market platform.

150k – 200k/yr
On-site5+ YOESecurity Engineering
Applied Intuition

Security Engineer (Purple Team)

Applied IntuitionSunnyvale, CA

Performs offensive security testing, penetration assessments, and risk analysis on vehicle software platforms and embedded systems. Collaborates with engineering teams to design secure architectures and implement mitigations for automotive products.

150k – 220k/yr
On-siteSecurity Engineering