# Security & Compliance Engineer

**Company:** [Aurelian](https://hotfix.jobs/companies/aurelian)
**Location:** Seattle, WA
**Role:** Security Engineering
**Salary:** $150k – $215k/yr
**Experience:** 5+ years
**Skills:** SOC 2, cjis, nist 800-53, nist 800-171, FedRAMP, Azure, IAM, GRC, compliance automation, Incident Response, Scripting
**Posted:** 2026-07-27

> Security & Compliance Engineer owning end-to-end security posture and compliance programs (SOC 2, CJIS) for public safety AI tools. Blend of hands-on cloud security engineering (Azure, IAM, logging) and compliance ownership, including questionnaires, policies, and automation.

## Job Description

## Responsibilities
- Own our security posture end-to-end: Be the single source of truth for how Aurelian handles sensitive data. Keep our security claims accurate, consistent, and defensible across every document, questionnaire, and contract.
- Run the compliance program: Own SOC 2 and our alignment to the CJIS Security Policy (and FedRAMP/GovCloud as our gov pipeline grows). Own the artifacts that don't fully exist yet - subprocessor lists, data management and retention policies, incident response plans - and keep them current.
- Turn security reviews from a bottleneck into a process: Own the customer security-questionnaire pipeline so deals don't wait on engineering. Work directly with our implementation and sales teams to get agencies the answers they need, quickly and accurately.
- Do the engineering, not just the paperwork: Harden our cloud infrastructure (Azure), tighten IAM and tenant isolation, improve logging/audit and detection, and shore up our secure development practices.
- Automate the compliance grind: Wire up and operate compliance-automation tooling so evidence collection, continuous controls monitoring, and questionnaire responses run as close to hands-off as possible. Treat compliance as code.
- Operationalize personnel security: Run the processes CJIS requires across engineering - background checks / fingerprinting, security-awareness training, and access controls for anyone who touches criminal justice information.

## Requirements
- A builder who can also run the program: You have a real security-engineering foundation and you've owned a compliance program. You're not a spreadsheet-only GRC analyst, and you're not a strategy-only leader who won't get hands-on. ~5–8 years across security engineering and GRC is a good marker, but we care about the blend more than the number.
- Fluent in the frameworks that matter to us: Direct experience with SOC 2 and hands-on familiarity with the CJIS Security Policy, NIST 800-53/800-171, or FedRAMP. Public-sector, GovCloud, or regulated-SaaS experience is a strong plus.
- Comfortable in the cloud and in code: You can harden a cloud environment (Azure ideally), reason about IAM, encryption, network isolation, and logging, and automate controls and evidence with scripting and GRC tooling.
- Credible in the room: You can face an auditor, a state CJIS Systems Officer, or a county CISO team and answer hard questions clearly — and translate the same material for our sales and implementation teams and our engineers.
- High ownership, low ceremony: You see the gap, define the right thing to build, and drive it to done. You'd rather build a durable system than win an argument, and you're energized by being the person the whole company relies on for this.
- Eligible for CJIS clearance: Because of the data we handle, this role requires passing a state and national fingerprint-based background check.

## Nice-to-Haves
- Public-sector, GovCloud, or regulated-SaaS experience.
- Experience with FedRAMP.

## Compensation and Benefits
- For Full-Time roles, Aurelian offers a variety of benefits, including: Comprehensive Medical, Dental, Vision & Life insurance; 401(k); Unlimited PTO; Company-wide offsites; Equipment stipend; Relocation assistance; Daily delivered lunches (on us); Office in Seattle; Start-up Equity.

## Similar roles

- [GRC Manager](https://hotfix.jobs/jobs/68a03d3e-1579-49d0-ab74-5a8e2b7e975b) - Baseten - San Francisco, CA - $150k – $250k/yr
- [Software Engineer, Identity](https://hotfix.jobs/jobs/95795ec8-bfd1-44c8-a7a1-b16c9be3d31b) - Mercor - San Francisco, CA - $150k – $325k/yr
- [IT Security Operations Engineer](https://hotfix.jobs/jobs/ab8df8f3-05c1-4b41-a516-c95445575498) - AKASA - San Francisco, CA - $150k – $190k/yr
- [Security Engineer](https://hotfix.jobs/jobs/79d32979-efc0-42db-8089-267517d351aa) - Novig - New York, NY - $150k – $200k/yr
- [Security Engineer (Purple Team)](https://hotfix.jobs/jobs/a555c8c6-de26-4174-8934-a2a145176469) - Applied Intuition - Sunnyvale, CA - $150k – $220k/yr

**Apply:** https://hotfix.jobs/jobs/0fe396b6-3353-482d-9e15-168119079999
**Canonical:** https://hotfix.jobs/jobs/0fe396b6-3353-482d-9e15-168119079999