Lead and scale compliance architecture by owning the ISMS, managing multi-framework audits (PCI, SOX, SOC, ISO), automating controls, and bridging regulators with internal teams. Requires 6-8+ years GRC experience, deep framework expertise, cloud security knowledge, and relevant certifications.
131k – 291k/yr
On-site7+ YOESecurity Engineering
About the role
What You'll Do
Compliance Program Leadership (Primary Focus)
Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)
Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes
Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments
Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives
Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows
Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations
Control Framework & Testing
Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirements
Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies
Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies
Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability
Governance, Policy & Documentation
Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practices
Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementation
Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking
Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees
Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders
Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutions
Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organization
What We’re Looking For
Experience & Background
6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program management
Demonstrated experience working directly with Big Four or external auditors through full audit cycles
Control automation experience: Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automation
ISMS management: Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent)
Framework & Regulatory Knowledge
Deep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls)
Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties)
Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworks
Hands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit requirements
Working knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBIT
Technical & Cloud Security
Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus)
Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident response
Ability to review and assess security architectures, data flows, and system designs from a compliance perspective
Tools & Technology
Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar)
Experience implementing automated evidence collection using APIs, scripts, or integration platforms
Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutions
Education & Certifications
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field
Certifications (one or more): CISA, CISM, CISSP, ISO 27001 Lead Auditor or Lead Implementer, CCSP or CCSK, PCI ISA or QSA
Specialized Experience
Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processes
Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworks
Demonstrated success building and maintaining unified or common control frameworks that map requirements across multiple standards
Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practices
Lead the design, integration, and sustainment of secure Cross Domain Solutions enabling data sharing across Top Secret and classified networks. Requires 7+ years experience, deep knowledge of networking, hypervisors, security engineering, and active Top Secret/SCI clearance.
130k – 200k/yrOn-site7+ YOESecurity Engineering
Staff Security Engineer
OktaSan Francisco, CA
Staff Security Engineer embedded in TDI to build centralized security posture analytics, automate issue tracking and remediation, and drive AI-powered risk management across AWS, SaaS apps, and enterprise systems.
134k – 185k/yrOn-site10+ YOESecurity Engineering
Staff Security Operations Engineer
CriblUnited States
Lead security operations and threat detection engineering for a remote-first telemetry platform company. Design detection logic, manage incidents, and optimize SIEM/EDR tooling.
128k – 200k/yrRemote7+ YOESecurity Engineering
Staff Security Architect
KrakenUnited States
Design and review security architectures for Kraken's crypto products, conduct assessments, and provide hands-on security consulting across blockchain, infrastructure, and AI projects.
127k – 254k/yrRemoteSecurity Engineering
Security Software Engineer, Infrastructure Security (Staff or Senior)
MongoDBAustin, TX +2
Designs and builds scalable security controls and services for MongoDB Atlas multi-cloud infrastructure using Linux mechanisms, Kubernetes, and eBPF. Requires 5+ years experience in software/SRE with security focus, proficiency in systems programming, and cloud platforms.