Compliance Engineer - US
Maintains US government compliance certifications like GovRAMP and FedRAMP, conducts risk assessments using NIST/CIS, builds documentation, and automates compliance tooling for cloud environments and CI/CD pipelines. Requires experience in regulated industries and compliance tools like Vanta.
About the job
Responsibilities
- Collaborate across teams to maintain US Government compliance certifications and frameworks such as GovRAMP, FedRAMP, CJIS, and CMMC.
- Shape ElevenLabs’ Enterprise offering towards regulated industries such as Local and State Government, Defense, and Finance.
- Build technical documentation to demonstrate compliance to customers throughout the stack.
- Assist the sales team by responding to client security requests and managing compliance-related queries.
- Conduct risk assessments based on CIS or NIST frameworks, document findings, and help teams achieve compliance efficiently.
- Enhance compliance as code tooling to automate monitoring, reporting, and reduce friction for other teams to remain compliant.
Requirements
- Experience in completing vendor security assessments and client security questionnaires in highly regulated industries, such as Government and Defense in the US.
- Strong technical expertise in managing and executing compliance, with hands-on experience using compliance management tools (e.g. Vanta).
- Proven ability to maintain and acquire certifications while managing audit readiness and documentation.
- Experience collaborating with cross-functional teams (sales, engineering, legal) to effectively communicate compliance requirements and ensure smooth operations.
- Experience with public cloud compliance (AWS, GCP, Azure) and automating compliance in cloud environments.
- Familiarity with integrating compliance tools into CI/CD pipelines to automate monitoring and reporting.
Skills
Vanta, Govramp, FedRAMP, Cjis, Cmmc, Nist, Cis, AWS, GCP, Azure, CI/CD
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.