Compliance Engineer
Build and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.
About the job
Responsibilities
- Build and maintain technical controls for SOC 2, ISO 27001, HIPAA, and other enterprise security and compliance requirements.
- Automate compliance workflows, evidence collection, access reviews, security checks, and other repetitive processes.
- Partner with Engineering and Security to implement and monitor controls for access management, infrastructure, data protection, logging, and vulnerability management.
- Own technical evidence collection and support audits, including addressing auditor requirements.
- Respond to customer security questionnaires, compliance requirements, and technical due diligence.
- Identify gaps in compliance and security programs and build scalable systems to address them.
- Collaborate across Engineering, Security, Legal, and customer-facing teams.
Requirements
- Technical background in software engineering, security, infrastructure, IT, or a related field.
- Strong scripting or programming skills in Python, JavaScript/TypeScript, Bash, or a similar language.
- Understanding of IAM, encryption, networking, logging, vulnerability management, and cloud security.
- Ability to learn security and compliance frameworks and translate requirements into practical technical solutions.
- Strong analytical, problem-solving, and communication skills.
- Ability to explain technical and compliance concepts to technical and non-technical audiences.
- Comfort working across technical, legal, security, and customer-facing teams.
Nice to Have
- Experience with SOC 2, ISO 27001, HIPAA, or other compliance frameworks.
- Experience with AWS, Google Cloud, Vanta, Drata, Wiz, Okta, or similar tools.
Compensation and Benefits
- Compensation of $6,000–$7,500 USD per month, based on experience.
- Full-time or part-time 1099 contractor engagement.
- Must be available for some overlapping hours with Pacific Time teams and customers.
Skills
Python, JavaScript, TypeScript, Bash, IAM, Encryption, Networking, Logging, Vulnerability Management, Cloud Security, SOC 2, ISO 27001, HIPAA, AWS, GCP
Similar jobs
Security Engineering jobsDevelop and operate global physical security systems, controls, and compliance processes across data centers and other facilities. The role manages investigations, risk mitigation, audits, vendor deployments, and cross-functional security initiatives, with approximately 35% travel required.
Security Engineer responsible for building detection and prevention controls, automating security operations, conducting threat hunts, and supporting incident response across a remote-first organization. Requires 3+ years of security or software development experience, cloud-native security expertise, and automation skills.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.