Compliance Engineering Lead
Own Socket’s compliance program as an engineered system, leading SOC 2 Type II, ISO 27001, risk and vendor programs, automated evidence pipelines, and customer assurance. The role requires deep audit ownership, ISO 27001 experience, automation skills, and the ability to build and lead a compliance function.
About the job
Responsibilities
- Own SOC 2 Type II end to end, including the observation window, auditor relationship, audit scoping, controls, findings, and evidence pipeline.
- Lead Socket through ISO 27001 certification by defining the scope and ISMS, conducting gap assessments and internal audits, preparing the organization, and maintaining the ISMS through surveillance audits.
- Build and maintain automated evidence collection from systems of record, including GCP, GitHub, identity providers, MDM, and ticketing systems.
- Create scheduled control monitoring that detects drift and alerts promptly.
- Own compliance platform strategy and evaluate whether to buy, build, or expand existing tooling.
- Run risk management and vendor-risk programs, including the risk register, vendor tiering, reviews, and renewal cadence.
- Own customer-facing assurance materials, including the trust portal and enterprise security artifact library.
- Evaluate AI assurance frameworks and regulations, including ISO/IEC 42001, AIUC-1, the EU AI Act, and the NIST AI Risk Management Framework.
- Report to the CISO and hire and lead the first customer trust teammate focused on security questionnaires, RFPs, and contract security reviews with Legal.
Requirements
- Personally owned at least two complete SOC 2 Type II cycles as the accountable owner, including auditor management, scoping, evidence, and findings.
- Experience taking an organization through ISO 27001 certification or managing an ISMS through surveillance audits.
- Ability to build and maintain automation against services and APIs; experience with GCP, GitHub, identity providers, MDM, and ticketing systems.
- Hands-on experience with Drata, Vanta, or a similar compliance platform, with clear opinions on their strengths and limitations.
- Strong judgment in prioritizing real control and risk gaps versus administrative or formatting issues.
- Excellent written communication for auditors, enterprise security reviewers, engineers, and executives.
- Experience working in a remote, fast-moving environment with shifting priorities and limited predefined structure.
Nice to Have
- Exposure to AI governance frameworks, including ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act.
- Experience at a security vendor or another company subject to rigorous customer security scrutiny.
- Experience with contract security review alongside Legal.
- Experience building compliance automation in-house.
Benefits
- Market-competitive salary bands.
- Meaningful equity program.
- Comprehensive health benefits with 99% coverage for employees and families.
- Flexible time off, holidays, and winter shutdown.
- Paid parental leave.
- Remote-first work with quarterly team off-sites.
Skills
Soc 2 Type Ii, ISO 27001, Isms, GCP, GitHub, Compliance Automation, Risk Management, Vendor Risk Management, Drata, Vanta, Iso/Iec 42001, Eu Ai Act, Nist Ai Rmf, Trust Portals
Similar jobs
Security Engineering jobsLeads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.