Leads Fingerprint’s security, IT operations, and compliance function, managing a team and owning application security, SOC 2, identity governance, and enterprise security communications. Requires 7+ years across security, IT, or GRC, team management experience, and demonstrated SOC 2 and application security ownership.
Salary not listed
Remote7+ YOESecurity Engineering
About the role
Mission
Unify security, IT operations, and compliance under a coherent strategy with shared standards, risk language, and a scalable roadmap.
Own Fingerprint's security posture, including application security, zero-trust principles, vulnerability management, and security-by-default practices.
Scale the compliance program, mature evidence collection, and prepare for expanding enterprise requirements.
Run reliable IT operations for a globally distributed, fully remote organization.
Represent security and compliance posture to enterprise customers, prospects, partners, auditors, and leadership.
Responsibilities
Security Strategy & Application Security
Define and own the application security roadmap, including vulnerability management, penetration testing, and security reviews for new features and architectural changes.
Build security-by-default practices into engineering workflows.
Own vendor security assessments and ensure third parties meet security standards.
Define zero-trust security principles and embed them across the Cloud Platform and engineering organization.
Compliance & GRC
Own the SOC 2 Type 2 annual audit cycle, including evidence collection, auditor management, and control maturation.
Drive compliance expansion, evaluating frameworks such as ISO 27001, GDPR, and customer-specific enterprise requirements.
Manage and develop the Compliance Lead.
Support enterprise sales cycles through security questionnaires, customer due diligence calls, and contractual security requirements.
Maintain and embed the company's policy framework.
IT Operations
Manage the Lead IT Engineer and provide strategic direction for day-to-day IT operations.
Own IT strategy, including tooling, access management, Okta, SCIM/SAML provisioning, endpoint management, and identity governance.
Scale IT operations with engineering headcount growth through proactive capacity planning.
Define and enforce IT security policies covering device management, access reviews, and offboarding.
Cross-functional Leadership & Communication
Communicate security posture, compliance status, and IT health to the VP of Engineering with actionable recommendations.
Partner with Cloud Platform leadership on infrastructure security, network security, IAM standards, security logging, and alerting.
Embed security practices across product engineering teams.
Represent security and compliance posture to customers, prospects, and auditors.
Requirements
7+ years of experience in security, IT, or GRC, including at least 3 years managing a team.
Broad fluency across application security, IT operations, and compliance/GRC.
Experience owning a SOC 2 audit cycle, including evidence collection, auditor relationships, and sustainable control operations.
Application security expertise, including OWASP, vulnerability management programs such as Snyk, and engineering security reviews.
IT operations leadership experience, including identity and access management, Okta or equivalent, endpoint management, and remote workforce IT at scale.
Strong strategic communication skills, translating security and compliance topics into business language for leadership and customers.
Nice-to-haves
Experience with ISO 27001, GDPR, or HIPAA.
Familiarity with Snyk, Wiz, Cloudflare, and Okta.
Experience answering enterprise security questionnaires for financial institutions or other demanding enterprise customers.
Experience in a high-growth SaaS company where security scaled with rapid product and customer growth.
Benefits & Compensation
The company operates as a globally distributed, 100% remote organization.
Fingerprint has achieved SOC 2 Type 2 and HIPAA compliance.
Skills
Application SecurityowaspVulnerability ManagementsnykSOC 2GRCISO 27001GDPRHIPAAOktaSCIMSAMLendpoint managementidentity and access managementCloudflare
Conduct quantitative risk assessments, threat modeling, and cybersecurity standards analysis across autonomous vehicles and cloud services. The role requires a master’s degree, 7+ years of experience, strong systems and embedded-security expertise, and the ability to produce high-quality technical and regulatory deliverables.
217k – 307k/yrHybrid7+ YOESecurity Engineering
Security Engineer - Threat Detection
SnowflakeUnited States
Builds and evolves AI-assisted threat detection, automation, and analytics at cloud scale. Requires 8+ years of security engineering experience, strong Python or Go skills, production software practices, cloud security expertise, and experience with large-scale telemetry and agentic workflows.
211k – 304k/yrRemote8+ YOESecurity Engineering
Senior Information Security Engineer
ZooxFoster City, CA
Senior Information Security Engineer who builds SIEM detections, SOAR automation, and LLM-powered alert-triage workflows. The role requires 8+ years in information security or DevSecOps, strong Python and AWS expertise, and hands-on incident response experience.
190k – 228k/yrHybrid8+ YOESecurity Engineering
Safety Operations Lead
Thinking Machines LabSan Francisco, CA
Leads operational trust and safety for human-AI collaboration products by reviewing abuse cases, enforcing policy, and building automation and detection systems. Requires 7+ years of recurring case-queue experience plus expertise in AI abuse risks, policy operations, and production safety incidents.
190k – 300k/yrHybrid7+ YOESecurity Engineering
Product Security Lead
ForterraClarksburg, MD
Leads Forterra’s end-to-end product security program for autonomous vehicle platforms, including DoD authorization, compliance, threat modeling, vulnerability management, and incident response. Requires 7+ years of cybersecurity experience, ATO ownership, embedded or autonomous systems expertise, and strong technical and executive leadership.