Skip to content

Cybersecurity Analyst - Commercial Compliance

Supports commercial compliance through audit assistance, evidence management with AI automation, policy updates, vendor risk tracking, and RFP security questionnaires. Requires 5+ years in security/GRC, bachelor's degree, and compliance framework knowledge.

140k – 160kCaliforniaSecurity EngineeringRemote5+ YOE

About the role

Responsibilities

  • Provide direct support for external and internal audit efforts, focusing on frameworks such as SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, and ISO 42001.
  • Execute and document procedures for continuous monitoring and evidence gathering; implement automated solutions, including AI, to reduce manual efforts.
  • Review, edit, and update internal security policies, standards, and procedures to reflect current controls and compliance requirements.
  • Assist in supply chain risk management by tracking vendor compliance, reviewing vendor security posture, and maintaining the vendor risk register.
  • Participate in internal security audits and support business development with security questionnaires for RFPs.

Requirements

  • 5+ years of experience in security, IT audit, GRC, or related technical field.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
  • Industry certifications such as CompTIA Security+; pursuing advanced like (ISC)² CISSP.
  • Foundational understanding of regulatory environments and frameworks (ISO, SOC, HIPAA, SOX, NIST, FedRAMP, GovRAMP, DoD IL 5/6, PCI DSS).
  • Foundational understanding of enterprise IT/OT/ICS environments, network protocols, OS, cloud platforms, and security technologies.
  • Foundational understanding of AWS and GCP security concepts and services.
  • Strong organizational skills, attention to detail, and documentation management.
  • Excellent written communication for technical documents and policies.

Preferred Skills

  • Experience supporting audits for listed frameworks.
  • Familiarity with FedRAMP.
  • Understanding of data encryption, logical access controls, boundary security.
  • Linux experience.
  • AWS/GCP compliance support.
  • Global remote team experience.
  • JIRA, Asana.
  • Microsoft Office 365, Google Workspace.
  • GRC platforms like Anecdotes, Drata.

Compensation

Pay range: $140,000 - $160,000 (excludes bonuses, stocks, benefits).

Skills

SOC 2ISO 27001NistFedRAMPAWSGCPGrc PlatformsDrataJiraLinuxComptia Security+CisspAI Automation

Security Engineer 2 - Cyber Threat Intelligence

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

140k – 195kNew York, NYSecurity EngineeringHybridScriptingTtp Analysis

Corporate Security Engineer, IAC & Automation

As a Corporate Security Engineer, you will lead the design, implementation, and optimization of corporate security infrastructure, enhancing controls and driving automation. You will work with IaC tools, deploy endpoint security, and manage data protection.

140k – 165kUnited StatesSecurity EngineeringRemote3+ YOEGoDlp

Security Engineer

Security Engineer building detections, security automation, and infrastructure security on AWS while managing SOC 2 and ISO 27001 compliance. Requires 4-7 years experience with strong AWS and IaC skills.

140k – 160kUnited StatesSecurity EngineeringRemote4+ YOEGoAWS

Security Program Manager

Own and mature GRC and security compliance programs (SOC 2, ISO 27001) as the CSO's operational lead, driving audits, risk management, vendor assessments, and cross-functional initiatives. Requires 5+ years in security program management or GRC with strong project management and AI fluency.

140k – 155kNew York, NYSecurity EngineeringRemote5+ YOEGRCAWS

Cyber Security Engineer

Build and maintain self-healing security infrastructure across AWS and Kubernetes, including cryptographic material lifecycle, telemetry pipelines, and AI-assisted automation workflows. Requires 5+ years of security engineering experience and fluency with agentic AI coding tools.

140k – 160kUnited StatesSecurity EngineeringRemote5+ YOEAWSPki