Skip to content

Security & Compliance Lead

150k – 225kNew York, NYOnsite5+ YOE
Summary

First Security & Compliance Lead building security program from scratch. Owns SOC 2, access management, infrastructure security, customer questionnaires, and compliance. Reports to CTO.

About the role

What you'll own

  • Access & identity management: Production access, service accounts, SSO, and the lifecycle of both - provisioning, periodic review, deprovisioning.
  • SOC 2: Own the program end-to-end, mapping controls to our environment, driving evidence collection, and getting us through Type 1 and then Type 2 and other security frameworks.
  • Customer trust: Own security questionnaires, RFP security sections, and the customer-facing trust narrative (trust center, security overview docs, DPAs).
  • Infrastructure security: VM lifecycle and patching, baseline hardening, secrets management, vulnerability management, and cloud security posture.
  • Security engineering (over time): Logging and monitoring, incident response runbooks, vendor security reviews, and partnering with engineering on secure design.

What we're looking for

  • 5+ years in security or security-adjacent roles
  • You've driven a SOC 2 audit - ideally owned one end-to-end, but if you ran the bulk of a program under a fractional CISO or security leader, that counts
  • Comfortable in cloud environments (AWS, GCP, or Azure) and writing enough code or Terraform to automate access and infrastructure workflows
  • You've owned customer security questionnaires and know how to make them faster
  • Strong written communication

Nice to have

  • A previous tour as the first or early security hire at a startup
  • Experience with identity tooling (Okta, AWS IAM Identity Center, Teleport, ConductorOne)
  • Experience with compliance platforms (Vanta, Drata, Secureframe)
  • Other frameworks beyond SOC 2 (ISO 27001, HIPAA, FedRAMP)
  • Background in security engineering, detection, or incident response
Skills
SOC 2AWSGCPAzureTerraformOktaAWS IAM Identity CenterTeleportConductorOneVantaDrataSecureframeISO 27001HIPAAFedRAMP
Similar roles at this salary range
All Security Engineering jobs →
Shield AI

Senior Staff Cybersecurity Engineer, Platform Security

Senior technical owner building secure-by-default infrastructure, IaC modules, policy-as-code guardrails, and CI/CD security tooling for cloud and platform engineering teams.

160k – 240kSan Diego, CASecurity EngineeringOn-site7+ YOEGoOPA
Coinbase

Insider Threat Analyst

Insider Threat Analyst responsible for triaging alerts, conducting investigations, and mitigating insider risks using SIEM, UBA, and DLP tools. Requires 3+ years in security operations or investigations with strong cross-functional collaboration skills.

135k – 159kUnited StatesSecurity EngineeringRemote3+ YOEUBADLP
Chainguard

Senior Security Engineer

Own AI platform posture end-to-end: administer Claude/ChatGPT enterprise controls, build MCP servers and agentic tooling, harden security against prompt injection and data leakage, and create spend dashboards. Requires 5+ years security/IT/DevOps experience plus hands-on AI platform administration.

130k – 160kUnited StatesSecurity EngineeringRemote5+ YOEGCPGit
Chainguard

Senior Security Engineer

Senior Security Engineer on the Cyber Resiliency team designing detection controls, engineering SOAR/AI playbooks, leading incident response, and conducting threat hunts to strengthen Chainguard's security posture.

130k – 150kUnited StatesSecurity EngineeringRemote5+ YOEGoSOAR
Metropolis

Senior Security Engineer, Infrastructure & Network Security

Lead AWS and network security infrastructure, zero-trust initiatives, and cloud automation for enterprise environments. Requires strong AWS, networking, IAM, and scripting experience.

160k – 215kLos Angeles, CASecurity EngineeringOn-site5+ YOEAWSVPN