Назад
Company hidden
9 дней назад

Senior Security Compliance Engineer (Cybersecurity)

139 200 - 196 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Compliance Engineer (Cybersecurity): Developing and managing GRC strategies, security assessments, and compliance programs for public-sector SaaS offerings with an accent on FedRAMP, CMMC, IRAP, SOC 2, and ISO 27001. Focus on automating control testing and evidence collection, implementing compliance-as-code, and supporting continuous monitoring for government services.

Location: Remote, United States; must be a US citizen based in the United States

Salary: $139,200–$196,000 USD per year

Company

hirify.global provides an intelligent orchestration platform for DevSecOps, helping organizations improve developer productivity and reduce security and compliance risk.

What you will do

  • Develop, implement, and manage GRC strategies and processes for public-sector and highly regulated customers.
  • Lead security assessments, audits, and certification activities, including FedRAMP continuous monitoring for hirify.global Dedicated for Government.
  • Work with customers to understand compliance requirements and provide tailored solutions.
  • Collaborate with IT, Product, Engineering, Security, Legal, auditors, and regulatory bodies to integrate compliance requirements into operations and technology.
  • Maintain policies, procedures, controls, and other compliance documentation.
  • Automate GRC processes and implement compliance-as-code or policy-as-code solutions.

Requirements

  • Valid proof of US citizenship and residency is required.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent related experience.
  • At least 5 years of experience in GRC, cybersecurity, or a related field focused on highly regulated industries.
  • Experience achieving and maintaining certifications such as FedRAMP, CMMC, SOC 2, IRAP, or ISO 27001.
  • Experience with compliance-as-code or policy-as-code, automated control testing, and evidence collection.
  • Knowledge of public-sector compliance, FedRAMP processes, cloud hyperscalers such as AWS and GCP, analytical problem-solving, and project management.

Nice to have

  • CISSP, CISM, CISA, or a similar certification.

Culture & Benefits

  • Fully remote work model with location-based eligibility requirements for this role.
  • Flexible paid time off.
  • Health, financial, and well-being benefits.
  • Equity compensation and employee stock purchase plan.
  • Growth and development fund, parental leave, and team member resource groups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →