Назад
Company hidden
7 дней назад

Senior Engineer, Security & Compliance (US)

110 000 - 160 000$
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Engineer, Security & Compliance (US) (Cloud Security and AI): Building and operating security controls, monitoring, automation, and compliance systems across SaaS products, cloud environments, and client delivery workflows with an accent on CI/CD security, privacy controls, and AI agent protection. Focus on implementing SOC 2 Type II, ISO 27001, and ISO 42001 programs, detecting and responding to incidents, and hardening AI-assisted development and production workflows.

Location: United States

Base compensation: $110,000–$160,000 per year

Company

hirify.global is a digital-first creative agency combining creativity and technology to build capabilities and solve complex problems for major brands and startups.

What you will do

  • Build and maintain code security controls across cloud infrastructure and SaaS products.
  • Operate cloud security monitoring, alerting, log aggregation, threat detection, and incident response across GCP, AWS, and/or Azure.
  • Integrate vulnerability scanners, SAST/DAST tools, and policy enforcement into CI/CD workflows.
  • Implement privacy controls covering data classification, retention, access management, and audit logging.
  • Lead technical implementation of SOC 2 Type II, ISO 27001, and ISO 42001 compliance programs.
  • Secure client environments and AI agent workflows, including access provisioning, environment segregation, prompt-injection protection, and forensic response.

Requirements

  • 5+ years of hands-on security engineering experience in a software product development team.
  • Deep practical cloud security knowledge in at least one major platform: GCP, AWS, or Azure.
  • Experience implementing security automation across CI/CD pipelines and integrating SAST/DAST and vulnerability-scanning tools.
  • Working knowledge of HIPAA, GDPR, and CCPA/CPRA, with experience translating requirements into technical controls.
  • Proficiency with security monitoring and security incident event management, plus strong technical documentation and communication skills.
  • Fluent English required, along with experience using AI-enabled development tools and hardening AI agent workflows.

Nice to have

  • Experience implementing SOC 2 Type II and ISO 27001 controls.
  • Agency, consultancy, or enterprise SaaS security experience.
  • Familiarity with ISO 42001, AI governance, and multi-tenant SaaS security.
  • CISSP, CCSP, cloud security, CIPP, or similar certifications.
  • Experience with Checkov, tfsec, OPA/Rego, or other infrastructure-as-code security tooling.

Culture & Benefits

  • Work within a distributed organization with teams across North America, South America, Europe, and Asia.
  • Collaborate across engineering, product, client delivery, and creative workstreams.
  • Support security for a global portfolio of Fortune 100 companies and startups.
  • Operate in an AI-native engineering environment focused on advancing software development practices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →