Назад
Company hidden
9 часов назад

Compliance Engineering Lead (Security)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Compliance Engineering Lead (Security) (SOC 2/ISO 27001): Building and owning Socket’s compliance program, automated evidence pipelines, risk and vendor risk programs, and customer-facing assurance artifacts with an accent on SOC 2 Type II, ISO 27001 certification, and compliance automation. Focus on designing scheduled control monitoring, evaluating compliance platforms, maintaining the ISMS, and scoping AI assurance frameworks.

Location: Remote in the United States

Company

hirify.global provides security teams with tools to find, audit, and manage open-source code.

What you will do

  • Own the SOC 2 Type II program, including audit scope, auditor relationships, observation windows, controls, findings, and evidence pipelines.
  • Lead hirify.global through ISO 27001 certification by defining the scope and ISMS, running gap assessments and internal audits, and maintaining the certified management system.
  • Build and maintain automated evidence collection and control monitoring across GCP, GitHub, the identity provider, MDM, and ticketing systems.
  • Run risk management and vendor risk programs with meaningful risk tiering, reviews, and renewal processes.
  • Own the customer-facing assurance surface, including the trust portal and security artifact library for enterprise buyers.
  • Evaluate AI assurance frameworks including ISO/IEC 42001, AIUC-1, the EU AI Act, and the NIST AI Risk Management Framework.

Requirements

  • Personally owned at least two complete SOC 2 Type II cycles, including auditor relationships, scoping, evidence, and findings.
  • Experience taking an organization through ISO 27001 certification or operating an ISMS through surveillance audits.
  • Ability to build and maintain service automations and scheduled control-monitoring jobs, including work with GCP and GitHub.
  • Hands-on experience with Drata, Vanta, or similar compliance platforms, with clear judgment about their strengths and limitations.
  • Strong prioritization, analytical judgment, and writing skills for auditors, enterprise security reviewers, engineers, and executives.
  • Experience working in a remote, fast-moving environment with shifting priorities and broad ownership across Security, Engineering, Legal, and Go-to-Market.

Nice to have

  • Exposure to AI governance frameworks such as ISO/IEC 42001, NIST AI RMF, or the EU AI Act.
  • Experience at a security vendor or another company subject to demanding customer assurance requirements.
  • Experience with contract security reviews alongside Legal.
  • Experience building compliance automation in-house.

Culture & Benefits

  • Remote-first work with quarterly team off-sites.
  • Competitive salary bands and a meaningful equity program.
  • Health benefits for employees and families with 99% coverage.
  • Flexible time off, holidays, and a winter shutdown.
  • Paid parental leave.
  • Culture focused on excellence, urgency, rigorous thinking, ownership, trust, and customer focus.

Hiring process

  • Informational conversation with Talent, followed by an interview with the CISO.
  • Working session covering an automated control and the design of an evidence pipeline.
  • Cross-functional interviews with Engineering and Go-to-Market, followed by a debrief and decision.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →