9 часов назад
Compliance Engineering Lead (Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Compliance Engineering Lead (Security) (SOC 2/ISO 27001): Building and owning Socket’s compliance program, automated evidence pipelines, risk and vendor risk programs, and customer-facing assurance artifacts with an accent on SOC 2 Type II, ISO 27001 certification, and compliance automation. Focus on designing scheduled control monitoring, evaluating compliance platforms, maintaining the ISMS, and scoping AI assurance frameworks.
Location: Remote in the United States
Company
provides security teams with tools to find, audit, and manage open-source code.
What you will do
- Own the SOC 2 Type II program, including audit scope, auditor relationships, observation windows, controls, findings, and evidence pipelines.
- Lead through ISO 27001 certification by defining the scope and ISMS, running gap assessments and internal audits, and maintaining the certified management system.
- Build and maintain automated evidence collection and control monitoring across GCP, GitHub, the identity provider, MDM, and ticketing systems.
- Run risk management and vendor risk programs with meaningful risk tiering, reviews, and renewal processes.
- Own the customer-facing assurance surface, including the trust portal and security artifact library for enterprise buyers.
- Evaluate AI assurance frameworks including ISO/IEC 42001, AIUC-1, the EU AI Act, and the NIST AI Risk Management Framework.
Requirements
- Personally owned at least two complete SOC 2 Type II cycles, including auditor relationships, scoping, evidence, and findings.
- Experience taking an organization through ISO 27001 certification or operating an ISMS through surveillance audits.
- Ability to build and maintain service automations and scheduled control-monitoring jobs, including work with GCP and GitHub.
- Hands-on experience with Drata, Vanta, or similar compliance platforms, with clear judgment about their strengths and limitations.
- Strong prioritization, analytical judgment, and writing skills for auditors, enterprise security reviewers, engineers, and executives.
- Experience working in a remote, fast-moving environment with shifting priorities and broad ownership across Security, Engineering, Legal, and Go-to-Market.
Nice to have
- Exposure to AI governance frameworks such as ISO/IEC 42001, NIST AI RMF, or the EU AI Act.
- Experience at a security vendor or another company subject to demanding customer assurance requirements.
- Experience with contract security reviews alongside Legal.
- Experience building compliance automation in-house.
Culture & Benefits
- Remote-first work with quarterly team off-sites.
- Competitive salary bands and a meaningful equity program.
- Health benefits for employees and families with 99% coverage.
- Flexible time off, holidays, and a winter shutdown.
- Paid parental leave.
- Culture focused on excellence, urgency, rigorous thinking, ownership, trust, and customer focus.
Hiring process
- Informational conversation with Talent, followed by an interview with the CISO.
- Working session covering an automated control and the design of an evidence pipeline.
- Cross-functional interviews with Engineering and Go-to-Market, followed by a debrief and decision.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →