
Compliance Engineering Lead
Posted Aug 26

Posted Aug 26
This is a fully remote position, open to applicants in United States.
• Take full ownership of SOC 2 Type II processes from start to finish, which includes managing the observation window, auditor relationships, audit scope, controls, evidence pipeline, and customer-facing reports.
• Guide Socket through the ISO 27001 certification process and ensure the maintenance of the Information Security Management System (ISMS).
• Develop and sustain automated evidence collection systems from GCP, GitHub, identity providers, MDM, and ticketing platforms.
• Establish scheduled control monitoring that triggers alerts for compliance deviations.
• Eliminate repetitive manual compliance activities.
• Maintain a risk register utilized by leadership for informed decision-making.
• Oversee third-party risk management, including tiering, reviews, and renewal cycles in collaboration with an external security partner.
• Launch and manage a customer-facing trust portal and assurance artifact library.
• Lessen the workload associated with enterprise customer questionnaires.
• Analyze AI assurance frameworks and regulations such as ISO/IEC 42001, AIUC-1, the EU AI Act, and the NIST AI Risk Management Framework.
• Report directly to the Chief Information Security Officer (CISO).
• Recruit and lead an initial team member dedicated to handling security questionnaires, RFPs, and contract security review in partnership with the Legal team.
• Have personally managed at least two complete SOC 2 Type II cycles as the accountable individual, involving auditor relationships, scope definition, evidence collection, and findings resolution.
• Proven experience in guiding an organization through ISO 27001 certification or managing an ISMS during surveillance audits.
• Proficient in building and maintaining automation solutions across various services and APIs.
• Familiarity with operating within GCP, GitHub, identity providers, MDM, and ticketing systems.
• Hands-on experience with compliance platforms such as Drata, Vanta, or similar tools.
• Capability to prioritize genuine compliance risks over auditor formatting preferences.
• Excellent writing skills tailored for audiences including auditors, enterprise security reviewers, engineers, and executives.
• Readiness to tackle issues across Security, Engineering, Legal, and Go-to-Market teams.
• Experience working in a remote, dynamic environment with changing priorities.
• Nice to have: familiarity with ISO/IEC 42001, NIST AI RMF, and the EU AI Act; experience with a security vendor; involvement in contract security review with Legal; and in-house compliance automation experience.
• Competitive salary ranges in the market.
• Significant equity program.
• Comprehensive health benefits for you and your family with 99% coverage.
• Flexible time-off policy, holidays, and a winter shutdown period for rest and relaxation.
• Paid parental leave.
• Remote-first work setup.
• Quarterly team off-site meetings.
Arista Networks
Coforma
Platform.sh
Arista Networks
Get handpicked remote jobs straight to your inbox weekly.