Cybersecurity Compliance Engineer

atiSeatzRemoteUS flagUnited StatesFull-timeCybersecurity / Security EngineerMid-levelSenior$112k – $140k/year

Posted 21 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Assist the Governance, Risk, and Compliance team while collaborating with team leaders, directors, and compliance auditors.

• Ensure that products, systems, and processes adhere to regulatory, security, and compliance standards.

• Oversee daily compliance operations related to PCI DSS, SOC 2, NIST, GDPR, ISO, and specific customer obligations.

• Lead the preparation and execution of internal and external audits, which includes evidence gathering, control validation, auditor coordination, issue tracking, and follow-up on remediation.

• Conduct technical security and compliance evaluations of third-party vendors and service providers.

• Assist with customer and partner security evaluations, questionnaires, evidence requests, technical discussions, and validation of contractual requirements.

• Assess new technologies and services for potential security and compliance risks.

• Convert compliance and regulatory requirements into technical and operational specifications for Engineering, DevOps, Product, and other teams.

• Aid in addressing findings from penetration testing and external audits.

• Review and validate controls associated with IAM, logging and monitoring, vulnerability management, encryption, network security, secrets management, data protection, and secure development practices.

• Manage compliance controls and evidence utilizing GRC and compliance automation platforms.

• Identify deficiencies through control assessments, technical reviews, risk evaluations, and monitoring; track remediation plans until completion.

• Perform periodic risk assessments, access reviews, vendor evaluations, policy reviews, and ongoing compliance activities.

• Maintain policies, standards, procedures, control documentation, risk records, exceptions, and other compliance-related artifacts.

• Enhance compliance processes by leveraging automation, monitoring, and efficient evidence collection and validation.


⛳️ Requirements

• Experience in information security, audit, compliance, GRC, or a related technical field.

• Solid understanding of PCI-DSS assessments, including support for assessments, control testing, evidence collection, and remediation efforts.

• Knowledge of IAM, encryption, vulnerability management, logging and monitoring, and data protection.

• Experience conducting security and compliance evaluations of systems, technologies, processes, or third-party service providers.

• Familiarity with evaluating technical and administrative controls.

• Experience with risk assessments, control testing, compliance findings, and tracking remediation efforts.

• Ability to comprehend technical architectures, system configurations, data flows, and security controls.

• Experience managing or assisting with internal and external security and compliance audits.

• Strong skills in documentation.

• Excellent organizational and project management capabilities.

• Effective written and verbal communication skills.

• Experience with GRC or compliance automation platforms such as Drata, Vanta, Secureframe, AuditBoard, or similar tools.

• Relevant certifications in security, audit, risk, or compliance such as CISA, CRISC, PCIP, CISSP, CIA, or ISO 27001 Lead Auditor/Lead Implementer (preferred).

• Experience with NIST CSF, NIST 800-53, ISO 27001, or comparable frameworks (preferred).

• Experience supporting compliance initiatives in AWS or other cloud-native environments (preferred).

• Experience mapping controls across various compliance frameworks (preferred).

• Familiarity with cloud security and compliance concepts, particularly within AWS environments (preferred).


🏝️ Benefits

• Comprehensive health insurance.

• 401(k) plan with company matching contributions.

• Generous paid time off policy.

• Up to eight weeks of paid parental leave available for eligible caregivers.

• Flexibility and autonomy with a remote-first work environment.

• Annual allowance for professional development.

• Tools and support provided for employee success.

• Reasonable accommodations for the application, interview, and employment processes.

People also viewed

CDW17 hours ago

Information System Security Officer – DoD Secret Clearance

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$140k – $175k/year
ApplyView job
CDW18 hours ago

Consulting Engineer – Physical Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$77.7k – $108.3k/year
ApplyView job
Empower18 hours ago

Counsel – Data Protection, Privacy & Cyber Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$144.2k – $209.2k/year
ApplyView job
Gormat19 hours ago

Cloud Information Systems Security Engineer, Level 1

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$139k – $154k/year
ApplyView job
Gormat19 hours ago

Cloud Information Systems Security Engineer 2

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$168k – $183k/year
ApplyView job
LocateRisk19 hours ago

Junior IT Security Consultant, Working Student – German C1

DE flagGermany OnlyPart-timeCybersecurity / Security Engineer€15 – €17/hour
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers