
Security & Compliance Engineer
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in Japan.
• Take ownership and lead the comprehensive implementation, maintenance, and renewal of SOC 2 Type II, ISO 27001, PCI DSS, and relevant compliance programs.
• Create, uphold, and enforce security policies, procedures, and documentation that align with industry standards.
• Conduct regular risk assessments, internal audits, and reviews of control effectiveness.
• Oversee third-party risk assessments and vendor security evaluations.
• Act as the main contact for external audits and certification entities.
• Collaborate with legal, privacy, and engineering teams on matters related to data protection.
• Keep track of regulatory updates in Japan and other operational markets.
• Establish and nurture relationships with engineering teams to integrate security and compliance requirements into development processes.
• A minimum of 3 years of experience in security compliance, risk, or governance positions.
• Demonstrated success in achieving and sustaining SOC 2 Type II and/or ISO 27001 certification.
• Practical experience with compliance automation platforms, preferably Drata.
• Comprehensive understanding of security frameworks and standards, including SOC 2 Trust Services Criteria, ISO 27001/27002, NIST CSF, and data privacy regulations.
• Excellent written and verbal communication abilities.
• Experience in coordinating with external auditors and managing the audit process from start to finish.
• Capability to work collaboratively with engineering teams to address findings and implement controls without requiring extensive hands-on coding.
• Knowledge of AWS security services at an operational level.
• Flexible work arrangements.
• Options for remote work.
Quisitive
Cisco
Highmark Health
BlackStone eIT
Get handpicked remote jobs straight to your inbox weekly.