
Security Operations Engineer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in United States.
• Lead compliance audit cycles for SOC 2, ISO 27001, PCI 4.0, and additional standards
• Collect and organize audit evidence while documenting, designing, and establishing controls
• Collaborate directly with auditors during fieldwork and assist in remediation efforts
• Manage the Vanta compliance automation platform, oversee control statuses, maintain integrations, and update the risk register
• Conduct vendor and third-party risk assessments and security reviews
• Collaborate with sales and legal teams on customer and vendor security questionnaires, RFP security sections, and trust-and-safety inquiries
• Lead the triage and prioritization of vulnerabilities, monitor remediation against SLAs, and report on metrics
• Monitor and respond to alerts related to endpoint, cloud, identity, and application security
• Assist in incident response by collecting evidence, constructing timelines, documenting findings, and tracking post-incident actions
• Maintain security runbooks, process documentation, and operational playbooks
• Develop scripts, integrations, reporting tools, and automation solutions for security operations
• A minimum of 3 years of experience in security operations, GRC, IT security, or a related field
• At least 2 years of experience with compliance audit cycles
• Possession of one or more security certifications—CISA, Security+, AWS Security Specialty, or equivalent
• Experience in executing recurring security operations tasks, including security reviews, vulnerability tracking, alert triage, or control monitoring
• Strong organizational skills for managing multi-week evidence collection processes involving multiple stakeholders
• Excellent written communication skills
• Proficiency in Python and the ability to read code written by others
• Familiarity with AI-assisted development tools such as Claude Code, Copilot, or similar
• Nice to have: knowledge of application security fundamentals, security tools across the development lifecycle, infrastructure-as-code, CI/CD pipeline security, AWS and IAM, identity and SaaS administration, SIEM detections and alerting pipelines, endpoint security, cloud security posture tools, AI/ML security, or experience in high-growth startup security
• Competitive equity grants
• 100% employer-paid benefits
• Fully remote work flexibility
• 401k match up to 4% for all US-based full-time team members
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.