Security and Compliance Engineer
Nexxa
About the Role
Selling autonomous systems into manufacturing, infrastructure, and logistics means our customers audit us before they trust us — security and compliance are a precondition for deploying our platform, not a function beside it.
We hold SOC 2 Type 2 and ISO 27001 , and we're moving toward more certifications because governing autonomous industrial systems responsibly is a commercial requirement in our market. You'll own our certification programs and the security and infrastructure underneath them — across our multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments, not customer plant-floor or control-system security.
This role is ideal for candidates who want real, ongoing ownership of a security function, including standing up and running one of the industry's first AI management systems, at a company where trust and compliance directly determine whether customers deploy the platform at all.
What You'll Do
Own the compliance calendar across SOC 2 Type 2 and ISO 27001 — evidence collection, access and vendor reviews, control monitoring, internal audit, management review, policy refresh, and audit readiness
Triage security findings across cloud posture, code scanning, dependencies, and secrets, and drive remediation to closure
Remediate what you triage directly in infrastructure as code, IAM policy, and pipeline configuration
Administer identity and access across cloud and SaaS, including SSO/federation, least-privilege roles, and the joiner/mover/leaver lifecycle
Support internal IT operations — endpoint fleet and device compliance, SaaS and license administration, asset inventory, support requests — while keeping the human cost of them flat as the company grows
Serve as the working interface to external auditors, our certification body, and customer security and procurement reviews
Build controls into infrastructure so they hold automatically, replacing manual verification with guardrails that fail closed
Harden CI/CD and the software supply chain — build identity, artifact provenance, dependency and secret hygiene
Debug production issues across cloud infrastructure, containers, and networking, and write the postmortem that keeps the fix from being forgotten
Produce documentation others rely on: runbooks, control narratives, architecture notes, postmortems
Required Qualifications
Professional experience in security engineering, infrastructure/platform engineering, or a closely related technical role — broad competence across security, networking, and operating systems, with real depth in at least one
Deep hands-on experience with:
Security fundamentals — trust boundaries and blast radius, authentication vs. authorization, least privilege, secrets handling, and judging real-world exploitability of findings
Networking — diagnosing connectivity issues across routing, firewalls/security groups, DNS, TLS termination, and proxies; comfortable with VPN/private connectivity and packet captures
Linux operating systems — processes, filesystems, permissions, systemd, resource limits, log analysis, and how containers relate to the host
Cloud infrastructure — hands-on with AWS or GCP beyond the console: IAM, networking, compute, and their failure modes
Strong scripting/automation skills ( Python , Bash , Go , or similar) — recurring manual work gets scripted away, not tracked by hand
Strong writing ability: control narratives, runbooks, postmortems, audit responses, risk assessments
Proven judgment under ambiguity — able to rank findings honestly and defend the ranking
CS/CE degree or equivalent hands-on experience
Preferred Qualifications
Hands-on ISO 27001 experience — operating an ISMS, recertification, surveillance audits, internal audit programmes, Statement of Applicability, risk treatment
SOC 2 experience in practice — producing evidence, answering auditor requests, remediating findings against a real deadline
Any exposure to AI governance or ISO 42001 — AI risk assessment, model inventory, AI lifecycle controls, the EU AI Act
Infrastructure as code at scale ( Pulumi primarily, Terraform secondarily — deep Terraform experience transfers fine)
Multi-account cloud organization experience: landing zones, org-level policy guardrails, centralized logging, cross-account access patterns
Identity provider and endpoint management at scale ( Google Workspace or Microsoft 365 , SSO/SAML/OIDC, MDM and device compliance tooling)
Cloud security tooling experience ( CSPM , SAST/SCA , vulnerability management platforms), including their false-positive rates
Container orchestration on ECS , EKS , or Kubernetes
Observability: metrics, logs, traces, and the judgment to instrument what will matter later
Experience across both AWS and GCP , including workload identity federation
Cloud cost awareness — you notice when spend and value diverge
Startup or high-growth experience building process rather than following one
What Success Looks Like
You can own ambiguous, high-stakes security and compliance problems end-to-end
Controls you build hold automatically as the company scales — you design for guardrails that fail closed, not recurring manual verification
You bring strong technical judgment on tradeoffs between security rigor, velocity, and cost
You raise the bar for security rigor and operational discipline across the team
You help define what's next for the security program, not just execute what's known
Why Join Nexxa.ai?
Innovative Environment : Play a critical role in transforming heavy industries through groundbreaking AI and automation technologies
Collaborative Culture : Be part of a team that values innovation, discipline, and continuous improvement
Professional Growth : Benefit from significant opportunities for career development and advancement
Competitive Compensation : Enjoy a comprehensive salary and equity package reflective of your expertise and contributions
If you're passionate about building the security and compliance backbone for advanced AI solutions in the real world, we'd love to connect.
- ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Security / Compliance Engineering to join our team in Jersey City, New Jersey (US-NJ), United States (US).AI Security & Compliance EngineerAI/ML...SuggestedTemporary workWork at officeRemote workFlexible hours
$118.8k - $205.6k
...help us connect people and build communities to create economic opportunity for all.The Global Information Security team is responsible for driving security compliance activities for eBay Payments, Marketplaces, Corporate IT, and adjacent businesses. The Security...SuggestedImmediate startRemote workVisa sponsorshipFlexible hours$115k - $125k
OverviewThe Tyndale Company is seeking a Security and Compliance Engineer to join their dynamic IT team! This position supports Tyndale's day-to-day IT security operations and compliance readiness across infrastructure, identity, applications, SaaS platforms, integrations...SuggestedFull timeCasual workRemote work1 day per week- ...Compliance Professional Born from groundbreaking research at Columbia University and... ...Yale University, CertiK is a leading Web3 security company focused on securing blockchain... ...usable deliverables, and work as/with Engineering to convert recurring compliance work into...SuggestedContract workRemote work
- ...Responsibilities: - Experience supporting documentation, reporting, and compliance activities - Understanding of network monitoring tools and... ..., compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic...SuggestedMinimum wageContract workTemporary workWork experience placementRemote work
$100k - $160k
...Are you the kind of security professional who likes turning findings into fixes? Do you enjoy working across AWS, Linux, and compliance-driven environments to keep systems secure and practical... ...a hands-on Security & Compliance Engineer to help maintain and improve the...Remote work$107.9k - $195.05k
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned... ..., particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device,...Full timeNight shift- ...logistics means our customers audit us before they trust us — security and compliance are a precondition for deploying our platform, not a... ...multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments...Full time
- A defense and government services integrator is seeking a part-time Security & Compliance Administrator to oversee compliance for Kubernetes and data lake deployments. The role requires an active secret clearance and a Bachelor’s degree in Cybersecurity, among other qualifications...Remote jobPart time
- ...Description Job Description Work with cross-organizational stakeholders to determine the understandability and relevance of published security policies and their impact on the business. Develop cyber resilience strategies. Design policies and procedures regarding risk...Remote work
- ...are a provider of outsourced IT and cyber security services for small and medium-sized... ...access management challenges, online fraud, compliance pressure, or any number of other... ...Summary The Security and Compliance Engineer will be a key member within the security...Work at officeRemote workFlexible hoursShift work
- ...About the Role We are hiring a Compliance Engineering Lead to own compliance as an engineered system rather than a calendar of reminders. Socket sells to security teams. Our customers ask harder questions than most buyers ask, and they are right to. That means our...Full timeContract workRemote workShift work
$97.01k - $164.91k
...Job Description The Process Quality Engineer (PQE) will lead and execute quality assurance... ...(QC) as necessary to validate process compliance. Maintain a regular and predictable... ...processes and quality practices. #LI-CC2 A security clearance or access with Polygraph is...Full timeWork at officeLocal areaRemote work- ...Yale University, CertiK is a leading Web3 security company focused on securing blockchain... ...monitoring, incident response, and compliance services for some of the largest projects... .... About the Role You will support the Engineering team in regulatory research, licensing...Contract workInternship
$175k - $190k
...solutions with the ingenuity of the world’s largest community of security researchers to continuously discover, validate, prioritize, and... ...function is modernizing and re-architecting the revenue engine, building an AI-native operating model that connects planning,...Contract workApprenticeshipLocal areaRemote workFlexible hoursShift work$104.9k - $182.13k
...want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Security / Compliance Engineering to join our team in Jersey City, New Jersey (US-NJ), United States (US). AI Security & Compliance Engineer AI/ML...Temporary workWork at officeRemote workFlexible hours$64.93k - $110.37k
...Description BAE Systems is seeking Digital Signal Processing Engineers to work in our Command, Control, Communications, Computers, Intelligence... ...of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services...Full timeContract workWork experience placementLocal areaRemote workFlexible hoursNight shift$100k
...our team! We are seeking a Digital Signal Processing (DSP) engineer to design, analyze and develop RF and optical systems and payloads... ...test sites. Are able to obtain an interim Top-Secret level security clearance by your start date and can ultimately obtain a TS/...Temporary workWork experience placementInterim roleRemote workRelocation packageFlexible hours- ...Job Description The Senior Process Engineer works as a technical expert on the successful delivery of projects for clients as a member... ...Us We set out more than 160 years ago to promote the security of life and property at sea and preserve the natural environment...Work at officeRemote workMonday to FridayFlexible hours
$90k - $120k
...Process Engineer When you work at Trex, you're helping to grow and enhance a true original. You join a company that boldly launched... ...Verify is a web-based system operated by the Department of Homeland Security (DHS) and the Social Security Administration (SSA) that allows...Full timeLocal area- ...Space is a critical domain, connecting our technologies, our security and our humanity. While others view space as a destination, we... ...space and find a career that's built for you. As a Component Engineer you'll work on a broad range of projects, in both a laboratory...Full timeWork at officeRemote workRelocationFlexible hoursShift work
- ...Senior Blockchain/Smart Contract Engineer We have been heads down building real Blockchain technology over the last 3 years in stealth... ...our cryptocurrency built on ETH Work regularly with security auditors and external contributors to document and upgrade currency...Contract workSummer workRemote work
$100k - $150k
...Voyager is an innovative space, defense, and national security technology company committed to advancing and delivering transformative... ...person, forge the future with Voyager. The Component Test Engineer is responsible for the development and evolution of Voyager's...Long term contractPermanent employmentFull timeContract workFlexible hours$82k - $97k
...basis protected by law. About the role: As a Vendor Risk & Compliance Engineer, you will be uniquely positioned to enhance Vendor risk... ...such as NIST, HIPAA, and SOC2. You'll lead and conduct vendor security risk assessments end to end — integrate AI to improve accuracy...Full timePart timeFlexible hours- ...solutions, tested leadership, and trusted results to enable national security missions worldwide. Job Description **This position is... ...of contract** SOSi is seeking a Business Process Engineer to support mission requirements for a structured approach to further...Contract workRemote workWorldwide
$80.5k - $149.5k
...resolve challenges, maintain quality system records, and ensure compliance with regulatory standards using cGMP and SOPs. Your... ...preventative actions (CAPA) in accordance with timelines. Who you are Engineer: BS/BA in Life Sciences/Engineering preferred, and 0-2 years of...Full timeLocal areaRelocation package- ...actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SR. RF & WIRELESS COMPLIANCE ENGINEER (STARLINK)SpaceX is leveraging its experience building rockets and spacecraft to deploy Starlink, the world’s most advanced...Permanent employmentLive inRemote workWorldwideWeekend work
$172k - $203k
...other major cities (like Boston and New York) occasionally gather informally at local co-working locations.We are looking for a Compliance Engineer to join our Hardware team. In this role, you will be the primary driver for global regulatory certifications, ensuring our...Work at officeLocal areaRemote workFlexible hours$110.57k - $147.43k
...solar and storage company in the country and has a mission to bring stably priced resilient power to the masses.OverviewThe Compliance Engineer is responsible for leading SnapNrack's regulatory compliance, certification and product approval activities. The role owns compliance...Full timeRemote work- ...enterprise services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering, Environmental, Sustainability, and Human Capital.... ...that support U.S. energy infrastructure, energy security, domestic production, and strategic energy investments...Full timeContract workTemporary workFor contractorsWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security and Compliance Engineer. Be the first to apply!
- security engineering manager Remote
- application security engineer Remote
- sr information security engineer Remote
- sr security engineer Remote
- senior application security engineer Remote
- staff security engineer Remote
- information system security engineer Remote
- principal security engineer Remote
- physical security engineer Remote
- security engineer Remote




