Security & Compliance Engineer
Rainfallcap
Overview Arist is the go-to agent-first enablement platform for the Fortune 500. Every deal ships with a security questionnaire, a Trust Center deep-dive, and a customer who wants to see SOC 2 + ISO 27001 + ISO 42001 evidence before signing. Today this work is split across people who have other day jobs. We need one owner. This is the person who keeps deals from stalling at security review, keeps our audits clean, and keeps our policies real instead of decorative. What you’ll own Procurement (deal velocity) Respond to security and infosec questionnaires from prospects and customers — owning SLAs that match deal timelines. Build and maintain a centralized answer library so the same question never gets answered three different ways. Stand up infosec questionnaire automation + AI augmentation so we move from artisanal to assembly-line. Triage net-new questions to the right SME — Eng for architecture, Security for controls, Legal for data handling, HR for personnel. Keep the Trust Center current and useful. Run vendor onboarding (classification + risk review), annual re-reviews, and offboarding. Compliance (SOC 2, ISO 27001, ISO 42001) Run continuous compliance — monthly/quarterly control checks Own the GRC platform (Vanta or Drata) and keep evidence current. HR controls: background checks, security awareness training, AUP acknowledgments, onboarding/offboarding ticket trails, access reviews tied to terminations. Ops controls: vendor risk assessments, BCP/DR documentation and tabletop exercises, change management evidence, board oversight artifacts. Technical controls: access provisioning + quarterly access reviews, MFA/SSO enforcement, encryption at rest and in transit, logging and monitoring evidence, vuln scans + remediation SLAs, pen test reports, secure SDLC evidence, and identifying + driving fixes for vulnerabilities in our software supply chain. Requests: Handle "right to be forgotten" GDPR and CCPA requests Auditor coordination: scoping, kickoff, walkthroughs, evidence, follow-ups, exceptions, remediation, clean report delivery to the Trust Center. Risk (policies and incident response) Maintain the policy library: infosec, AUP, access control, incident response, data classification, BYOD, encryption, change management, vendor management, BCP/DR. Run the annual policy review cycle — updates, exec approval, employee re-acknowledgment. Monitor adherence: MDM enrollment, endpoint protection coverage, SSO/MFA enforcement, privileged access reviews, exception tracking. Run incident response when something happens — detection, containment, internal + customer comms, post-mortem, regulatory and contractual notifications. What you’ll have done before Ideally, you have DevOps chops. We’d love someone who's lived on the engineering side too — comfortable in CI/CD, cloud infra (AWS/GCP), IaC (Terraform), and shipping fixes themselves rather than only filing tickets. The strongest candidates won't just audit our technical controls; they'll harden them. If you've worn both the GRC hat and the DevOps hat, tell us. Owned SOC 2 Type II at a SaaS company end-to-end. ISO 27001 a strong plus. ISO 42001 a bonus — happy to grow into it. Run a GRC platform (Vanta, Drata, or similar) as the primary admin. Read a SaaS application architecture and held your own with engineers about the security implications. You don't need to be a developer, but you can talk to ours. Led at least one real incident response, not just a tabletop. How we’ll know you’re great Questionnaire turnaround drops from weeks to days, with consistent answers. Trust Center is the first thing prospects see and the last thing they ask about. Audits are non-events. No 11th-hour evidence scrambles. Policies are followed because they’re current and clear, not ignored because they’re stale. When something goes wrong, the response is calm, fast, and well-communicated. How we work Small team. High trust. Speed-to-deploy and close deals is our edge, so your job is to make compliance and procurement match that pace, not slow it down. We default to simplicity, not 20-page specs. We expect crisp written communication and a low tolerance for ceremony that slows. Apply Send a note to maxine @ arist dot co with 1) why you’re interested in Arist and 2) what makes you exceptional for this role that spans security, compliance, and DevOps in a fast-growing startup environment. #J-18808-Ljbffr Rainfallcap
$130k - $225k
Bloomberg L.P. is seeking a skilled professional to automate security applications within their Corporate Technology - Finance team.... ...position requires a strong understanding of enterprise security, compliance, and data protection platforms, alongside the ability to...Suggested- A defense and government services integrator is seeking a part-time Security & Compliance Administrator to oversee compliance for Kubernetes and data lake deployments. The role requires an active secret clearance and a Bachelor’s degree in Cybersecurity, among other qualifications...SuggestedRemote jobPart time
- Senior Security Compliance Engineer, AWS (FedRAMP High / DoD IL5) Remote, US Description Keeper Security is hiring a Senior Security Compliance Engineer to lead the technical implementation and ongoing maintenance of FedRAMP High and DoD IL5 compliance for our AWS-based...SuggestedTemporary workRemote work
- ...partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining... ...: - Experience supporting documentation, reporting, and compliance activities - Understanding of network monitoring tools and...SuggestedMinimum wageFull timeContract workTemporary workWork experience placementRemote work
- Zafran is seeking a Senior DevOps Engineer with expertise in security and compliance to enhance their compliance posture. The role includes leading efforts for achieving certifications like SOC 2 and FedRAMP, implementing security controls across cloud infrastructure,...SuggestedRemote jobFlexible hours
- ...Job Description Job Description Salary: Senior Network Security Engineer Company:SoHo Dragon represents an Investment Bank client Location:Hybrid Jersey City, NJ (4 days in office) Contract Duration: 24 months Responsibilities Operate and support...Contract workFor contractorsWork at office
- Assurant, Inc. is seeking a Compliance Business Technical Specialist to enhance workflows and systems within the organization. This role involves evaluating operational processes, leading improvement projects, and maintaining business systems for peak performance. The...
$234.4k - $385k
...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial... ...About the Role As a Security Engineer, Application Security you will be responsible... ...to inquiries unrelated to job posting compliance. We are committed to providing...Work at officeRemote workRelocation package$200k - $255k
...Security Engineer We are seeking an experienced Security Engineer with a specialization in product security to join our team. As a strategic... ...about the latest security threats, vulnerabilities, and compliance mandates affecting cloud environments, provide strategic...Odd jobImmediate start$167.5k - $226.3k
...Senior Security Engineer (AI Security) New York, New York Apply Who We Are At Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in...Casual workWork at officeLocal area$237.6k - $297k
...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...Full time- ...Francisco, NYC, or London offices. You'll own application security at a company where the app layer is the highest-priority security... ...and guardrails that make the safe path the easy path for 50+ engineers Threat models for new features and architecture changes -...Work at officeRemote workRelocation packageShift work
$150k - $200k
...Senior Security Engineer - Application Security New York, NY About the Role This is an opportunity to join K's critical InfoSec... ...multiple areas such as AppSec, CloudSec, SecOps, ITSec, and Compliance and apply it towards reading and interpreting architecture,...Full timeWork at officeLocal area$104k - $156k
...Type Remote/Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design, build, and operate... ...(SC-300). ~ Knowledge of Zero Trust principles and compliance standards (e.g., GDPR, HIPAA). ~ Exposure to other cloud...Remote work- ...join us on our journey to create a better future of work with AI. About the role This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems...Full timeWork at officeLocal areaFlexible hours
$165k - $242k
...Senior Security Engineer, Enterprise Security CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI...Temporary workFor contractorsRemote workFlexible hours$120k - $175k
...We are seeking a Security Research Engineer to operate as a hybrid Forward Deployed Engineer and offensive security researcher. You'll be on the... ...Azure) and containerized environments Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS) as they relate to...- ...Security Research Engineer We are seeking talented engineers intent on changing the security industry. If you have experience on fast-moving teams, building security products that developers love, and driving projects to completion through ambiguity: we want to talk...
$135k - $236.25k
...all official communication will only be sent from @Rippling.com addresses. About The Role Rippling is looking for a hands‑on Security Engineer - Offensive Security to join our growing security team. In this role, you’ll design and execute offensive security initiatives...Work at office3 days per week- Senior Security Engineer, Security Incident Response Team (SIRT) Remote, US GitLab is the intelligent orchestration platform for DevSecOps... ..., improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million...Remote work
- A leading technology firm is looking for a passionate Security Engineer to join their Product Security team. In this role, you will design secure architectures and develop tools that protect Chainlink and support the Web3 ecosystem. Candidates should have experience in...Remote job
- ...fast-growing fintech company in the U.S. is seeking a Senior Security Engineer to enhance security within their innovative platform. This... ...environments, conducting vulnerability assessments, and ensuring SOC 2 compliance. The ideal candidate will possess extensive AWS experience...Remote job
- A financial technology company in New York is seeking a Senior Security Engineer to create a security foundation that scales trust to millions of consumers. You will embed security into product capabilities, drive security-by-design, and architect systems for data protection...
- Job DescriptionFragomen is seeking a Security Engineer - Application Security to join our talented Cyber Security team in our Technology Innovation Lab in Pittsburgh.Our industry-leading, immigration specific software and supporting infrastructure is undergoing tremendous...Local area
- A tech consulting firm is looking for a Sr. Infrastructure Security Engineer to develop and enhance security systems across AWS, GCP, and Azure. This remote role requires expertise in cloud security and automation, with responsibilities including architecting security systems...Remote job
$40 per hour
A cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical problems. Ideal candidates should have over 2 years in cybersecurity, strong analytical and writing skills, and some coding experience. This is a remote...Remote jobHourly payFlexible hours$100k - $140k
...keep reading - this may be your next great opportunity. As a Security Engineer, you will be part of BlackCloak’s internal technology team... ...corporate security, information technology operations, and compliance. This is a critical role that is both hands‑on and strategic...Full timeTemporary workRemote workHome officeFlexible hoursShift work$195k - $240k
Here at Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations... ...massive cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We’re looking...Work at office- BSH Home Appliances Corporation is seeking a CS Material Compliance Engineer to ensure that products comply with packaging and labeling regulations. This remote full-time role requires a four-year degree in Chemical or Mechanical Engineering and 3-5 years of regulatory...Remote jobFull time
- ...provider in the United States is seeking a Customer Onboarding Engineer to ensure secure integration of customers into their platform. This hands-... ...requires expertise in DevSecOps, CI/CD management, and compliance with federal regulations. Ideal candidates will have 3-5...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security & Compliance Engineer. Be the first to apply!
- security infrastructure engineer New York, NY
- senior cloud security engineer New York, NY
- azure security engineer New York, NY
- senior application security engineer New York, NY
- lead security engineer New York, NY
- physical security engineer New York, NY
- security engineering manager New York, NY
- endpoint security engineer New York, NY
- sr information security engineer New York, NY
- senior security operations engineer New York, NY



