Source Job

$6,000–$7,500/mo
US

  • Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
  • Automate compliance workflows, evidence collection, access reviews, and security checks.
  • Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.

Python JavaScript Security Compliance AWS IAM

20 jobs similar to Compliance Engineer

Jobs ranked by similarity.

US

  • Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
  • Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
  • Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.

Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.

$174,000–$238,000/yr
US

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
  • Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.

Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.

Canada Unlimited PTO

  • Own the security compliance program end-to-end, including audits, customer trust, vendor risk, and vulnerability management.
  • Automate evidence collection and control monitoring to be audit-ready year-round, not just during the August–November season.
  • Act as the external security face for enterprise prospects and translate AI regulatory changes into requirements.

Ada is an AI customer service company that helps enterprises automate customer conversations with AI agents. Founded in 2016, we've powered over 5.5 billion interactions and raised over $250M from top investors.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

$105,000–$123,750/yr
Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

$112,000–$140,000/yr
US

  • Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
  • Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
  • Perform technical security and compliance reviews of third-party vendors and service providers.

iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.

$191,250–$258,750/yr
US

  • Architect and automate security workflows across CI/CD and compliance operations.
  • Integrate and monitor security tooling within automated pipelines.
  • Build automation for compliance and ATO artifacts.

Our partner is a technology company that builds secure, automated cloud environments for mission-critical programs. They offer a fully remote work model with a focus on autonomy and work-life balance.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.

US

  • Support security and compliance initiatives across cloud-based environments.
  • Conduct web application penetration testing and vulnerability assessments.
  • Implement and maintain security controls aligned with compliance frameworks.

Epsilon ASI is a technology company focused on providing secure and compliant environments for its clients. The company is looking for early-career security professionals to join its highly technical team in a remote setting.

$126,000–$140,000/yr
US Unlimited PTO

  • Serve as the security subject matter expert on customer calls, owning responses to security questionnaires and due diligence requests.
  • Operate and tune security tools including CrowdStrike EDR, Entra ID identity controls, and vulnerability management.
  • Drive the SOC 2 Type 2 compliance program using Vanta, maintaining controls, policies, and vendor risk reviews.

AssetWatch is a remote-first industrial condition monitoring company that helps manufacturers predict equipment failure before it happens. The team includes world-renowned engineers and distinguished business leaders, united by a goal to build the future of predictive maintenance.

$175,000–$210,000/yr
Global Unlimited PTO

  • Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
  • Manage identity and access, device fleet, and vendor security with ownership over control state.
  • Drive compliance as a sales enabler and own the customer-facing security package.

Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.

Europe 5w PTO

  • Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
  • Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
  • Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.

Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.

US

  • Own IRAP and ISMAP program strategy and execution across Australia and Japan.
  • Coordinate with regional assessors and government agencies to maintain compliance.
  • Design and maintain compliance documentation and manage continuous monitoring.

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.

US

  • Evaluate security controls and assess alignment with ISO 27001, SOC 2, NIST, and other frameworks.
  • Coordinate with internal teams and external auditors to support audit engagements and maintain control evidence.
  • Apply risk-based monitoring and contribute to compliance oversight, security operations, and secure-by-design initiatives.

The company is a mission-driven cybersecurity partner focused on strengthening information security, privacy, and organizational resilience. While specific size details are not provided, the team fosters a collaborative, high-impact environment with opportunities for continuous learning and career development.

$166,600–$208,300/yr
North America

  • Design and implement cloud security posture and automation to protect customer trust.
  • Enable cyber resilience and lead zero trust initiatives across the infrastructure.
  • Collaborate with engineering teams to enhance reliability and security of cloud systems.

Mercury is a fintech company providing banking and financial services for startups, focusing on simplicity and security. With a team of around 500 employees, the culture is collaborative, innovative, and values diversity.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

India Unlimited PTO

  • Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
  • Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
  • Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.

Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.

United States

  • Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
  • Strengthen security monitoring, detection, incident response, and integrate security into CI/CD pipelines.
  • Support compliance efforts including SOC 2 and ISO audits, and lead customer security reviews.

AlertMedia helps organizations protect their people, operations, and brand with a modern Risk Intelligence and Response platform. It is a high-growth, PE-backed SaaS company with more than 4,000 clients and a 10-year award-winning culture.

$114,800–$173,250/yr
US

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
  • Drive recurring continuous monitoring and evidence workflows across multiple teams.
  • Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.

Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.

US

  • Design, implement, and maintain security controls across AWS environments, including IAM, VPC, encryption, and logging.
  • Integrate security checks into CI/CD pipelines and harden Kubernetes/EKS workloads using Terraform and policy-as-code.
  • Automate vulnerability management, security monitoring, and incident response to reduce cloud and application risk.

Electric Power Engineers provides consulting expertise and energy intelligence software solutions for power and energy clients, focusing on modern, secure, and resilient grid challenges. They are leaders in the renewables space and emphasize collaboration, innovation, and making an impact on communities and the environment.