Source Job

  • Owns product, cloud, engineering, vendor, AI-tooling, and compliance security functions.
  • Builds practical guardrails for AI tools, agents, MCPs, data leakage, and automation.
  • Understands OWASP, IAM, secrets, cloud security, vulnerability management, CI/CD, incident response, and frameworks like SOC 2, ISO 27001, GDPR, or HIPAA.

OWASP IAM Cloud Security Vulnerability Management CI/CD

20 jobs similar to Security & Compliance Lead

Jobs ranked by similarity.

US

  • Support the day-to-day security posture of systems across cloud and on-prem environments, including vulnerability management and remediation tracking.
  • Partner with infrastructure, platform, and engineering teams on secure configuration, access control, logging, and incident readiness.
  • Support compliance activities related to GovRAMP, FedRAMP, PCI DSS, and internal reviews using AWS security tooling.

Grant Street Group is a growing company that provides SaaS products for electronic payments, auctions, and tax collection. The company fosters a culture of teamwork, professional excellence, and individual responsibility in a technology-rich remote environment.

UK Global

  • Lead and own the ongoing operation and maintenance of Samsara’s vulnerability management program.
  • Collaborate with engineering teams to track and support the remediation of identified vulnerabilities.
  • Champion Samsara’s cultural principles in daily work.

Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. As a recently public company with a global team, they foster a culture of rapid career development and encourage employees to architect their own careers.

US

  • Enable software engineering teams to continuously improve the security posture of products and SaaS environments through AppSec and DevSecOps expertise.
  • Serve as the go-to AppSec expert, mentoring engineers on secure design patterns and coding practices while collaborating on threat models and design reviews.
  • Lead automation of vulnerability management tooling across CI/CD pipelines, perform security code reviews, and contribute to compliance strategies.

Hypori is a high-growth cybersecurity SaaS company transforming how organizations think about secure mobility. Backed by $55M in funding from investors including UBS and AE Industrial Partners, the company is expanding into new commercial and regulated markets.

US

  • Embed security into every stage of software delivery across multi-cloud environments (AWS, Azure) as a hands-on technical leader.
  • Architect secure, scalable infrastructure, set engineering standards, and mentor a team of DevSecOps engineers.
  • Champion a shift-left security culture, integrate AI-powered tooling, and partner with cross-functional teams to align secure cloud solutions with business objectives.

ComPsych is the worldwide leader in organizational mental health, well-being, and absence management, dedicated to igniting human potential in workplaces across the globe. For over 40 years, they have combined technology with human expertise to support more than 75,000 customers worldwide, touching over 160 million lives across 200 countries.

US Unlimited PTO

  • Serve as a senior security and compliance advisor for clients in finance, VC, PE, and biotech, translating complex requirements into practical action plans.
  • Lead consultative conversations on governance, risk, controls, AI adoption, and audit readiness, delivering clear executive-level recommendations.
  • Build and refine Outpost's service delivery playbooks, templates, and documentation to scale the offering and improve client experience.

Pliancy is fundamentally changing how businesses value technology, specializing in IT support for life sciences, capital management, and startups. With a people-first culture, the company prioritizes curiosity and empathy, investing in long-term employee success.

US

  • Lead integration of security across the SDLC, embedding automated testing into CI/CD pipelines.
  • Secure cloud-native AWS architectures and enforce least privilege access and runtime protections.
  • Perform threat modeling, automate compliance, and innovate with AI security standards.

TrueML is a mission-driven financial software company that uses machine learning to improve customer experiences for distressed borrowers. The team includes data scientists, financial services experts, and customer experience fanatics building inclusive financial technology.

US Canada

  • Define security architecture and build controls for AI platforms, training and inference workflows, and agentic systems.
  • Design reusable security patterns for identity, authorization, and runtime controls to constrain execution and data exposure.
  • Lead hands-on security reviews and influence security architecture through practical design changes and reusable controls.

Cerebras Systems builds the world's largest AI chip, 56 times larger than GPUs, delivering industry-leading training and inference speeds. With dozens of model releases and rapid growth, they have a non-corporate work culture that respects individual beliefs.

Global

  • Be the security expert enterprise customers trust, owning calls and deep-dives with sophisticated security teams at Fortune 500 companies.
  • Lead AI security conversations credibly on agent behavior, MCP exposure, and governance frameworks like ISO 42001.
  • Build automation and AI agents that shrink manual security review work, turning reviews into a customer onboarding accelerator.

Atlan builds the context layer for enterprise AI, connecting business context behind data to ensure accuracy and confidence for AI agents. Backed by top investors and trusted by Fortune 500 companies like General Motors and Nasdaq, Atlan fosters an AI-native, high-trust, remote-first culture.

Ireland

  • Design and implement security controls across CI/CD pipelines, cloud infrastructure, and software development workflows.
  • Integrate security testing tools including SAST, DAST, dependency scanning, and vulnerability management.
  • Partner with Engineering, Infrastructure, and Security teams to implement secure development practices.

Kaseya is the leading provider of AI-powered IT management and cybersecurity software, serving Managed Service Providers (MSPs) and internal IT organizations worldwide. Backed by Insight Partners, the company supports customers in more than 20 countries, manages over 15 million endpoints, and fosters a culture of innovation, accountability, and results.

US

  • Manage security compliance programs against frameworks like PCI-DSS, NIST, and SOC 1/2, leveraging automation tools for continuous assessment.
  • Oversee identity and access management, including automated provisioning audits and anomaly detection.
  • Collaborate with engineering, DevOps, and product teams to integrate compliance into CI/CD and cloud infrastructure.

Prosper is a FinTech company focused on improving financial well-being. It is a growing company with a collaborative culture and offers resources for professional growth and holistic well-being.

Spain

  • Play a key role in protecting and strengthening large-scale cloud-native applications that power next-generation AI infrastructure.
  • Work at the intersection of software engineering and cybersecurity, ensuring security is embedded throughout the software development lifecycle.
  • Collaborate cross-functionally to identify and remediate vulnerabilities in complex distributed systems.

Our partner is a company building large-scale cloud-native applications that power next-generation AI infrastructure. They have a high-impact security engineering environment with a collaborative and innovative culture focused on trust, learning, and impact.

India

  • Remediate platform-level security vulnerabilities using tools like Snyk and SAST/DAST.
  • Manage identity and access management and support security audits.
  • Implement security controls in CI/CD pipelines and manage Adobe Cloud Manager.

Solvative is a technology company that provides digital solutions and software development services. They have a small to medium-sized team with an informal, fun work culture that includes regular team activities and investment in employee growth.

US

  • Design and implement comprehensive security architectures for network, application, data protection, and identity management.
  • Identify and assess security risks, developing mitigation strategies to reduce organizational risk.
  • Leverage automation across the technology stack to ensure best practices in Identity and Access Management.

HealthEdge provides software solutions for the healthcare industry. The company fosters a positive, fun, and collaborative work environment with an emphasis on mentoring and building influence.

Europe

  • Champion and implement security best practices and automated tooling across Spotify's infrastructure and platforms.
  • Partner closely with teams to integrate security throughout the software development lifecycle from design to deployment.
  • Conduct threat modeling, security reviews, and risk assessments for both AI and non-AI systems.

Spotify is the world's most popular audio streaming subscription service, unlocking the potential of human creativity by giving artists the opportunity to live off their art. With over 700 million users, the company values curiosity, collaboration, and a willingness to both teach and learn from others.

Canada Unlimited PTO

  • Partner with engineering teams to design, build, and operate secure-by-default cloud infrastructure across AWS and Google Cloud.
  • Build reusable Terraform modules and policy-as-code guardrails to make secure implementation easier for engineering teams.
  • Operate CSPM/CNAPP tooling and drive remediation of cloud vulnerabilities and misconfigurations.

Fullscript is a health technology company that provides a platform for practitioners to access clinical insights, lab interpretations, and high-quality supplements, serving over 125,000 practitioners and 10 million patients. The company has a remote-first culture, emphasizes work-life balance, and values inclusivity and continuous learning.

US

  • Design and implement secure, scalable Azure cloud architectures including landing zones, hybrid environments, and migration from legacy systems.
  • Embed Zero Trust and security-by-design principles using Azure-native tools like Defender for Cloud, Sentinel, and Entra ID.
  • Act as Agile Product Owner for Azure infrastructure and security services, managing backlogs and roadmaps while ensuring compliance with regulatory frameworks.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. They use a technology-driven process to review applications and share top-fitting candidates directly with employers.

US Unlimited PTO

  • Lead the technical work to achieve and maintain compliance certifications (SOC 2, ISO 27001, and the upcoming FedRAMP process)
  • Design and implement security controls across AWS infrastructure, CI/CD pipelines, Kubernetes, and application deployments
  • Build the automation, logging, and evidence collection required for continuous compliance

Zafran's mission is to stop the exploitation of vulnerabilities everywhere, using an Exposure Graph that maps and neutralizes real attack paths. Backed by Menlo Ventures, Sequoia Capital, and Cyberstarts, they are one of the fastest-growing companies in cybersecurity, with a culture of meaningful work and challenging teammates.

Canada

  • Embed secure-by-design principles across cloud, SaaS, and AI-driven systems.
  • Lead threat modeling sessions and security design reviews for applications, APIs, and microservices.
  • Define security standards, mentor engineers, and drive organization-wide risk reduction programs.

Jobgether uses an AI-powered matching process to connect candidates with hiring companies quickly and objectively. They are a remote-first, globally distributed company with an inclusive engineering culture.

US Unlimited PTO 14w maternity 14w paternity

  • Own the end-to-end software delivery lifecycle, designing and operating the DevSecOps pipeline from code intake to secure production deployment.
  • Define and scale hosting architecture in DoD IL-5/IL-6 environments, integrating security and compliance directly into the delivery process.
  • Lead transition from existing government-furnished environments to a scalable, long-term production system with zero-downtime deployments.

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies in healthcare, cyber, and national security. DEFCON AI, a portfolio company, leverages AI and optimization for resilient complex systems; the overall firm culture is mission-driven and fast-paced.

US

  • Lead and mentor a high-performing team of security engineers, setting technical direction and standards for excellence.
  • Define and execute the security roadmap for infrastructure, remote access, endpoints, and M&A.
  • Design and implement security controls across cloud, production, and corporate environments.

Anduril Industries is a defense technology company transforming U.S. and allied military capabilities with advanced technology, powered by Lattice OS. They bring the expertise and business model of innovative companies to the defense industry, focusing on autonomy, AI, and networking.