Source Job

US

  • Support security and compliance initiatives across cloud-based environments.
  • Conduct web application penetration testing and vulnerability assessments.
  • Implement and maintain security controls aligned with compliance frameworks.

Security Engineering Penetration Testing Cloud Security Compliance AWS

20 jobs similar to Security & Compliance Engineer

Jobs ranked by similarity.

$174,000–$238,000/yr
US

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
  • Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.

Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.

$80,000–$130,000/yr
US

  • You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
  • You will run the vulnerability management program and remediate security findings across AWS.
  • You will support security incident response, fraud investigations, and third-party risk assessments.

We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.

United States

  • Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
  • Strengthen security monitoring, detection, incident response, and integrate security into CI/CD pipelines.
  • Support compliance efforts including SOC 2 and ISO audits, and lead customer security reviews.

AlertMedia helps organizations protect their people, operations, and brand with a modern Risk Intelligence and Response platform. It is a high-growth, PE-backed SaaS company with more than 4,000 clients and a 10-year award-winning culture.

US

  • Lead the development and implementation of security strategies, policies, and procedures.
  • Architect secure systems and collaborate with engineering teams to integrate security throughout the software development lifecycle.
  • Conduct risk assessments, incident response, and mentor junior engineers to promote security awareness.

Gemini is a global crypto and Web3 platform founded in 2014, offering secure crypto products and services to individuals and institutions in over 70 countries. The company is publicly traded with a mission to bridge traditional finance with the emerging cryptoeconomy, fostering a diverse team that prioritizes trust and security.

$166,600–$208,300/yr
North America

  • Design and implement cloud security posture and automation to protect customer trust.
  • Enable cyber resilience and lead zero trust initiatives across the infrastructure.
  • Collaborate with engineering teams to enhance reliability and security of cloud systems.

Mercury is a fintech company providing banking and financial services for startups, focusing on simplicity and security. With a team of around 500 employees, the culture is collaborative, innovative, and values diversity.

US

  • Own IRAP and ISMAP program strategy and execution across Australia and Japan.
  • Coordinate with regional assessors and government agencies to maintain compliance.
  • Design and maintain compliance documentation and manage continuous monitoring.

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.

US

  • Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
  • Oversee preparation and execution of external compliance audits, including facilitating security assessments.
  • Support mapping of compliance requirements to security control implementation using agile development processes.

Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.

US

  • Lead vulnerability management and SOC 2 compliance across SaaS products and cloud infrastructure.
  • Harden Azure and Microsoft security tooling (Defender, Intune) and respond to security alerts.
  • Partner with engineering, IT, and legal to drive secure SDLC, policies, and customer security reviews.

HSP Group is a premier provider of global expansion services, helping companies with legal setup, HR, payroll, compliance, and tax across international markets. The company partners with scale-ups and innovative technology firms to reduce risk and scale faster, fostering a trusted-partner culture.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

US Canada Unlimited PTO

  • Collaborate with sales representatives to identify and secure prospects.
  • Provide security & compliance subject matter expert services on sales calls.
  • Address technical compliance inquiries from sales prospects and screen them for product fit.

Secureframe is a cybersecurity compliance company that provides trusted solutions to help businesses achieve and maintain compliance standards. Backed by top VCs, the company is growing rapidly and values professional excellence, continuous learning, and a collaborative environment.

$180,000–$260,000/yr
US Unlimited PTO

  • Own the security boundary of Percy, including vault enclave and sandbox isolation for AI agents processing live PII.
  • Assess and harden encryption, key management, access control, and the append-only audit ledger across AWS Nitro Enclaves.
  • Drive product-security controls for SOC 2, PCI DSS, and GDPR audits, and run technical pentests.

Footprint builds Percy, an AI agent that automates financial crime investigations for banks and fintechs. Backed by QED, Index, and Box Group, the company is small, senior, and ships fast, having 5x'd revenue last year.

$145,000–$160,000/yr
US

  • Design, implement, and maintain enterprise security solutions to strengthen cybersecurity posture and advance Zero Trust maturity.
  • Operate security tools like EDR, SIEM, and vulnerability scanners, integrating security into CI/CD pipelines.
  • Build dashboards to measure security performance and Zero Trust maturity metrics.

Valiant Solutions is a security-focused IT solutions provider serving public clients nationwide. Named one of the fastest-growing privately held companies, they pride themselves on an employee-centric culture and great benefits.

US Unlimited PTO

  • Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
  • Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
  • Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.

Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.

US

  • Serve as primary point of contact for users of application security and cloud security tools, helping teams understand and remediate findings.
  • Manage security requests through ServiceNow, analyze findings, and provide hands-on support and troubleshooting.
  • Collaborate with teams to improve customer experience, develop knowledge base articles, and identify automation opportunities.

Marlabs is a global AI and Digital Solutions Consulting firm delivering intelligent solutions across AI, data, analytics, and product engineering. Since 2000, the company has partnered with large healthcare, life sciences, financial services, and government organizations, fostering an innovative and dynamic team culture.

$129,813–$172,500/yr
US 3w PTO 3w maternity 3w paternity

  • Lead and maintain ATO documentation and coordinate with security, engineering, and project teams to ensure compliance.
  • Monitor security events, investigate threats, and assess vulnerabilities across cloud and enterprise environments.
  • Develop and implement security policies, conduct risk analysis, and provide cybersecurity guidance to stakeholders.

The company is a partner organization focused on cybersecurity and federal technology modernization. It offers a fully remote, mission-driven culture with opportunities for growth in a technology-focused environment.

$141,000–$221,000/yr
US Unlimited PTO

  • Review system designs and implementations to identify security issues and align with best practices.
  • Develop cloud security architecture and implement automated security testing tools.
  • Promote DevSecOps principles through CI pipeline integration and Infrastructure as Code scanning.

Iterable is the leading AI-powered customer engagement platform that helps brands like Redfin and SeatGeek create dynamic experiences. With nearly 1,200 clients globally and a diverse workforce, we foster a culture of innovation and inclusion, recognized as one of Inc's Best Workplaces.

$150,000–$180,000/yr
US

  • Serve as acting CISO for multiple client organizations and SGP, providing strategic security leadership and executive guidance.
  • Lead cybersecurity and compliance programs aligned with NIST SP 800-171, CMMC Levels 1-2, and ISO/IEC 27001.
  • Conduct security assessments, gap analyses, and risk reviews; develop SSPs, POA&Ms, and policies.

Strategic Growth Partners provides cybersecurity and compliance services to clients across multiple time zones. They foster a collaborative, innovative, and diverse work environment.

$139,000–$218,000/yr
US

  • Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
  • Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
  • Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.

Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.