Remote job
Security Operations Engineer
Job details
About this role
Role overview
The role centers on day-to-day ownership of the operational backbone of a mature security and compliance program that protects a Voice AI platform processing large volumes of audio and API traffic. It blends security operations with governance, risk, and compliance (GRC) work, including running audits, managing vendor risk, triaging vulnerabilities, and responding to customer security inquiries. The position suits someone who wants high ownership on a small, high-impact team and is comfortable partnering across engineering, sales, and legal.
Responsibilities
- Lead end-to-end audit cycles for frameworks such as SOC 2, ISO 27001, and PCI 4.0, including evidence collection, control design, auditor coordination, and remediation tracking. - Operate and maintain the compliance automation platform (Vanta), monitor control health, resolve failing checks, and keep the risk register current as the business evolves. - Run vendor and third-party risk reviews, security assessments of new tools, periodic re-reviews, and track subprocessor and vendor inventories. - Partner with sales and legal to respond to customer and vendor security questionnaires, RFP security sections, and trust-and-safety inquiries. - Drive vulnerability triage and prioritization across teams, track remediation against SLAs, and report progress metrics to stakeholders. - Investigate alerts from endpoint, cloud, identity, and application security tools, support incident response activities, and follow through on post-incident action items. - Build scripts, integrations, and automations that reduce manual toil across evidence gathering, reporting, and routine controls.
Requirements
- Hands-on experience in security operations, GRC, or a closely related role at a technology company. - Demonstrated ownership of SOC 2 and/or ISO 27001 audit cycles, including evidence gathering and direct auditor coordination. - Familiarity with PCI 4.0 controls, or the ability to ramp quickly on payment-card requirements. - Working knowledge of cloud infrastructure (AWS preferred), identity and access management, and SaaS administration. - Experience responding to customer security questionnaires and translating technical controls into clear business-friendly answers. - Comfort writing scripts in a general-purpose language to automate repetitive security or compliance work.
Nice to have
- Application security fundamentals such as threat modeling, secure code review, or familiarity with OWASP Top 10 and CWE classes. - Experience with SAST, SCA, DAST, secret scanning, or infrastructure-as-code scanning tools. - Terraform and CI/CD pipeline security exposure. - SIEM detection engineering and alerting pipeline work. - Endpoint security platforms or cloud security posture management tooling. - Background securing AI/ML systems or inference infrastructure. - Prior security role at a high-growth startup.
Benefits and work setup
- Base salary range of $180,000 to $220,000 USD for US-based candidates. - Competitive equity grants and 100% employer-paid benefits. - Fully remote work setup. - 401(k) plan with up to 4% employer match for US-based full-time team members.