Remote job
Security Engineer
Job details
About this role
Role overview Establish the security and compliance foundations for a platform that handles sensitive digital evidence. You’ll own security architecture and lead readiness for SOC 2 Type II, while developing controls aligned with CJIS requirements to support trust before and after launch.
Responsibilities - Design and implement security controls and infrastructure. - Assess systems through security reviews, vulnerability testing, and penetration testing. - Lead SOC 2 Type II readiness and the path toward certification. - Create security policies and manage monitoring, logging, and incident response. - Review code, cloud infrastructure, and third-party integrations for security risks. - Work with engineering teams on secure development practices and investigate incidents. - Address applicable CJIS, HIPAA, and other regulatory requirements.
Requirements - At least five years of information security or cybersecurity experience. - Strong knowledge of security frameworks such as NIST, ISO 27001, and SOC 2. - Cloud security experience with AWS, GCP, Azure, or comparable platforms. - Familiarity with SIEM, IDS/IPS, vulnerability scanners, and security monitoring. - Understanding of network security, encryption, authentication, and audit processes. - Relevant degree or equivalent background, strong analytical and communication skills, and a security certification such as CISSP, CISM, or CEH.
Nice to have - CJIS, law enforcement, legal technology, or evidence-handling security experience. - Experience leading SOC 2 readiness or audits, or knowledge of chain of custody and audit logging. - Familiarity with secure development lifecycles, zero-trust design, container security, or Kubernetes. - An active security clearance or ability to obtain one.