Lead Security Compliance Engineer
Core
Lead Security Trust & Compliance Engineer owning internal/external audits, security policies, standards, and continuous control monitoring for a B2C CRM platform.
Role type
Senior IC security compliance engineer (GRC & automation)
Builds
Automated control testing pipelines, evidence collection systems, and self-service security workflows
Domain
Cybersecurity, GRC, SaaS compliance, AI governance
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Security and privacy frameworks (NIST, ISO, SOC, PCI, GDPR), end-to-end audit management, policy and standards authoring, control design and assessment, security automation engineering, SaaS architecture knowledge, program management with KPIs/SLAs, technical mentoring
Preferred skills
GRC platform experience (Drata, Vanta), SQL, REST APIs, Python, Infrastructure-as-code (Terraform), Policy-as-code (OPA/Rego), Agentic AI tooling, Identity Governance tools
Technologies
AWS, Kubernetes, Terraform, OPA/Rego, MCP, SQL, Python, REST APIs
Responsibilities
Own internal and external audits from scoping to findings resolution; define strategy and implement new certifications/regulations; author and maintain security policy hierarchies; design and monitor net-new security controls; build automated pipelines for control health metrics; automate security workflows and evidence collection; identify risks and propose mitigation plans; mentor practitioners and drive technical direction without formal authority
Seniority
Senior, hands-on IC with tactical leadership