CareerPlanSign in

Lead Security Compliance Engineer

Boston💼 Full-time🗓 2026-09-22 → 2026-09-26

Core

Lead Security Trust & Compliance Engineer owning internal/external audits, security policies, standards, and continuous control monitoring for a B2C CRM platform.

Role type

Senior IC security compliance engineer (GRC & automation)

Builds

Automated control testing pipelines, evidence collection systems, and self-service security workflows

Domain

Cybersecurity, GRC, SaaS compliance, AI governance

Deliverable

production ML models | product features | dashboards & analysis | client delivery | infrastructure

Required skills

Security and privacy frameworks (NIST, ISO, SOC, PCI, GDPR), end-to-end audit management, policy and standards authoring, control design and assessment, security automation engineering, SaaS architecture knowledge, program management with KPIs/SLAs, technical mentoring

Preferred skills

GRC platform experience (Drata, Vanta), SQL, REST APIs, Python, Infrastructure-as-code (Terraform), Policy-as-code (OPA/Rego), Agentic AI tooling, Identity Governance tools

Technologies

AWS, Kubernetes, Terraform, OPA/Rego, MCP, SQL, Python, REST APIs

Responsibilities

Own internal and external audits from scoping to findings resolution; define strategy and implement new certifications/regulations; author and maintain security policy hierarchies; design and monitor net-new security controls; build automated pipelines for control health metrics; automate security workflows and evidence collection; identify risks and propose mitigation plans; mentor practitioners and drive technical direction without formal authority

Seniority

Senior, hands-on IC with tactical leadership

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.