Security Engineering Lead
Core
Own the governance, risk, and compliance function for a Customer Intelligence Platform, ensuring SOC 2, ISO/IEC 27001, and ISO/IEC 42001 certifications while building automation tooling and defining AI governance standards.
Role type
Security Engineering Lead (GRC & Compliance)
Builds
Automated compliance tooling, security posture monitoring, and AI governance frameworks
Domain
SaaS / Customer Intelligence / AI Security
Deliverable
production ML models | infrastructure | dashboards & analysis
Required skills
GRC program ownership, SOC 2 and ISO/IEC 27001 certification management, AWS security tooling (GuardDuty, Security Hub, Inspector, Detective), Infrastructure as Code (Pulumi, Terraform), Cloud security posture management, Vendor risk management, AI governance frameworks (ISO/IEC 42001, NIST AI RMF)
Preferred skills
TypeScript, EKS, Detection and response tooling, Enterprise security questionnaire handling
Technologies
AWS, GuardDuty, Security Hub, Inspector, Detective, EKS, Pulumi, Terraform, TypeScript
Responsibilities
Maintain risk registers and drive mitigations for new products; Run SOC 2, ISO/IEC 27001, and ISO/IEC 42001 certification cycles end-to-end; Handle security questionnaires and due diligence for enterprise customers; Build tooling to automate evidence collection and control drift monitoring; Define standards for assessing and controlling AI systems and agentic workflows; Contribute to security incident response processes; Mentor engineers on security decision-making
Seniority
Senior, hands-on IC