
Staff Security Engineer
What you'll do:\nMaintain and mature the ISMS, including SoA and MRM process.\nSupport ISO 27001 and SOC 2 Type 2 audits, including scoping, evidence collection, and auditor interviews.\nContribute to SOC 2 System Description and other audit narratives.\nTrack gaps and remediation from readiness assessments and audits.\nLead the policy program: create, revise, and review policies across functions.\nSupport scaling of compliance as products/business units grow.\nAssist internal audit; partner with engineering, legal, privacy, people, and product leadership.\nAdvise GRC manager and Security leadership on audit risk and strategy.\nWhat you'll bring: 5 years in information security/GRC/compliance; deep ISO 27001 and SOC 2 familiarity; experience with ISMS components; strong policy and cross-functional collaboration; independent work capability; certifications (CISA/CISSP) are a plus.\nCommitment to our values: Welcoming differences, Relationship-minded, Responsible participation, Grit.\nWhat you'll get: Bonuses, comprehensive health coverage, generous retirement contributions, wellness days, home office stipend, development budget, parental leave, referral bonuses, and more.
Job Details
Responsibilities
- Maintain and mature the ISMS including SoA and MRM process
- Support ISO 27001 and SOC 2 Type 2 audits
- Contribute to SOC 2 System Description and audit narratives
- Track gaps and remediation
- Lead the policy program
- Support scaling of compliance as products/business units grow
- Support internal audit
- Collaborate with Engineering, IT, Legal, Privacy, People, and product leadership
- Advise GRC manager and Security leadership on audit risk and strategy
Requirements
- 5 years of information security, GRC, or compliance-focused roles
Skills & Technologies
Education Level
No degree required
Related Opportunities
Discover more opportunities that match your interests and skills