Be a technical contributor on our assurance team covering a range of areas, including certifications, application, build, cloud, and supply chain security, and internal security tooling development
Develop, implement, and maintain highly automated security assurance programs to ensure compliance with organizational and regulatory requirements (e.g., ISO 27001, SOC 2, GDPR, NIST, PCI-DSS, TISAX)
Develop systems, automations, and methods of security observability to push the GRC engineering organization beyond just meeting certification requirements
Deploy security and compliance checks in an employee-enabling way in their daily workflows and build pipelines
Collaborate with cross-functional teams to integrate security controls into the software development lifecycle and operational processes
Respond to customer security issues, security alerts, and potential incidents
Requirements
Solid experience with at least one programming language (e.g., Go, TypeScript, Python)
Knowledge of using and securing containerized, cloud-native applications, ideally with Kubernetes
Experience in automating security compliance processes using tools, scripts, and frameworks
Strong interpersonal skills; experience collaborating with peers, stakeholders, auditors, and customers
Some understanding of industry-recognized security frameworks, standards, and certifications (e.g., ISO 27001, SOC 2, PCI DSS, NIST, GDPR)
A degree in Computer Science, Information Security, or related field (or equivalent experience)
Benefits
100% Remote, Global Culture
Scaling Organization
Transparent Communication
Innovation-Driven
Open Source Roots
Empowered Teams
Career Growth Pathways
Approachable Leadership
Passionate People
In-Person onboarding
Balance is Key - 30 days annual leave including shutdown days
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
GoTypeScriptPythonKubernetesautomationsecurity compliancesecurity observabilitysecurity tooling developmentbuild pipelinessoftware development lifecycle