Code and Theory logo
Code and TheoryPosted 1 month ago

Senior Engineer, Security & Compliance (US)

$110,000–$150,000 year

On-siteAustin, Texas, United States

Full TimeSenior LevelMediumDigital Agency

Job Summary

Build and maintain security controls across cloud infrastructure and SaaS products, covering identity, encryption, logging, and multi-tenancy patterns. Own the technical implementation of SOC 2 Type II, ISO 27001, and ISO 42001 compliance by constructing evidence pipelines and automating control testing. Instrument security monitoring and alerting across GCP, AWS, and Azure environments to manage threat detection and log aggregation. Partner with engineering teams to embed security into CI/CD pipelines, integrating vulnerability scanning, SAST/DAST, and dependency management. Implement privacy controls aligned with HIPAA, GDPR, and CCPA/CPRA requirements while executing client engagement security models for access provisioning and environment segregation. Conduct hands-on vendor security assessments and maintain incident response playbooks for forensic analysis. Build AI-specific security controls to mitigate prompt injection and data leakage risks in agent workflows. Contribute to security questionnaires and RFP responses as the technical author for customer assurance requests.

Required Qualifications

  • 5+ years of hands-on security engineering experience
  • Deep practical knowledge of cloud security in at least one major platform (GCP, AWS, or Azure)
  • Hands-on experience with SOC 2 Type II and ISO 27001 control implementation
  • Experience building security automation across CI/CD pipelines
  • Working knowledge of privacy regulations (HIPAA, GDPR, CCPA/CPRA)
  • Proficiency with security monitoring and SIEM tooling
  • Strong communication skills
  • Comfort working across a distributed, fast-moving organization with multiple concurrent workstreams
  • Experience working with AI-enabled development tools and integrating security thinking into AI-assisted workflows
  • Hands-on experience reviewing and hardening AI agent workflows
  • Comfortable leveraging AI-enabled development tools and workflows to accelerate engineering, automation, debugging, and operational tasks
  • Experience orchestrating multi-step AI or agent-driven workflows
  • Strong judgment reviewing and hardening AI-assisted output for security, scalability, maintainability, and architectural fit
  • Experience building or maintaining prompts, evaluation frameworks, documentation, or operational context systems that improve engineering velocity and reliability
  • Familiarity with automated evaluation and feedback loops for AI-enabled systems and workflows

Desired Qualifications

  • Experience in agency, consultancy, or enterprise SaaS environments where you've had to meet varying client security requirements
  • Familiarity with ISO 42001 and AI governance frameworks
  • Experience securing multi-tenant SaaS architectures at the infrastructure and application layer
  • Relevant certifications: CISSP, CCSP, AWS/GCP/Azure Security Specialty, CIPP, or similar
  • Experience with infrastructure-as-code security tooling (e.g., Checkov, tfsec, OPA/Rego)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce