Jobgether
Accountabilities:: Own the engineering side of the SOC 2 Type 2 compliance program, including control implementation, evidence collection, and audit readiness. Operate and improve compliance automation platforms, integrations, evidence pipelines, and control mappings. Productize compliance through policy-as-code, automated evidence generation, and security guardrails embedded into engineering workflows. Own cloud security posture management and runtime security capabilities, including posture monitoring, container scanning, infrastructure-as-code scanning, and runtime coverage. Triage, prioritize, and remediate security findings against defined SLAs while developing automation and alerting to manage security at scale. Build automated remediation workflows, including AI-assisted pipelines that can detect, create, and safely resolve security findings with minimal manual intervention. Design and maintain CI/CD security gates covering SAST, SCA, secret scanning, SBOM generation, dependency management, and container and IaC scanning. Encode security and compliance requirements into infrastructure-as-code and policy-as-code so secure practices become the default path for engineering teams. Help transition prototypes into production-ready systems by introducing secure-by-default architectures and automated controls. Develop reusable infrastructure modules, pipeline components, internal tooling, and AI/agentic capabilities that turn security operations into scalable self-service functionality. Partner with corporate security and GRC teams while strengthening the organization’s internal security engineering capabilities and decision-making processes. Requirements: 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus; Staff-level candidates should have 8+ years and a track record of building security functions or programs. Deep hands-on experience securing cloud environments, including compute, networking, IAM, key management, and logging on a major cloud platform. Strong infrastructure-as-code expertise, particularly with Terraform and policy-as-code. Proven experience implementing CI/CD security controls such as SAST, SCA, secret scanning, dependency scanning, and container security within developer workflows. Hands-on experience managing vulnerabilities at scale, including triage, prioritization, SLA-driven remediation, and automation. Working knowledge of SOC 2 or comparable compliance frameworks, including implementing and evidencing controls within real engineering environments. Familiarity with modern security tooling across CSPM, application security, SAST, secret scanning, compliance automation, and SIEM. Strong coding and scripting skills with the ability to build scalable automation, pipelines, infrastructure modules, and security tooling rather than simply configure existing products. Experience establishing or maturing an in-house security engineering function. Multi-cloud experience and a background securing internal developer platforms. Experience designing security monitoring, detection, alerting, and response capabilities. Experience applying AI and LLM technologies to security operations, including automated remediation, evidence generation, and agentic workflows. Ability to collaborate effectively across engineering, security, compliance, and GRC teams while operating with a high degree of technical ownership. Benefits: Total cash compensation range of $150,000–$225,000 per year, depending on location, experience, and qualifications. Remote or hybrid work options, with a preference for candidates on the East Coast. Hybrid opportunities centered around New York, NY and Charlotte-area offices. Health insurance coverage, including medical, dental, and vision. Life insurance. Short- and long-term disability insurance. Flexible spending accounts. Holiday pay. 401(k) plan with company match. Employee Assistance Program. Paid parental bonding benefit program. Flexible paid time off, with full-time employees accruing 20 days annually and increasing to 25 days after five years of service. The role requires availability during Eastern Standard Time working hours. The position does not offer visa sponsorship or transfer of visa sponsorship and is not available for corp-to-corp arrangements. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1