STN Inc Logo

STN Inc

Security and Compliance Engineer

Posted 7 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Owns security operations and compliance for a multi-tenant GPUaaS platform. Maintains SOC 2 and SOC 3 programs, coordinates audits and penetration tests, manages IAM and security tooling, leads vulnerability management and incident response, supports customer security reviews and contracts, maintains policies, and drives security awareness and phishing programs.
The summary above was generated by AI
Security and Compliance Engineer

Platform and software · shared across customers

Reports to: CISO (or VP, Security)

Location: Remote (US) or Pleasanton, CA (hybrid)

Department: Compliance & Security / Compliance

Position summary

The Security and Compliance Engineer owns security operations and compliance posture for the GPU One (GPUaaS) platform. The role maintains SOC 2 and SOC 3 programs, supports customer security requirements during sales and operations, and leads security incident response.

Key responsibilities
  • Maintain SOC 2 Type 2 and SOC 3 compliance programs including control evidence and audit support

  • Manage customer security questionnaires, audits, and penetration test coordination

  • Operate identity and access management (IAM) for both platform and customer environments

  • Drive vulnerability management across infrastructure, platform, and corporate IT

  • Investigate security incidents and lead incident response (IR)

  • Maintain security policies, standards, and operating procedures

  • Support customer security reviews and security-related contract negotiations

  • Coordinate with TAM on customer-specific security requirements

  • Manage security tooling (SIEM, EDR, vulnerability scanners, IAM/SSO)

  • Drive security awareness training and phishing programs across STN

Required qualifications
  • 5+ years in information security, GRC, or security engineering

  • Demonstrated SOC 2, ISO 27001, FedRAMP, or comparable compliance experience

  • Strong knowledge of cloud security, network security, IAM, and identity federation

  • CISSP, CISM, CCSP, or equivalent certification

  • Excellent written communication including audit narratives and policy authorship

Preferred qualifications
  • Multi-tenant or service provider security background

  • HIPAA, PCI-DSS, CMMC, or government compliance experience

  • Hands-on technical security skills (cloud configuration audit, IR forensics)

  • Experience supporting AI/ML or data-sensitive customer workloads

Similar Jobs

6 Days Ago
Easy Apply
Remote
United States
Easy Apply
139K-196K Annually
Senior level
139K-196K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead public sector security compliance initiatives, including FedRAMP continuous monitoring, audits, certifications, GRC strategy, compliance automation, documentation, customer support, and regulatory analysis. Collaborate with IT, Product, Engineering, Security, Legal, auditors, and government customers to strengthen compliance across GitLab’s SaaS and self-managed offerings.
Top Skills: AWSCisaCismCisspCloud ComputingCmmcCompliance-As-CodeFedrampGCPGovernance Risk And Compliance (Grc)IrapIso 27001Policy-As-CodeScriptingSoc 2
Yesterday
Remote
United States
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Cybersecurity
Supports AWS GovCloud IL5 cybersecurity compliance and security operations. Performs RMF impact analysis, maintains SSPs, POA&Ms, SARs, and control evidence, validates STIGs and cloud configurations, monitors vulnerabilities and logs, supports IL5 migrations, audits, ATO activities, and continuity planning, and documents remediation and compliance findings.
Top Skills: Aws GovcloudCloud Logging And MonitoringContainer SecurityEncryptionIamInfrastructure As CodeRmfSIEMSoarStigVulnerability ScanningZero Trust
21 Days Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Design and build automated compliance engineering systems: continuous evidence collection and control monitoring, integrate cloud and identity tooling, apply LLMs/agents for validation, lead auditor engagements for certifications (ISO, SOC2, CSA STAR), drive remediation with stakeholders, and author compliance documentation and strategy.
Top Skills: AgentsAWSAzureGCPLlms

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account