Security Compliance Engineer

| Remote
Sorry, this job was removed at 7:59 a.m. (EST) on Friday, June 10, 2022
Find out who’s hiring remotely
See all Remote jobs
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Renting a home is the world's oldest subscription service. People spend thousands of dollars every month for an experience that is outdated, inconvenient, analog, impersonal, and leaves a lot to be desired. Latch is working to make every building better, and while we've methodically executed this mission since our founding with great success, we're just getting started.

Leveraging our knowledge from companies like Apple, BCG, and IDEO, we’ve rethought how people interact with space. Latch delivers a full-building operating system designed to help owners, residents, and third parties like guests, couriers, and service providers, seamlessly experience the modern building. We’ve done this by combining software, devices, and services into a holistic platform that makes spaces more efficient, enjoyable, and profitable.

The next chapter of the Latch story will be our most exciting yet, and we’re looking for more talented team members to help fuel our growth.

Our team is in search of a Security Compliance Engineer to help us change the way digital products are secured.

About the Team:

Our experienced security team manages all areas of product security, platform security, compliance, audit, and risk. We build and protect the systems that enable companies to create designs that make everything possible. You will be part of a unique team that develops and manages compliance with audit requirements and other frameworks, creates and enhances audit automation as well as the identification of risk that doesn't inhibit speed and innovation for product development. This position will report to the Director of Security Compliance.

What you'll do:

  • Help us be compliant. Develop roadmap initiatives based on business needs by performing control analysis and compliance mapping (e.g.: GDPR, SOC 2, ISO 27001, etc.) and then drive results through gap assessments, control implementation, and third party audits.
  • Create consistency. Utilize existing GRC tools and attend training to find the best, most effective and efficient approach to upload controls, evidence, and manage control effectiveness audits as part of the continuous compliance lifecycle.
  • Delight in the details. Respond to questionnaires, emails, conduct research, lead calls, and communicate with internal/external stakeholders using explicit technical details and professionalism.
  • Understand risky business. Take traditional risk management concepts and apply them to out of the box situations and complex technologies that drive acceptable business resolutions as a co-owner.
  • Build knowledge, not perfection. Ability to create diagrams or necessary customer artifacts including policies, standards and procedures, and surface work to build on areas that need improvement. 
  • Be comfortable with the uncomfortable. Must be highly driven towards performance based outcomes and navigating unknown gray areas. Maintain a growth mindset at all times and dig in whenever necessary without being asked.
  • Work harder, not longer. Establish process improvements utilizing automation for audit testing, task creation, evidence validation and establishing in-scope system documentation.
  • Empower others. Share information, build relationships, and collaborate across all aspects of security, sales, legal, finance and engineering with candor and compassion.

What you'll bring:

  • 5+ years' experience in Information Security
  • 3+ years' experience in areas of compliance, audit, and risk; preferably at a SaaS startup or technology company
  • 2+ years' experience with audit testing, control validation and automation utilizing AWS (AWS audit certifications preferred)
  • 2+ years’ experience with continuous monitoring GRC tools, such as Tugboat Logic or Reciprocity’s ZenGRC.
  • 2+ years’ experience with Atlassian products such as Jira and Confluence as well as code repositories like Github.
  • Polished professionalism developed through consulting or engaging directly with customers, auditors, and third-parties
  • Self-directed and motivated to foster creative problem solving as well as out of the box thinking
  • Working understanding of how compliance operates with cloud-native technology stacks in balance with business needs
  • Broad exposure to complex and cutting edge technologies such as containerization, real-time threat detection, secrets management, continuous deployment, code repository change controls and AWS/DevSecOps tools


Founded in 2014, Latch now has 400+ team members working to make spaces better places to live, work, and visit. 

We offer unlimited Paid Time Off, a comprehensive benefits package, mental health support, and an environment where employees are surrounded by creative, empowered, and dynamic peers.

In conjunction with our ​core values​: Contagious Determination, Humility, Trust, Inclusion, Action with Intent, and Privacy, we approach our work with care and a sense of duty, to make the world a better space.

We embrace diversity and strive to create an inclusive and equitable environment for all.

Latch has over 100 employees and is subject to OSHA guidelines that require all employees be vaccinated against COVID-19.

Applicant Privacy Notice

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Location

NY

Similar Jobs

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about LatchFind similar jobs