STN Inc Logo

STN Inc

Security and Compliance Engineer

Posted 4 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Owns security operations and compliance for a multi-tenant GPUaaS platform. Maintains SOC 2 and SOC 3 programs, coordinates audits and penetration tests, manages IAM and security tooling, leads vulnerability management and incident response, supports customer security reviews and contracts, maintains policies, and drives security awareness and phishing programs.
The summary above was generated by AI
Security and Compliance Engineer

Platform and software · shared across customers

Reports to: CISO (or VP, Security)

Location: Remote (US) or Pleasanton, CA (hybrid)

Department: Compliance & Security / Compliance

Position summary

The Security and Compliance Engineer owns security operations and compliance posture for the GPU One (GPUaaS) platform. The role maintains SOC 2 and SOC 3 programs, supports customer security requirements during sales and operations, and leads security incident response.

Key responsibilities
  • Maintain SOC 2 Type 2 and SOC 3 compliance programs including control evidence and audit support

  • Manage customer security questionnaires, audits, and penetration test coordination

  • Operate identity and access management (IAM) for both platform and customer environments

  • Drive vulnerability management across infrastructure, platform, and corporate IT

  • Investigate security incidents and lead incident response (IR)

  • Maintain security policies, standards, and operating procedures

  • Support customer security reviews and security-related contract negotiations

  • Coordinate with TAM on customer-specific security requirements

  • Manage security tooling (SIEM, EDR, vulnerability scanners, IAM/SSO)

  • Drive security awareness training and phishing programs across STN

Required qualifications
  • 5+ years in information security, GRC, or security engineering

  • Demonstrated SOC 2, ISO 27001, FedRAMP, or comparable compliance experience

  • Strong knowledge of cloud security, network security, IAM, and identity federation

  • CISSP, CISM, CCSP, or equivalent certification

  • Excellent written communication including audit narratives and policy authorship

Preferred qualifications
  • Multi-tenant or service provider security background

  • HIPAA, PCI-DSS, CMMC, or government compliance experience

  • Hands-on technical security skills (cloud configuration audit, IR forensics)

  • Experience supporting AI/ML or data-sensitive customer workloads

Similar Jobs

3 Days Ago
Easy Apply
Remote
United States
Easy Apply
139K-196K Annually
Senior level
139K-196K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead public sector security compliance initiatives, including FedRAMP continuous monitoring, audits, certifications, GRC strategy, compliance automation, documentation, customer support, and regulatory analysis. Collaborate with IT, Product, Engineering, Security, Legal, auditors, and government customers to strengthen compliance across GitLab’s SaaS and self-managed offerings.
Top Skills: AWSCisaCismCisspCloud ComputingCmmcCompliance-As-CodeFedrampGCPGovernance Risk And Compliance (Grc)IrapIso 27001Policy-As-CodeScriptingSoc 2
18 Days Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Design and build automated compliance engineering systems: continuous evidence collection and control monitoring, integrate cloud and identity tooling, apply LLMs/agents for validation, lead auditor engagements for certifications (ISO, SOC2, CSA STAR), drive remediation with stakeholders, and author compliance documentation and strategy.
Top Skills: AgentsAWSAzureGCPLlms
21 Days Ago
Remote
USA
125K-170K Annually
Senior level
125K-170K Annually
Senior level
Other
Lead application and operational implementation of GRC/compliance frameworks (SOC 1/2, ISO 27001, CSA STAR, NIST CSF). Develop policies, run internal audits, support risk management and remediation, coordinate with SecOps to ensure controls meet audit standards, and support access reviews and annual audits.
Top Skills: Amazon Web ServicesAnti-VirusAuthentication SystemsCsa StarFirewallsIntrusion Detection SystemsIso 27001Log ManagementMicrosoft 365AzureNist CsfService Oriented ArchitecturesSharepoint OnlineSoc 1Soc 2Web ApplicationsWeb Services

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account