STN Inc Logo

STN Inc

Security and Compliance Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Owns security operations and compliance for a multi-tenant GPUaaS platform. Maintains SOC 2 and SOC 3 programs, coordinates audits and penetration tests, manages IAM and security tooling, leads vulnerability management and incident response, supports customer security reviews and contracts, maintains policies, and drives security awareness and phishing programs.
The summary above was generated by AI
Security and Compliance Engineer

Platform and software · shared across customers

Reports to: CISO (or VP, Security)

Location: Remote (US) or Pleasanton, CA (hybrid)

Department: Compliance & Security / Compliance

Position summary

The Security and Compliance Engineer owns security operations and compliance posture for the GPU One (GPUaaS) platform. The role maintains SOC 2 and SOC 3 programs, supports customer security requirements during sales and operations, and leads security incident response.

Key responsibilities
  • Maintain SOC 2 Type 2 and SOC 3 compliance programs including control evidence and audit support

  • Manage customer security questionnaires, audits, and penetration test coordination

  • Operate identity and access management (IAM) for both platform and customer environments

  • Drive vulnerability management across infrastructure, platform, and corporate IT

  • Investigate security incidents and lead incident response (IR)

  • Maintain security policies, standards, and operating procedures

  • Support customer security reviews and security-related contract negotiations

  • Coordinate with TAM on customer-specific security requirements

  • Manage security tooling (SIEM, EDR, vulnerability scanners, IAM/SSO)

  • Drive security awareness training and phishing programs across STN

Required qualifications
  • 5+ years in information security, GRC, or security engineering

  • Demonstrated SOC 2, ISO 27001, FedRAMP, or comparable compliance experience

  • Strong knowledge of cloud security, network security, IAM, and identity federation

  • CISSP, CISM, CCSP, or equivalent certification

  • Excellent written communication including audit narratives and policy authorship

Preferred qualifications
  • Multi-tenant or service provider security background

  • HIPAA, PCI-DSS, CMMC, or government compliance experience

  • Hands-on technical security skills (cloud configuration audit, IR forensics)

  • Experience supporting AI/ML or data-sensitive customer workloads

Similar Jobs

15 Days Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Design and build automated compliance engineering systems: continuous evidence collection and control monitoring, integrate cloud and identity tooling, apply LLMs/agents for validation, lead auditor engagements for certifications (ISO, SOC2, CSA STAR), drive remediation with stakeholders, and author compliance documentation and strategy.
Top Skills: AgentsAWSAzureGCPLlms
18 Days Ago
Remote
USA
125K-170K Annually
Senior level
125K-170K Annually
Senior level
Other
Lead application and operational implementation of GRC/compliance frameworks (SOC 1/2, ISO 27001, CSA STAR, NIST CSF). Develop policies, run internal audits, support risk management and remediation, coordinate with SecOps to ensure controls meet audit standards, and support access reviews and annual audits.
Top Skills: Amazon Web ServicesAnti-VirusAuthentication SystemsCsa StarFirewallsIntrusion Detection SystemsIso 27001Log ManagementMicrosoft 365AzureNist CsfService Oriented ArchitecturesSharepoint OnlineSoc 1Soc 2Web ApplicationsWeb Services
18 Days Ago
Remote
United States
Senior level
Senior level
Software
Lead FedRAMP, SOC 2, and ISO 27001 compliance efforts by hardening AWS and Kubernetes infrastructure, implementing security controls, automating evidence collection, improving CI/CD security, and collaborating with security, legal, and engineering teams to support regulated customers.
Top Skills: Admission ControlAws (IamAws GovcloudBashCi/Cd PipelinesConfig)DastGuarddutyImage ScanningKmsKubernetesPolicy-As-CodePythonRuntime SecuritySastScaSecrets ManagementSecurity HubTerraformVpc

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account