Lead Security Engineering & Compliance
You will join as the first security member and lead the development and operation of the security framework across the organization. You will manage security governance and compliance, design and operate AWS cloud security controls, improve security operations through automation and AI, and lead security communications with global B2B customers. You will define and solve security problems independently while expanding your expertise across global security functions.
Responsibilities
- Operate and improve security and privacy frameworks including SOC 2, ISO 27001, and GDPR.
- Conduct security risk assessments and support audit responses.
- Establish security policies, standards, and technical security baselines.
- Manage security controls and related evidence.
- Design and operate cloud security architecture and controls in AWS.
- Improve security across IAM, network security, WAF, encryption, logging, and monitoring.
- Manage cloud security risks and vulnerabilities.
- Operate security solutions such as EDR and detect, analyze, and respond to security events.
- Design and implement automation for repetitive security operations tasks.
- Use AI and security agents in practical security operations.
- Analyze global B2B customer security requirements and lead communications.
- Respond to customer security questionnaires.
Requirements
- At least 5 years of experience in information security or cybersecurity.
- Hands-on experience with AWS cloud security.
- Experience operating SOC 2, ISO 27001, or similar security compliance programs.
- Experience with GDPR or privacy-related work.
- Understanding of IAM, network security, WAF, encryption, logging, EDR, and other key security technologies.
- Ability to collaborate with engineering teams to solve security problems technically.
- Ability to communicate and collaborate in English.
- Experience working in a rapidly changing startup environment is preferred.
- Experience in information security at a SaaS or B2B company is preferred.
- Experience operating SIEM or EDR security tools is preferred.
- Experience with security automation or using AI, LLMs, or agents in security operations is preferred.
Benefits
- Flexible working hours with an 8–10 AM start window.
- Remote work two days per week.
- US stock-based NSO options upon joining.
- Regular health checkups.
- English conversation education at the office.
- Lunch allowance when working from the office.
- Dinner allowance and taxi fare for late-night work.
- Team meal allowances for team building.
- Snacks, beverages, coffee, and beer.