Security & Compliance Engineer

Aurelian

$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years in security engineering and governance, risk, and compliance (GRC) roles.
  • Experience with SOC 2 and CJIS Security Policy.
  • Hands-on skills in cloud environments, especially Azure.
  • Strong ability to communicate technical concepts to non-technical stakeholders.
  • Self-driven, with a focus on building lasting systems rather than processes.
  • Must pass a state and national fingerprint-based background check.

Responsibilities

  • Own and manage the company's security posture regarding sensitive data.
  • Lead and maintain SOC 2 compliance and CJIS Security Policy adherence.
  • Streamline security reviews to reduce delays in the sales process.
  • Engage in hands-on engineering to enhance cloud infrastructure security.
  • Automate compliance processes to minimize manual intervention.
  • Implement and oversee personnel security processes as per CJIS requirements.

Benefits

  • Comprehensive Medical, Dental, Vision & Life insurance
  • 401(k) plan
  • Unlimited Paid Time Off (PTO)
  • Company-wide offsite events
  • Equipment stipend for home office setup
  • Relocation assistance available
  • Daily delivered lunches for staff
  • Located in Seattle with a dynamic work environment
  • Equity participation in the start-up
Full Job Description
What You'll Be Doing
  • Own our security posture end-to-end: Be the single source of truth for how Aurelian handles sensitive data. Keep our security claims accurate, consistent, and defensible across every document, questionnaire, and contract.
  • Run the compliance program: Own SOC 2 and our alignment to the CJIS Security Policy (and FedRAMP/GovCloud as our gov pipeline grows). Own the artifacts that don't fully exist yet - subprocessor lists, data management and retention policies, incident response plans - and keep them current.
  • Turn security reviews from a bottleneck into a process: Own the customer security-questionnaire pipeline so deals don't wait on engineering. Work directly with our implementation and sales teams to get agencies the answers they need, quickly and accurately.
  • Do the engineering, not just the paperwork: Harden our cloud infrastructure (Azure), tighten IAM and tenant isolation, improve logging/audit and detection, and shore up our secure development practices.
  • Automate the compliance grind: Wire up and operate compliance-automation tooling so evidence collection, continuous controls monitoring, and questionnaire responses run as close to hands-off as possible. Treat compliance as code.
  • Operationalize personnel security: Run the processes CJIS requires across engineering - background checks / fingerprinting, security-awareness training, and access controls for anyone who touches criminal justice information.
Who We're Looking For
  • A builder who can also run the program: You have a real security-engineering foundation and you've owned a compliance program. You're not a spreadsheet-only GRC analyst, and you're not a strategy-only leader who won't get hands-on. ~5-8 years across security engineering and GRC is a good marker, but we care about the blend more than the number.
  • Fluent in the frameworks that matter to us: Direct experience with SOC 2 and hands-on familiarity with the CJIS Security Policy, NIST 800-53/800-171, or FedRAMP. Public-sector, GovCloud, or regulated-SaaS experience is a strong plus.
  • Comfortable in the cloud and in code: You can harden a cloud environment (Azure ideally), reason about IAM, encryption, network isolation, and logging, and automate controls and evidence with scripting and GRC tooling.
  • Credible in the room: You can face an auditor, a state CJIS Systems Officer, or a county CISO team and answer hard questions clearly - and translate the same material for our sales and implementation teams and our engineers.
  • High ownership, low ceremony: You see the gap, define the right thing to build, and drive it to done. You'd rather build a durable system than win an argument, and you're energized by being the person the whole company relies on for this.
  • Eligible for CJIS clearance: Because of the data we handle, this role requires passing a state and national fingerprint-based background check.

To learn more about what it's like to work at Aurelian, visit our About Us page and follow us on LinkedIn to stay up to date!

We encourage you to apply even if you don't meet every qualification listed above. We believe exceptional people come from many different backgrounds, and we'd rather connect with you than miss the opportunity.

Come do the best work of your life and join us in shaping the future of critical technology that truly matters.

For Full-Time roles, Aurelian offers a variety of benefits, including:
  • Comprehensive Medical, Dental, Vision & Life insurance
  • 401(k)
  • Unlimited PTO
  • Company-wide offsites
  • Equipment stipend
  • Relocation assistance
  • Daily delivered lunches (on us)
  • Office in Seattle
  • Start-up Equity

Similar Jobs

More Jobs at Aurelian

More Information Technology Jobs

Find similar Security & Compliance Engineer jobs: