Lead Product Security and Compliance Engineer
Big HappyMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Own end-to-end product security including identifying vulnerabilities in code, dependencies, APIs, and cloud infrastructure and collaborating directly with engineering teams for remediation.
Lead and maintain SOC 2 compliance efforts including control implementation, evidence collection, audit readiness, and ongoing maintenance.
Manage security tooling, incident response, access control, data protection, and act as primary liaison for auditors, customers, and vendors on security posture.
Minimum Requirements
6+ years in product/application security with demonstrated ownership of SOC 2 compliance, including carrying through multiple audit cycles or building from scratch.
Hands-on experience with common vulnerabilities (OWASP Top 10+), embedding security into SDLC, and familiarity with security tooling (SAST/DAST, SCA, secrets scanning).
Proficiency in reviewing and fixing backend production code in at least one language: Go, Node.js, Python, or Java.
Must be willing to work US time zones (EST/EDT, PST/PDT hours).
Ideal Candidate Profile
Able to influence engineering teams on security best practices without formal authority and without blocking shipping.
Experience with cloud security in AWS environment aligned to infrastructure tech stack.
Strong cross-functional communicator capable of translating technical risk into business terms for leadership, auditors, and customers.
