Senior Security & Compliance Engineer - Austin

Biorce

Barcelona

Híbrido

EUR 60.000 - 90.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Hybrid work
MacBook provided
Private health coverage
Global team

Descripción de la vacante

Biorce is a pioneering Healthtech company using AI to accelerate drug development. We seek a Senior Security & Compliance Engineer to lead security and compliance efforts across SaaS and cloud environments, reporting to Security / Engineering leadership.

The role embeds automated checks, incident response, and risk-based controls into how we build and operate technology, with a hybrid work model and strong emphasis on certifications.

Formación

  • Hands-on experience implementing ISO 27001 and SOC 2 Type II certifications.
  • Experience with GRC platforms (Vanta, Drata, Secureframe) for evidence collection.
  • Ability to write code and scripts to fix cloud, IAM, and infra gaps without dev handoffs.
  • Strong foundation in AI-enabled security tools and automating workflows.

Responsabilidades

  • Drive end-to-end implementation and audit readiness for ISO 27001, SOC 2 Type II, and future frameworks.
  • Operate and optimize automated GRC platforms and maintain evidence collection workflows.
  • Own internal security policy management, risk registers, and vendor security assessments.
  • Remediate non-compliance findings and vulnerabilities across SaaS and cloud infra.
  • Oversee internal IT stack, zero-trust controls, and identity management.
  • Provide technical escalation support for security and IT service tasks.

Conocimientos

ISO 27001
SOC 2 Type II
Security automation
Cloud security
Vulnerability remediation
Identity & access management
Zero trust

Educación

Bachelor's or Master's in Computer Science, Cybersecurity, Information Security, or related field

Herramientas

Vanta
Drata
Secureframe
Terraform
IaC scripting
Python
Bash

Descripción del empleo

Biorce is a pioneering Healthtech company dedicated to revolutionizing drug development through the power of AI. We are passionate about accelerating medical advancements and improving patient outcomes.

Our team comprises seasoned clinical research professionals, data scientists, and AI experts, working collaboratively to bridge the gap between cutting‑edge technology and real‑world clinical needs.

With an unwavering commitment to revolutionize healthcare, we envision a world where all patients benefit from accelerated and cost‑effective access to treatments. Biorce is poised to redefine the landscape of healthcare, shaping a future where innovation and accessibility converge for the betterment of humanity.

About the company

Biorce is a pioneering Healthtech company dedicated to revolutionizing drug development through the power of AI. We are passionate about accelerating medical advancements and improving patient outcomes.

Our team comprises seasoned clinical research professionals, data scientists, and AI experts, working collaboratively to bridge the gap between cutting‑edge technology and real‑world clinical needs.

With an unwavering commitment to revolutionize healthcare, we envision a world where all patients benefit from accelerated and cost‑effective access to treatments. Biorce is poised to redefine the landscape of healthcare, shaping a future where innovation and accessibility converge for the betterment of humanity.

About the role

Following our successful expansion into the U.S. and continued growth across Europe, we are seeking a Senior Security & Compliance Engineer to manage and elevate Biorce's security and compliance posture.

Reporting directly to our Security / Engineering leadership, this person will play a critical role getting our customers and partners' trust, driving the certifications audits, keeping our certification monitoring tool up to date, and working with different teams to keep internal processes running smoothly.

This role will be key in embedding automated security checks, compliance support, and incident response into the way our teams build and operate technology.

Who We’re Looking For:

This is not a purely advisory or auditing role. We are looking for a hybrid operator who can lead heavy‑lift compliance frameworks (ISO 27001, SOC 2, ISO 27701) and possesses the technical capability to directly remediate non‑compliance findings, configure cloud security controls, and fix vulnerabilities in code and infrastructure—without needing to hand off tasks to dev teams.

Key Responsibilities:
  • Drive end‑to‑end implementation, audit readiness, and continuous management for ISO 27001, SOC 2 Type II, and other frameworks in the future.
  • Operate and optimize automated GRC platforms (Vanta) and maintain continuous evidence collection workflows
  • Own internal security policy management, risk registers, vendor security assessments, and regulatory compliance aligned with healthtech data standards
  • Autonomously remediate identified non‑compliance findings and vulnerabilities across SaaS, cloud infrastructure, CI/CD pipelines, working with other teams when necessary
  • Proactively oversee Biorce's internal IT stack, endpoint security (MDM), zero‑trust access controls, and identity management
  • Provide technical escalation support for internal security and IT service desk tasks to keep day‑to‑day operations secure and frictionless
Must-haves
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, or a related field, with 4+ years of experience in application or product security.
  • Demonstrated, hands‑on experience implementing, driving, and maintaining ISO 27001 and SOC 2 Type II certifications
  • Experience working with GRC tools like Vanta, Drata, Secureframe, or similar compliance platforms.
  • Proven ability to write code and infrastructure scripts (e.g., Python, Bash, Terraform/IaC) to directly fix cloud, IAM, and infrastructure gaps without dev team handoffs.
  • Proven track record or strong enthusiasm for leveraging modern AI tools and scripts to automate workflows, accelerate evidence collection, and scale individual output
Nice-to-Haves
  • Experience with infrastructure‑as‑code security, Terraform, Pulumi.
  • Certifications such as OSCP, OSWE, CISSP, or CSSLP.
  • Experience leading penetration testing efforts or coordinating with third‑party security assessors.
  • Hands‑on experience performing security code reviews, threat modeling, and vulnerability assessments.
  • Practical experience with AppSec tools such as Aikido, Snyk, or equivalents, such as GitHub Advanced Security or SonarQube.
  • Direct exposure to or preparation for ISO 27701 or HIPAA/GDPR health data frameworks
Why Join Us?
  • A dynamic work environment with an international team, where collaboration and diversity thrive.
  • Work alongside top talent, united by a shared purpose and committed to making a real impact.
  • Comprehensive private health coverage to ensure your physical and mental well‑being.
  • Hybrid work model offering flexibility to balance your professional and personal life.
  • Company events to celebrate achievements and enjoy time together.
  • Get equipped with a MacBook to enhance your productivity and work experience.
  • Our office is pet‑friendly! You'll likely be greeted by a few wagging tails upon arrival.

--

By submitting this application, I agree that my personal data will be collected, processed, and retained by the company solely for the purposes of managing and assessing my candidacy.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Business Performance Lead - Barcelona
Business Performance Lead - Barcelona

Biorce • Barcelona

Híbrido
EUR 90.000 - 130.000
Private health coverage
Hybrid work model
MacBook provided
+1
Principal Architect (Applied AI + SaaS) - Office of the CTO
Principal Architect (Applied AI + SaaS) - Office of the CTO

Biorce • Barcelona

Híbrido
EUR 120.000 - 180.000
Client Partner - Commercial / Strategic Accounts (Pharma)
Client Partner - Commercial / Strategic Accounts (Pharma)

Biorce • Barcelona

Híbrido
EUR 175.000 - 200.000
MacBook provided
Private health coverage
Hybrid work model
+1
Technical Product Manager
Technical Product Manager

Biorce • Barcelona

Presencial
EUR 70.000 - 95.000
Health benefits
Flexible hybrid work culture
Equity participation
VP/Head of Ecosystem Partnerships
VP/Head of Ecosystem Partnerships

Biorce • Barcelona

Híbrido
EUR 218.000 - 285.000
Hybrid work model
MacBook
Private health coverage
+3
Senior Backend Developer (Delta Team) - Barcelona
Senior Backend Developer (Delta Team) - Barcelona

Biorce • Barcelona

Presencial
EUR 70.000 - 100.000
MacBook provided
Hybrid work model
Medical, dental, vision insurance
Director / Senior Director, Clinical Solutions (Business Development) - EU
Director / Senior Director, Clinical Solutions (Business Development) - EU

Biorce • Barcelona

Híbrido
EUR 120.000 - 180.000
Competitive base salary
Uncapped commission
Hybrid work model
+2
Lead Data Engineer - Barcelona
Lead Data Engineer - Barcelona

Biorce • Barcelona

Presencial
EUR 90.000 - 120.000
Private health coverage
MacBook provided
Hybrid work model
+1
Strategy Manager, CEO Office
Strategy Manager, CEO Office

Biorce • Barcelona

Híbrido
EUR 100.000 - 140.000
MacBook
Hybrid work model
Private health coverage
+3
Senior Director / VP of Business Development - CRO Vertical
Senior Director / VP of Business Development - CRO Vertical

Biorce • Barcelona

Híbrido
EUR 175.000 - 225.000
Hybrid work model
MacBook provided
Pet-friendly office
+2