Compliance Engineering Lead

Socket

United States

On-site

USD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity program
Health benefits
Remote-first culture
Parental leave

Job summary

Socket seeks a Compliance Engineering Lead to own compliance as an engineered system. You will drive SOC 2 Type II, ISO 27001, and ISMS programs, building automated evidence pipelines from GCP, GitHub, identity providers, and ticketing systems.

You will report to the CISO, hire a teammate focused on security questionnaires, RFPs, and contract security reviews with Legal. This role blends security, engineering, and governance in a remote-first environment.

Qualifications

  • Owned at least two full SOC 2 Type II cycles as the accountable person.
  • Experience taking ISO 27001 certification and ISMS through surveillance audits.
  • Automation of evidence collection from systems of record (GCP, GitHub, identity providers, MDM, ticketing).

Responsibilities

  • Own SOC 2 Type II end to end, including auditor relationship and evidence pipeline.
  • Lead ISO 27001 certification and ongoing ISMS maintenance.
  • Develop automated evidence collection and monitoring to detect drift before audits.
  • Turn risk management into working programs and maintain a risk register.
  • Own the customer-facing assurance surface and build a trust portal and artifact library.
  • Scope and guide AI assurance posture and decide which standards to pursue.

Skills

SOC 2 Type II
ISO 27001
Automation
Risk management
Communication

Tools

Drata/Vanta
GCP
GitHub
Identity provider
MDM
Ticketing systems

Job description

About Us

Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets to see for yourself!)

About Us

Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets to see for yourself!)

Founded by Feross Aboukhadijeh, a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $125M in funding from top angels, operators, and security leaders.

About The Role

We are hiring a Compliance Engineering Lead to own compliance as an engineered system rather than a calendar of reminders.

Socket sells to security teams. Our customers ask harder questions than most buyers ask, and they are right to. That means our SOC 2 Type II, our path to ISO 27001, our risk and vendor programs, and the assurance artifacts we put in front of enterprise buyers all have to be genuinely well run, not merely present. The credibility of what we sell depends on it.

This is a foundational role, and it is deliberately an engineering role. The person we want does not manage compliance by chasing people for screenshots. They write code against APIs, build control tests that run on a schedule and fail loudly, and treat evidence collection as a pipeline with an owner and an SLA. You will own the compliance platform decision, including whether the platform we use today is the right one. If your answer is that we should build more of it ourselves, make that case.

You will report directly to the CISO, own the compliance program end to end, and hire and lead your first teammate, a customer trust hire focused on security questionnaires, RFPs, and contract security review with Legal. You will shape what GRC at Socket becomes.

What You’ll Do
  • Own SOC 2 Type II end to end. Run the observation window, the auditor relationship, and the evidence pipeline behind both. Scope the audit and make sure the controls we describe are the controls that actually run. You own the report our customers read.
  • Take Socket through ISO 27001 certification. Define the scope and the ISMS, run the gap assessment and internal audit, prepare the organization and get us certified. Enterprise customers are asking for this now. Then keep the ISMS alive as something the company uses rather than something the auditor visits.
  • Make evidence collection continuous, automated, and boring. Write and maintain automation that pulls evidence directly from the systems of record: GCP, GitHub, our identity provider, MDM, ticketing. Build control monitoring that alerts on drift the day it happens instead of surfacing it the week before an audit. Every recurring manual task you inherit is a candidate for deletion.
  • Turn risk management and vendor risk into working programs. Maintain a risk register that reflects the risks we actually carry and that leadership uses when making decisions. In partnership with our external security partner, run third party risk with real tiering, real reviews, and a renewal cadence that holds.
  • Own the customer-facing assurance surface. Launch and maintain our trust portal, and build the library of artifacts that answers enterprise buyers before they send a spreadsheet. Measure your success by how much questionnaire load disappears, not by how quickly it gets processed.
  • Scope our AI assurance posture. Our customers are shipping AI systems and so are we. Evaluate what matters: ISO/IEC 42001, emerging AI agent assurance standards such as AIUC-1, the EU AI Act, and the NIST AI Risk Management Framework. Inform which of these to commit to, in what order, and what it would take. This is open ground and you will help decide what Socket does here.
What You’ll Bring
  • You have personally owned at least two full SOC 2 Type II cycles as the accountable person. Not contributed to them. Owned them, including the auditor relationship, the scoping arguments, the evidence, and the findings. You can describe a control that failed, why, and what you changed so it stopped failing.
  • ISO 27001 depth. You have taken an organization through certification or run an ISMS through surveillance audits, and you know the difference between an ISMS that works and a binder that satisfies an auditor.
  • You build automations. Comfortable building and maintaining automations against services. You can operate with GCP, GitHub, Iru and other reaching for a scheduled job before a recurring calendar reminder. You do not need to be a software engineer by training. You do need to be someone who automates.
  • Clear opinions about compliance platforms. Hands-on experience with Drata, Vanta, or similar, and specific views on where these tools create leverage and where they create the appearance of control.
  • The judgment to prioritize. You can tell the difference between a control gap that represents real risk and one that represents an auditor's formatting preference, and you spend the company's time accordingly.
  • Writing that holds up in front of four audiences. Auditors, enterprise security reviewers, engineers, and executives.
  • The instinct to step toward unowned problems, including the unglamorous seams between Security, Engineering, Legal, and Go-to-Market. Compliance at a company our size lives in those seams.
  • Experience in a remote, fast-moving environment where priorities shift and nobody hands you a fully defined program.
  • Nice to Have:
    • Exposure to AI governance frameworks (ISO/IEC 42001, NIST AI RMF, EU AI Act); experience at a security vendor or another company held to a higher bar by its own customers; contract security review alongside Legal; having built compliance automation in-house rather than buying it.
Our Interview Process
  • Informational with a member of our Talent Team
  • Hiring Manager interview with our CISO
  • Working session: walk us through a control you automated, and design an evidence pipeline with us
  • Cross-functional interviews with Engineering and Go-to-Market
  • Debrief
  • Decision and offer

Hiring is a big decision on both sides. Read more about our Hiring Philosophy and how we approach the process at Socket.

Benefits:

Our benefits are crafted to support you and your family, so you can take care of what matters most and thrive in and outside of work. We offer:

  • Market competitive salary bands
  • Meaningful equity program
  • Comprehensive health benefits for you and your family (99% coverage)
  • Flexible time-off, holidays, and winter shutdown to rest & recharge
  • Paid parental leave
  • Remote-first, with quarterly team off-sites
At Socket, we
  • Pursue Excellence: We set ourselves apart by consistently delivering work of exceptional quality and distinction.
  • Move with urgency and focus: We prioritize swift, decisive action.
  • Think rigorously: We care about being right and it often takes reasoning from first principles to get there. We value alternative perspectives and have constructive discussions.
  • Trust and amplify: We overtrust, always assume good intent, and give specific feedback to help each other improve.
  • Feel a strong sense of ownership: We wear many hats and feel a strong sense of overall ownership of the company and we're non-territorial regarding our nominal domains.
  • Are customer obsessed: We relentlessly prioritize the needs of our customers, striving to exceed their expectations and delight them at every interaction.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Engineering Lead
Compliance Engineering Lead

Socket • Northern (KY)

Hybrid
USD 150,000 - 230,000
Equity program
Comprehensive health benefits
Remote-first with team off-sites
+1
Technical Account Manager, Commercial at Socket
Technical Account Manager, Commercial at Socket

Matcha • Northern (KY)

Hybrid
USD 90,000 - 150,000
Competitive salary bands
Equity program
Health benefits for you and family
+3
Enterprise Account Executive
Enterprise Account Executive

DaParrot Ltd • Northern (KY)

Hybrid
USD 140,000 - 200,000
Equity program
Health benefits
Remote-first
+2
Technical Account Manager, Enterprise at Socket
Technical Account Manager, Enterprise at Socket

Matcha • Northern (KY)

Hybrid
USD 90,000 - 130,000
Market competitive salary bands
Meaningful equity program
Comprehensive health benefits for you
+2
Sales Development Representative
Sales Development Representative

Socket • San Francisco (CA)

On-site
USD 80,000 - 108,000
Competitive salary bands
Equity program
Health benefits for you and family
+3
Forward Deployed Engineer, Python
Forward Deployed Engineer, Python

Socket • Northern (KY)

Hybrid
USD 140,000 - 180,000
Competitive salary bands
Meaningful equity
Health benefits for you and family
+3
Sales Engineer, Commercial
Sales Engineer, Commercial

Coinscapture • Northern (KY)

Hybrid
USD 90,000 - 160,000
Equity program
Comprehensive health benefits
Remote-first culture
+2
Sales Engineer, Enterprise
Sales Engineer, Enterprise

Coinscapture • Northern (KY)

Hybrid
USD 110,000 - 160,000
Remote-first
Quarterly team off-sites
Equity program
+1
Head of IT/Compliance
Head of IT/Compliance

Footprint • New York (NY)

On-site
USD 180,000 - 260,000
Equity package
Free meals
Wellness stipend
+2
Forward Deployed Engineer, Python
Forward Deployed Engineer, Python

Coinscapture • Northern (KY)

Hybrid
USD 150,000 - 210,000
Remote-first
Travel opportunities