Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
iSeatz, Inc. is seeking a Cybersecurity Compliance Engineer to support the Governance, Risk, and Compliance function.
You will ensure products, systems, and processes meet regulatory, security, and compliance requirements across PCI-DSS, SOC 2, NIST, GDPR, ISO frameworks, and customer obligations. You will lead audits, coordinate evidence collection, perform vendor security reviews, and translate regulatory needs into actionable technical requirements for Engineering, DevOps, Product, and other
The Cybersecurity Compliance Engineer reports to the Information Security Manager and supports the Governance, Risk, and Compliance function, partnering with team leads, directors, and compliance auditors to maintain and enhance our compliance initiatives, focusing on data protection and security. In this role, you will ensure our products, systems, and processes meet applicable regulatory, security, and compliance requirements.
Ensure day-to-day compliance activities across applicable frameworks and requirements with a focus on PCI DSS but including SOC 2, NIST, GDPR, ISO, and customer-specific security and compliance obligations.
Lead the preparation and execution of internal and external audits, including evidence collection, control validation, auditor coordination, issue tracking, and remediation follow-up.
Perform technical security and compliance reviews of third-party vendors and service providers, evaluating security controls, architecture, data handling practices, compliance posture, and associated risks.
Support customer and partner security assessments, including security questionnaires, evidence requests, technical discussions, and validation of contractual security and compliance requirements.
Evaluate new technologies and services for security and compliance risk, and provide practical recommendations before implementation or adoption.
Translate compliance and regulatory requirements into clear technical and operational requirements for Engineering, DevOps, Product, and other teams.
Support remediation of Pen Test and external audit findings.
Review and validate technical security controls related to identity and access management, logging and monitoring, vulnerability management, encryption, network security, secrets management, data protection, and secure development practices.
Manage compliance controls and evidence within compliance automation and GRC platforms, ensuring controls are properly implemented, tested, documented, and supported by appropriate evidence.
Identify compliance and security gaps through control testing, technical reviews, risk assessments, and monitoring, and work with control owners to develop and track remediation plans through completion.
Conduct and support periodic risk assessments, access reviews, vendor reviews, policy reviews, and other recurring compliance activities.
Maintain policies, standards, procedures, control documentation, risk records, exceptions, and other compliance artifacts to ensure they remain accurate and aligned with current business and technical environments.
Partner with Information Security and technical teams to improve compliance processes through automation, improved monitoring, and more efficient evidence collection and validation.
Experience working in information security, audit, compliance, GRC, or a closely related technical field.
Strong working knowledge of PCI-DSS assessments, including experience supporting assessments, control testing, evidence collection, and remediation activities.
Understanding of common security concepts and controls, including IAM, encryption, vulnerability management, logging and monitoring, and data protection.
Experience performing security and compliance reviews of systems, technologies, processes, or third-party service providers.
Experience evaluating technical and administrative controls to determine whether they are appropriately designed, implemented, and supported by sufficient evidence.
Experience with risk assessments, control testing, compliance findings, and remediation tracking.
Ability to understand technical architectures, system configurations, data flows, and security controls well enough to identify compliance concerns and communicate them effectively.
Experience working with GRC or compliance automation platforms such as Drata, Vanta, Secureframe, AuditBoard, or similar tools.
Relevant security, audit, risk, or compliance certifications such as CISA, CRISC, PCIP, CISSP, CIA, or ISO 27001 Lead Auditor/LeadImpler.
Experience working with additional security and compliance frameworks such as NIST CSF, NIST 800-53, ISO 27001, or similar frameworks.
Experience supporting compliance programs in AWS or other cloud-native environments.
Experience mapping controls across multiple compliance frameworks.
Working knowledge of cloud security and compliance concepts, preferably within AWS environments, including IAM, logging, encryption, network security, and the shared responsibility model.
Experiencework …