Cybersecurity Compliance Engineer

iSeatz, Inc.

United States

Remote

USD 90,000 - 130,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

iSeatz, Inc. is seeking a Cybersecurity Compliance Engineer to support the Governance, Risk, and Compliance function.

You will ensure products, systems, and processes meet regulatory, security, and compliance requirements across PCI-DSS, SOC 2, NIST, GDPR, ISO frameworks, and customer obligations. You will lead audits, coordinate evidence collection, perform vendor security reviews, and translate regulatory needs into actionable technical requirements for Engineering, DevOps, Product, and other

Qualifications

  • Experience in information security, audit, compliance, or GRC related fields.
  • Strong working knowledge of PCI-DSS assessments and supporting activities.
  • Understanding of common security controls such as IAM, encryption, logging, and vulnerability management.
  • Experience reviewing systems, processes, or third-party providers for security/compliance.
  • Ability to translate regulatory requirements into clear technical and operational requirements.

Responsibilities

  • Support Governance, Risk, and Compliance programs across PCI-DSS, SOC 2, NIST, GDPR, ISO.
  • Lead preparation and execution of internal and external audits, including evidence collection and remediation follow-up.
  • Perform security and compliance reviews of third-party vendors and service providers.
  • Assist with customer security assessments and validation of contractual security requirements.
  • Evaluate new technologies for security/compliance risk and provide recommendations.
  • Develop and track remediation plans with control owners until closure.

Skills

Information security
Audit and compliance
GRC

Tools

Drata
Vanta
Secureframe
AuditBoard

Job description

What you’ll do

The Cybersecurity Compliance Engineer reports to the Information Security Manager and supports the Governance, Risk, and Compliance function, partnering with team leads, directors, and compliance auditors to maintain and enhance our compliance initiatives, focusing on data protection and security. In this role, you will ensure our products, systems, and processes meet applicable regulatory, security, and compliance requirements.


Your Impact

Ensure day-to-day compliance activities across applicable frameworks and requirements with a focus on PCI DSS but including SOC 2, NIST, GDPR, ISO, and customer-specific security and compliance obligations.


Lead the preparation and execution of internal and external audits, including evidence collection, control validation, auditor coordination, issue tracking, and remediation follow-up.


Perform technical security and compliance reviews of third-party vendors and service providers, evaluating security controls, architecture, data handling practices, compliance posture, and associated risks.


Support customer and partner security assessments, including security questionnaires, evidence requests, technical discussions, and validation of contractual security and compliance requirements.


Evaluate new technologies and services for security and compliance risk, and provide practical recommendations before implementation or adoption.


Translate compliance and regulatory requirements into clear technical and operational requirements for Engineering, DevOps, Product, and other teams.


Support remediation of Pen Test and external audit findings.


Review and validate technical security controls related to identity and access management, logging and monitoring, vulnerability management, encryption, network security, secrets management, data protection, and secure development practices.


Manage compliance controls and evidence within compliance automation and GRC platforms, ensuring controls are properly implemented, tested, documented, and supported by appropriate evidence.


Identify compliance and security gaps through control testing, technical reviews, risk assessments, and monitoring, and work with control owners to develop and track remediation plans through completion.


Conduct and support periodic risk assessments, access reviews, vendor reviews, policy reviews, and other recurring compliance activities.


Maintain policies, standards, procedures, control documentation, risk records, exceptions, and other compliance artifacts to ensure they remain accurate and aligned with current business and technical environments.


Partner with Information Security and technical teams to improve compliance processes through automation, improved monitoring, and more efficient evidence collection and validation.


What you bring to the table

Experience working in information security, audit, compliance, GRC, or a closely related technical field.


Strong working knowledge of PCI-DSS assessments, including experience supporting assessments, control testing, evidence collection, and remediation activities.


Understanding of common security concepts and controls, including IAM, encryption, vulnerability management, logging and monitoring, and data protection.


Experience performing security and compliance reviews of systems, technologies, processes, or third-party service providers.


Experience evaluating technical and administrative controls to determine whether they are appropriately designed, implemented, and supported by sufficient evidence.


Experience with risk assessments, control testing, compliance findings, and remediation tracking.


Ability to understand technical architectures, system configurations, data flows, and security controls well enough to identify compliance concerns and communicate them effectively.


Experience working with GRC or compliance automation platforms such as Drata, Vanta, Secureframe, AuditBoard, or similar tools.


Bonus points

Relevant security, audit, risk, or compliance certifications such as CISA, CRISC, PCIP, CISSP, CIA, or ISO 27001 Lead Auditor/LeadImpler.


Experience working with additional security and compliance frameworks such as NIST CSF, NIST 800-53, ISO 27001, or similar frameworks.


Experience supporting compliance programs in AWS or other cloud-native environments.


Experience mapping controls across multiple compliance frameworks.


Working knowledge of cloud security and compliance concepts, preferably within AWS environments, including IAM, logging, encryption, network security, and the shared responsibility model.


Experiencework …

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Compliance Engineer
Security Compliance Engineer

ANAUTICS INC • Oklahoma City (OK)

On-site
USD 80,000 - 100,000
Senior Information Security Engineer
Senior Information Security Engineer

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Security Compliance Manager
Security Compliance Manager

MW Partners • Lehi (UT)

On-site
USD 80,000 - 110,000
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
Cyber Security Engineer
Cyber Security Engineer

Qualibar • United States

Hybrid
USD 120,000 - 180,000
Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • New York (NY)

Remote
USD 170,000 - 240,000
Senior Cloud Security Specialist
Senior Cloud Security Specialist

EPAM Systems Inc • United States

Remote
USD 140,000 - 190,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2