San Francisco or Remote (US) Full-time $185,000 – $230,000
About the role
Pazau holds SOC 2 Type II, ISO 27001, ISO 27701 and ISO 42001, signs BAAs with healthcare customers and runs a PCI DSS-scoped voice payments path. Every enterprise deal comes with a security questionnaire, and many come with an auditor. You'll join Omar Haddad's security team to run our compliance program as engineering, not paperwork, with controls as code, evidence collected automatically and answers our sales team can trust.
The base salary range for this role is $185,000 – $230,000. Final offers depend on level and location, and every offer includes equity.
What you'll do
- Own the annual SOC 2 Type II and ISO 27001/27701/42001 surveillance audits, and our audit firm relationships
- Automate evidence collection from AWS, Okta, GitHub and our deployment pipeline so that an audit takes days rather than months
- Maintain our CAIQ, HECVAT and standard security questionnaire answers, and review non-standard questionnaires for enterprise deals
- Run vendor risk reviews for new sub-processors, working with our DPO, Aoife Brennan, on the 30-day notice process
- Map new frameworks such as the EU AI Act and DORA to our control set as customers begin asking for them
What you'll bring
- 4+ years in security compliance, GRC or security engineering at a SaaS company
- Hands-on experience leading SOC 2 and ISO 27001 audits
- Enough engineering skill to write a Python script or a Terraform policy instead of taking a screenshot
- Judgment about which controls reduce risk and which only reduce auditor questions
Nice to have
- Experience with HIPAA, PCI DSS or ISO 42001
- Familiarity with compliance automation platforms
- CISA, CISSP or ISO 27001 Lead Auditor certification
- Medical, dental and vision for you and your dependents, with 100% of premiums covered
- Equity in Pazau, with a 10-year exercise window after you leave
- 16 weeks of fully paid parental leave for every parent
- 401(k) with a 4% match
- $2,000 a year for learning, plus conference travel when you're speaking
- Four weeks of paid time off, plus a company-wide week off at the end of December
- Recruiter call (30 min). We walk through the role, compensation and timeline, and answer your questions first.
- Hiring manager conversation (45 min). A conversation about work you're proud of and the problems this team owns.
- Questionnaire review (60 min). We'll share a redacted enterprise security questionnaire and talk through how you'd answer, push back on or elevate a handful of its questions.
- Final interviews (3–4 hours, virtual or on-site). Three or four conversations with the people you'd work with every day, including one cross-functional partner.
- Founder conversation and references. A 30-minute conversation with Amara or Lukas, then two references you choose.
Most candidates go from first call to offer in three to four weeks. You'll hear back from us within three business days after every stage, and every candidate who reaches final interviews gets written feedback.
Sound like your next job?
We reply to every application within five business days.