Security Engineer, GRC San Francisco or Remote (US) $185,000 – $230,000

Pazau, Inc.

San Francisco (CA)

Remote

USD 185,000 - 230,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity in Pazau
4 weeks paid time off
16 weeks parental leave
401(k) with 4% match
Medical, dental and vision insurance

Job summary

Pazau, Inc. is seeking a security compliance engineer in the San Francisco area or fully remote within the United States.

The role focuses on running and automating SOC 2 Type II and ISO audits, with a hands-on engineering approach to controls as code and evidence collection. You will automate evidence gathering from major platforms, maintain industry-standard questionnaires, and lead vendor risk reviews while aligning with evolving frameworks like the EU AI Act and DORA.

Qualifications

  • 4+ years in security compliance, GRC or security engineering at a SaaS company.
  • Hands-on experience leading SOC 2 and ISO 27001 audits.
  • Ability to write small scripts (Python) or policy-as-code (Terraform).
  • Judgment on effective controls vs. auditor questions.

Responsibilities

  • Own SOC 2 Type II and ISO audits and audit-firm relationships.
  • Automate evidence collection from AWS, Okta, GitHub and CI/CD pipelines.
  • Maintain CAIQ/HECVAT and standard security questionnaire answers for enterprise deals.
  • Run vendor risk reviews with the DPO on 30-day notice process.
  • Map new frameworks (EU AI Act, DORA) to our control set as customers request.

Skills

SOC 2 audits
ISO 27001 audits
Python scripting
Terraform policy

Job description

San Francisco or Remote (US) Full-time $185,000 – $230,000

About the role

Pazau holds SOC 2 Type II, ISO 27001, ISO 27701 and ISO 42001, signs BAAs with healthcare customers and runs a PCI DSS-scoped voice payments path. Every enterprise deal comes with a security questionnaire, and many come with an auditor. You'll join Omar Haddad's security team to run our compliance program as engineering, not paperwork, with controls as code, evidence collected automatically and answers our sales team can trust.

The base salary range for this role is $185,000 – $230,000. Final offers depend on level and location, and every offer includes equity.

What you'll do
  • Own the annual SOC 2 Type II and ISO 27001/27701/42001 surveillance audits, and our audit firm relationships
  • Automate evidence collection from AWS, Okta, GitHub and our deployment pipeline so that an audit takes days rather than months
  • Maintain our CAIQ, HECVAT and standard security questionnaire answers, and review non-standard questionnaires for enterprise deals
  • Run vendor risk reviews for new sub-processors, working with our DPO, Aoife Brennan, on the 30-day notice process
  • Map new frameworks such as the EU AI Act and DORA to our control set as customers begin asking for them
What you'll bring
  • 4+ years in security compliance, GRC or security engineering at a SaaS company
  • Hands-on experience leading SOC 2 and ISO 27001 audits
  • Enough engineering skill to write a Python script or a Terraform policy instead of taking a screenshot
  • Judgment about which controls reduce risk and which only reduce auditor questions
Nice to have
  • Experience with HIPAA, PCI DSS or ISO 42001
  • Familiarity with compliance automation platforms
  • CISA, CISSP or ISO 27001 Lead Auditor certification
  • Medical, dental and vision for you and your dependents, with 100% of premiums covered
  • Equity in Pazau, with a 10-year exercise window after you leave
  • 16 weeks of fully paid parental leave for every parent
  • 401(k) with a 4% match
  • $2,000 a year for learning, plus conference travel when you're speaking
  • Four weeks of paid time off, plus a company-wide week off at the end of December
  • Recruiter call (30 min). We walk through the role, compensation and timeline, and answer your questions first.
  • Hiring manager conversation (45 min). A conversation about work you're proud of and the problems this team owns.
  • Questionnaire review (60 min). We'll share a redacted enterprise security questionnaire and talk through how you'd answer, push back on or elevate a handful of its questions.
  • Final interviews (3–4 hours, virtual or on-site). Three or four conversations with the people you'd work with every day, including one cross-functional partner.
  • Founder conversation and references. A 30-minute conversation with Amara or Lukas, then two references you choose.

Most candidates go from first call to offer in three to four weeks. You'll hear back from us within three business days after every stage, and every candidate who reaches final interviews gets written feedback.

Sound like your next job?

We reply to every application within five business days.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Lead
Information Security Lead

Secfix • United States

On-site
USD 180,000 - 240,000
Remote work: 100% remote
Equity: generous equity package
Mentorship from top VCs
+6
Lead Security Engineer
Lead Security Engineer

8090 Solutions Inc • Redwood City (CA)

On-site
USD 180,000 - 350,000
Group Security & Compliance Manager ($60,000/year USD), Sparkrock
Group Security & Compliance Manager ($60,000/year USD), Sparkrock

Ionic Partners, LLC • United States

Remote
USD 140,000 - 210,000
100% remote and global
Stipend for home office
Flexible work hours
+2
Commercial GRC Engineer - Sr. Security Engineer
Commercial GRC Engineer - Sr. Security Engineer

Jobgether SRL • Town of Montana (WI)

On-site
USD 175,000 - 228,000
Health insurance
401(k) match
Paid holidays
+1
Sr Security Technologist - Risk & Compliance
Sr Security Technologist - Risk & Compliance

Uber • San Francisco (CA)

On-site
USD 180,000 - 200,000
Security Engineer
Security Engineer

Invictus Direct • San Francisco (CA)

On-site
USD 100,000 - 200,000
Relocation assistance
Visa sponsorship
Senior Application Security engineer
Senior Application Security engineer

G-P • United States

Remote
USD 96,000 - 120,000
Paid parental leave
Medical insurance
Dental insurance
+2
Software Engineer Security – Remote US – Paraform
Software Engineer Security – Remote US – Paraform

Syndesus, Inc. • United States

Remote
USD 180,000 - 230,000
Health insurance
Unlimited PTO
Parental leave
+1
Cybersecurity Lead
Cybersecurity Lead

Coverflex • United States

Remote
USD 74,000 - 108,000
Stock options
All Coverflex benefits apply
Security Engineer
Security Engineer

Gamma • San Francisco (CA)

On-site
USD 180,000 - 310,000