Senior Compliance Engineer

Estuary

United States

On-site

USD 160,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Estuary is a real-time data integration platform seeking a Senior Compliance Engineer to own governance, risk, and audit programs across GDPR, PCI DSS, SOC 2 and HIPAA. You will translate policy into automated controls, drive evidence collection, and partner with engineers to keep controls current as products evolve.

You’ll lead enterprise diligence, vendor assessments, and security questionnaires while shaping how we demonstrate protection of customer data at scale.

Qualifications

  • Led compliance programs end to end at a company where product security was audited.
  • Experience with SOC 2 Type II audits and ongoing attestation processes.
  • Genuine privacy fluency across GDPR, data transfers, DPAs and sub-processor management.
  • Policy development that is auditable and enforceable across engineering teams.
  • Hands-on ownership of IAM, device and SaaS security within a distributed org.

Responsibilities

  • Govern governance and compliance programs, automate evidence and audits.
  • Maintain SOC 2 and HIPAA programs with ongoing evidence collection and testing.
  • Lead GDPR and PCI DSS initiatives, including gap analysis and remediation sequencing.
  • Coordinate vendor risk, sub-processor reviews, and customer security questionnaires.
  • Manage incident readiness, business continuity, and disaster recovery planning.

Skills

Compliance leadership
SOC 2 depth
Privacy governance
Policy writing
Engineering empathy
Audit coordination
Identity access
Cloud architectures
Communication

Job description

Estuary is a real-time data integration platform built for both fast-moving developers and large-scale enterprises. We combine change data capture (CDC), stream processing, and declarative configuration into a unified system that simplifies complex data movement. With Estuary, teams build reliable, low-latency pipelines, without the overhead of managing data infrastructure.

The Role

We are looking for a Senior Compliance Engineer to join our security and compliance function. Our SOC 2 and HIPAA programs are mature and audited. Two areas will have your attention from the start: GDPR, where EU enterprise demand keeps raising the bar across our category, and PCI DSS, which this role will lead as customer demand builds. You will drive both, while keeping the established programs running at the standard our customers expect.

This is a governance role first. You will be the person who designs the control set, automates the evidence, runs the audit cycle, keeps policy current as the company and product change, and answers the hard questions on a customer security call. The role also covers corporate IT, because identity and endpoint management are where a meaningful share of those controls operate day to day.

Success requires a blend of deep framework expertise and practical systems judgment. You will be translating abstract control language into automation and defaults engineers can work with, rather than policy that sits apart from the work.

Compliance at Estuary carries commercial weight, not just risk weight. Customers move sensitive data through our platform, and our ability to show exactly how it is protected is part of what earns that. This work is visible to customers in a way compliance often isn’t.

A note on fit. This role spans governance and IT; we are looking for someone who has been the person accountable for a compliance program rather than a contributor to one, and who can also run the systems underneath it. We are not looking for a systems administrator who has been adjacent to audits. If your experience is primarily device and identity administration without program ownership, this is likely not the right role, and we would rather tell you that here than in a fourth interview.

What You’ll Do
Governance and Compliance
  • Deepen Our GDPR Program: Estuary exists to move customer data across systems, which puts privacy close to the product. Take our GDPR program to the depth EU enterprise buyers’ counsel look for across records of processing, lawful basis, DPAs and sub-processor management, cross-border transfer mechanisms, data residency commitments, retention, and DSAR handling.
  • Lead Our PCI DSS Effort: Take us to attestation as a service provider, as a planned and resourced program rather than a reaction to one deal. Scope how the platform’s role in moving customer data maps to the requirements, run the gap assessment, sequence the remediation, and carry us through attestation.
  • Sustain SOC 2 and HIPAA: Run the day to day of two programs with a good audit track record: continuous evidence collection, access reviews, control testing, auditor coordination, BAAs and PHI handling. Both programs are in good standing, and your job is to keep them there as the company and the product surface grow.
  • Risk and Assessments: Keep our risk register and system of record current, working with the engineers and leaders who hold each risk. Run vendor and sub-processor assessments, coordinate penetration testing, and keep security awareness training on schedule.
  • Keep Compliance Scope Current as the Platform Evolves: As Estuary’s architecture, deployment options, and vendor footprint change, the compliance boundary moves with them. You will work out what each change means for scope, controls, and customer commitments, and keep our documentation and customer-facing answers current as it happens.
  • Support Enterprise Diligence: Partner with sales on security questionnaires, vendor risk reviews, and customer audits, so buyers get accurate answers quickly. Maintain a trust center and keep our security documentation current.
  • Keep Us Incident Ready: Maintain and exercise incident response, business continuity, and disaster recovery plans alongside engineering. Be the calm, organized presence when a plan has to be used.
The Systems Underneath
  • Run Identity and Access: SSO and IdP administration, provisioning and deprovisioning, MFA, and least privilege. Keep extending the automation behind access reviews so they draw directly from system state.
  • Run Endpoints and the SaaS Estate: Device management and MDM, endpoint security, onboarding and offboarding, vendor procurement and security review, license hygiene, and full visibility into the SaaS estate.
  • Automate the Evidence Path: Extend our compliance automation and evidence collection so controls stay continuously satisfied by default and keep shrinking the set that needs manual effort.
What We’re Looking For
  • 8+ years in compliance, GRC, or security governance: You have personally carried organizations through audits and come out the other side, at companies where the product was the thing being audited. Program ownership is the requirement here, not audit participation.
  • You Have Built, Not Just Maintained: You have stood up at least one compliance program from close to nothing. You know what the first ninety days look like, which gaps matter, and how to sequence remediation when everything is technically a finding.
  • SOC 2 Depth: You have run a SOC 2 Type II through a full audit cycle, and you know the difference between a control that passes and a control that works.
  • Privacy Fluency: You are genuinely comfortable with GDPR mechanics: data processing agreements, lawful basis, transfer mechanisms, sub-processor management, and data residency. Not just familiar with the acronym.
  • Policy and Judgment: You write policy that is precise enough to audit against and practical enough for the team to work with, you can make and document a defensible risk acceptance decision, and you can explain your reasoning to an auditor and stand behind it.
  • Hands-On Systems Ownership: You have run identity, device, and SaaS administration for a distributed company yourself. You are as comfortable in an IdP admin console as you are in an audit workbook.
  • Systems Thinking: You enjoy detective work: tracing how a system behaves under load, where data moves and who can reach it, and where documented process and lived process diverge.
  • Engineering Empathy: You can read a cloud architecture diagram, hold your own with engineers about infrastructure and access controls, and design controls that hold up without slowing delivery.
  • Clear Communication: Ability to explain complex compliance trade-offs to both technical and non-technical stakeholders, including a prospect’s CISO on a live call.
  • Practical Experience: Certifications like CISSP, CISA, or CIPP/E are welcome. What we weigh most heavily is a track record of programs you have run end to end.

We know that excellence comes in many forms. If you don't meet 100% of these qualifications but have carried a compliance program through a full audit cycle and are excited about what we’re building, we encourage you to apply.

Bonus Points For
  • Direct PCI DSS Experience: Hands-on with PCI scoping, cardholder data environments, and the SAQ or ROC process, especially as a service provider rather than a merchant.
  • ISO 27001: Experience building toward or maintaining certification, and mapping a shared control set across overlapping frameworks.
  • Data Infrastructure Context: Experience supporting a data platform, ETL or CDC vendor, or a similar company where customer data is the product surface.
  • Compliance Automation Tooling: Hands-on with platforms like Vanta, Drata, or Secureframe, and clear eyed about where they help and where they don't.
  • Public Sector Exposure: Familiarity with FedRAMP, StateRAMP, or NIST 800-53, enough to tell us honestly what that path would demand.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Senior Security Program Manager
Senior Security Program Manager

Flexhire • United States

On-site
USD 140,000 - 190,000
GRC Analyst - Public Sector
GRC Analyst - Public Sector

Apply • Washington, Northern (KY)

Hybrid
USD 110,000 - 140,000
Senior Compliance Engineer: GDPR, PCI DSS & Audit Lead
Senior Compliance Engineer: GDPR, PCI DSS & Audit Lead

Estuary • United States

On-site
USD 160,000 - 210,000
Senior Manager of Governance, Risk, and Compliance
Senior Manager of Governance, Risk, and Compliance

Maven Clinic • United States

On-site
USD 140,000 - 180,000
Parental leave
401K matching
Professional development stipend
+2
Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)
Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)

UberEther • United States

Hybrid
USD 150,000 - 190,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)
Senior DevOps/Compliance Engineer (FedRAMP Continuous Compliance)

UberEther • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Medical, Dental & Vision
401K with company match
Paid time off
+3
Compliance and Privacy Engineer
Compliance and Privacy Engineer

SPECTRAFORCE • Cupertino (CA)

On-site
USD 120,000 - 160,000
IT Security and Systems Engineer
IT Security and Systems Engineer

SilencerCo • West Valley City (UT)

On-site
USD 120,000 - 180,000