Estuary is a real-time data integration platform built for both fast-moving developers and large-scale enterprises. We combine change data capture (CDC), stream processing, and declarative configuration into a unified system that simplifies complex data movement. With Estuary, teams build reliable, low-latency pipelines, without the overhead of managing data infrastructure.
The Role
We are looking for a Senior Compliance Engineer to join our security and compliance function. Our SOC 2 and HIPAA programs are mature and audited. Two areas will have your attention from the start: GDPR, where EU enterprise demand keeps raising the bar across our category, and PCI DSS, which this role will lead as customer demand builds. You will drive both, while keeping the established programs running at the standard our customers expect.
This is a governance role first. You will be the person who designs the control set, automates the evidence, runs the audit cycle, keeps policy current as the company and product change, and answers the hard questions on a customer security call. The role also covers corporate IT, because identity and endpoint management are where a meaningful share of those controls operate day to day.
Success requires a blend of deep framework expertise and practical systems judgment. You will be translating abstract control language into automation and defaults engineers can work with, rather than policy that sits apart from the work.
Compliance at Estuary carries commercial weight, not just risk weight. Customers move sensitive data through our platform, and our ability to show exactly how it is protected is part of what earns that. This work is visible to customers in a way compliance often isn’t.
A note on fit. This role spans governance and IT; we are looking for someone who has been the person accountable for a compliance program rather than a contributor to one, and who can also run the systems underneath it. We are not looking for a systems administrator who has been adjacent to audits. If your experience is primarily device and identity administration without program ownership, this is likely not the right role, and we would rather tell you that here than in a fourth interview.
What You’ll Do
Governance and Compliance
- Deepen Our GDPR Program: Estuary exists to move customer data across systems, which puts privacy close to the product. Take our GDPR program to the depth EU enterprise buyers’ counsel look for across records of processing, lawful basis, DPAs and sub-processor management, cross-border transfer mechanisms, data residency commitments, retention, and DSAR handling.
- Lead Our PCI DSS Effort: Take us to attestation as a service provider, as a planned and resourced program rather than a reaction to one deal. Scope how the platform’s role in moving customer data maps to the requirements, run the gap assessment, sequence the remediation, and carry us through attestation.
- Sustain SOC 2 and HIPAA: Run the day to day of two programs with a good audit track record: continuous evidence collection, access reviews, control testing, auditor coordination, BAAs and PHI handling. Both programs are in good standing, and your job is to keep them there as the company and the product surface grow.
- Risk and Assessments: Keep our risk register and system of record current, working with the engineers and leaders who hold each risk. Run vendor and sub-processor assessments, coordinate penetration testing, and keep security awareness training on schedule.
- Keep Compliance Scope Current as the Platform Evolves: As Estuary’s architecture, deployment options, and vendor footprint change, the compliance boundary moves with them. You will work out what each change means for scope, controls, and customer commitments, and keep our documentation and customer-facing answers current as it happens.
- Support Enterprise Diligence: Partner with sales on security questionnaires, vendor risk reviews, and customer audits, so buyers get accurate answers quickly. Maintain a trust center and keep our security documentation current.
- Keep Us Incident Ready: Maintain and exercise incident response, business continuity, and disaster recovery plans alongside engineering. Be the calm, organized presence when a plan has to be used.
The Systems Underneath
- Run Identity and Access: SSO and IdP administration, provisioning and deprovisioning, MFA, and least privilege. Keep extending the automation behind access reviews so they draw directly from system state.
- Run Endpoints and the SaaS Estate: Device management and MDM, endpoint security, onboarding and offboarding, vendor procurement and security review, license hygiene, and full visibility into the SaaS estate.
- Automate the Evidence Path: Extend our compliance automation and evidence collection so controls stay continuously satisfied by default and keep shrinking the set that needs manual effort.
What We’re Looking For
- 8+ years in compliance, GRC, or security governance: You have personally carried organizations through audits and come out the other side, at companies where the product was the thing being audited. Program ownership is the requirement here, not audit participation.
- You Have Built, Not Just Maintained: You have stood up at least one compliance program from close to nothing. You know what the first ninety days look like, which gaps matter, and how to sequence remediation when everything is technically a finding.
- SOC 2 Depth: You have run a SOC 2 Type II through a full audit cycle, and you know the difference between a control that passes and a control that works.
- Privacy Fluency: You are genuinely comfortable with GDPR mechanics: data processing agreements, lawful basis, transfer mechanisms, sub-processor management, and data residency. Not just familiar with the acronym.
- Policy and Judgment: You write policy that is precise enough to audit against and practical enough for the team to work with, you can make and document a defensible risk acceptance decision, and you can explain your reasoning to an auditor and stand behind it.
- Hands-On Systems Ownership: You have run identity, device, and SaaS administration for a distributed company yourself. You are as comfortable in an IdP admin console as you are in an audit workbook.
- Systems Thinking: You enjoy detective work: tracing how a system behaves under load, where data moves and who can reach it, and where documented process and lived process diverge.
- Engineering Empathy: You can read a cloud architecture diagram, hold your own with engineers about infrastructure and access controls, and design controls that hold up without slowing delivery.
- Clear Communication: Ability to explain complex compliance trade-offs to both technical and non-technical stakeholders, including a prospect’s CISO on a live call.
- Practical Experience: Certifications like CISSP, CISA, or CIPP/E are welcome. What we weigh most heavily is a track record of programs you have run end to end.
We know that excellence comes in many forms. If you don't meet 100% of these qualifications but have carried a compliance program through a full audit cycle and are excited about what we’re building, we encourage you to apply.
Bonus Points For
- Direct PCI DSS Experience: Hands-on with PCI scoping, cardholder data environments, and the SAQ or ROC process, especially as a service provider rather than a merchant.
- ISO 27001: Experience building toward or maintaining certification, and mapping a shared control set across overlapping frameworks.
- Data Infrastructure Context: Experience supporting a data platform, ETL or CDC vendor, or a similar company where customer data is the product surface.
- Compliance Automation Tooling: Hands-on with platforms like Vanta, Drata, or Secureframe, and clear eyed about where they help and where they don't.
- Public Sector Exposure: Familiarity with FedRAMP, StateRAMP, or NIST 800-53, enough to tell us honestly what that path would demand.