Senior Engineer, Security & Compliance (US)

Code and Theory

United States

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Code and Theory is seeking a Senior Security Engineer to lead hands-on security and compliance across our SaaS products and client work. You will own controls, tooling, automation, and processes to secure products and client data, partnering with engineering teams to embed security into delivery workflows.

You will implement SOC 2 II, ISO 27001, and privacy controls, monitor cloud environments, and lead incident response.

Qualifications

  • 5+ years of hands-on security engineering in SaaS or agency delivery.
  • Deep cloud security knowledge (GCP/AWS/Azure) with IAM, networking, logging.
  • Hands-on SOC 2 Type II and ISO 27001 control implementation.
  • Experience embedding security into CI/CD pipelines with SAST/DAST.
  • Familiarity with HIPAA, GDPR, CCPA/CPRA compliance.
  • Proficient in security monitoring and incident response.
  • Strong cross-functional communication skills.

Responsibilities

  • Build and maintain security controls across cloud infra and SaaS products.
  • Own SOC 2 Type II, ISO 27001, and ISO 42001 compliance implementation.
  • Instrument security monitoring and alerting across cloud environments.
  • Integrate security into CI/CD pipelines and enforce policy.
  • Implement privacy controls aligned to HIPAA, GDPR, CCPA/CPRA.
  • Lead client engagements security provisioning and environments segregation.
  • Conduct vendor security assessments and review third-party practices.
  • Maintain incident response playbooks and perform forensic analysis.
  • Develop AI-specific security controls for agent workflows and data handling.
  • Contribute to security questionnaires and RFP responses.

Skills

Security engineering
Cloud security
SOC 2 Type II
ISO 27001
CI/CD security tooling
Privacy regulations
Incident response
AI security
Communication

Education

Certifications: CISSP / CCSP / Cloud Security Specialty

Tools

SIEM tooling
IaC security tooling (Checkov tfsec OPA/Rego)

Job description

The Machine is the agentic operating system for marketing, built by Code & Theory. It plugs into the tools marketing teams use and turns disconnected workflows into a single intelligent system, connecting brand strategy, creative production, and media performance. The Machine helps power agencies across Stagwell's network and world‑leading brands.

We're looking for a Senior Security Engineer to be the hands‑on technical backbone of our security and compliance program across our SaaS products and client delivery work. This role would own the implementation — building the controls, tooling, automation, and processes that make our security program real. You'll work directly with engineering teams, embed into delivery workflows, and be the person who actually builds and runs the systems that keep our products and client data secure.

Our engineers are AI native and engage in and advance the state of the art in the practice of software development flow with AI.

WHAT YOU'LL DO
  • Build and maintain security controls across our cloud infrastructure and SaaS products — identity and access, encryption, logging, monitoring, secrets management, and multi‑tenancy patterns
  • Own the technical implementation of SOC 2 Type II, ISO 27001, and ISO 42001 compliance — building evidence pipelines, automating control testing, and maintaining audit artifacts
  • Instrument and operate security monitoring and alerting across cloud environments (GCP, AWS, and/or Azure), with hands‑on responsibility for threat detection, log aggregation, and response
  • Partner with engineering teams to embed security into CI/CD pipelines — vulnerability scanning, SAST/DAST tooling, dependency management, container security, and secure code review
  • Implement privacy controls in product and client environments, including data classification, retention, access controls, and audit logging aligned to HIPAA, GDPR, and CCPA/CPRA requirements
  • Execute the client engagement security model — provisioning and deprovisioning access, configuring environment segregation, and meeting client‑specific delivery security requirements
  • Conduct hands‑on vendor security assessments, reviewing third‑party architectures, configurations, and data handling practices
  • Maintain and test incident response playbooks; lead technical response and forensic analysis during security events
  • Build and maintain AI‑specific security controls — reviewing model inputs/outputs, securing agent workflows, managing prompt injection and data leakage risks in AI‑enabled products
  • Contribute to the security questionnaire and RFP response library, serving as the technical author for detailed customer assurance requests
WHAT YOU'LL NEED
  • 5+ years of hands‑on security engineering experience, ideally spanning SaaS product environments and/or professional services/agency delivery
  • Deep practical knowledge of cloud security in at least one major platform (GCP, AWS, or Azure) — IAM, networking, secrets management, logging, and security tooling
  • Hands‑on experience with SOC 2 Type II and ISO 27001 control implementation — not just familiarity with frameworks, but actually building and operating the controls
  • Experience building security automation across CI/CD pipelines — integrating vulnerability scanners, SAST/DAST tools, and policy enforcement into engineering workflows
  • Working knowledge of privacy regulations (HIPAA, GDPR, CCPA/CPRA) and experience implementing technical controls that operationalize compliance requirements
  • Proficiency with security monitoring and SIEM tooling — building detection logic, tuning alerts, and responding to incidents with real technical depth
  • Strong communication skills — you can explain a complex finding clearly to an engineer, a PM, or a client, and write a crisp, credible response to a security questionnaire
  • Comfort working across a distributed, fast‑moving organization with multiple concurrent workstreams
  • Experience working with AI‑enabled development tools and integrating security thinking into AI‑assisted workflows
  • Hands‑on experience reviewing and hardening AI agent workflows — understanding risks like prompt injection, data leakage, and model misuse in production systems
  • Comfortable leveraging AI‑enabled development tools and workflows to accelerate engineering, automation, debugging, and operational tasks
  • Experience orchestrating multi‑step AI or agent‑driven workflows, including selecting appropriate models, tools, and execution patterns for different use cases
  • Strong judgment reviewing and hardening AI‑assisted output for security, scalability, maintainability, and architectural fit
  • Experience building or maintaining prompts, evaluation frameworks, documentation, or operational context systems that improve engineering velocity and reliability
  • Familiarity with automated evaluation and feedback loops for AI‑enabled systems and workflows
NICE TO HAVE
  • Experience in agency, consultancy, or enterprise SaaS environments where you've had to meet varying client security requirements
  • Familiarity with ISO 42001 and AI governance frameworks
  • Experience securing multi‑tenant SaaS architectures at the infrastructure and application layer
  • Relevant certifications: CISSP, CCSP, AWS/GCP/Azure Security Specialty, CIPP, or similar
  • Experience with infrastructure‑as‑code security tooling (e.g., Checkov, tfsec, OPA/Rego)
ABOUT US

Born in 2001, Code and Theory is a digital‑first creative agency that sits at the center of creativity and technology. We pride ourselves on not only solving consumer and business problems, but also helping to establish new capabilities for our clients. With a global client roster of Fortune 100s and start‑ups alike, we crave the hardest problems to solve. We have teams distributed across North America, South America, Europe, and Asia. The Code and Theory global network of agencies is growing and includes Kettle, Instrument, Left Field Labs, Create Group, Current, and TrueLogic.

Striving never to be pigeonholed, we work across every major category: from tech to CPG, financial services to travel & hospitality, government and education to media and publishing. We value the collaboration with our client partners, including but not limited to Adidas, Amazon, Con Edison, Diageo, EY, J.P. Morgan Chase, Lenovo, Marriott, Mars, Microsoft, Thomson Reuters, and TikTok.

The Code and Theory network is comprised of nearly 2,000 people with 50% engineers and 50% creative talent. We’re always on the lookout for smart, driven, and forward‑thinking people to join our team.

The base compensation range for this role is $110,000 – $150,000 and spans multiple levels. We're open to hiring at the level that best matches the right candidate's experience. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, budget, and location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Engineer, Security & Compliance (US)
Senior Engineer, Security & Compliance (US)

twentysix • Austin (TX)

On-site
USD 110,000 - 150,000
Senior Engineer, DevOps (US)
Senior Engineer, DevOps (US)

Code and Theory • United States

On-site
USD 110,000 - 150,000
Agency experience
Cloud certifications
Senior Director, Principal Engineer
Senior Director, Principal Engineer

Code and Theory • Austin (TX)

On-site
USD 180,000 - 250,000
Senior Director, Principal Engineer
Senior Director, Principal Engineer

Code and Theory • San Francisco (CA)

On-site
USD 180,000 - 250,000
Senior Director, Principal Engineer
Senior Director, Principal Engineer

Code and Theory • New York (NY)

On-site
USD 180,000 - 250,000
Apply for Senior Director, Principal Engineer (US)
Apply for Senior Director, Principal Engineer (US)

Code and Theory • New York (NY)

On-site
USD 180,000 - 250,000
Apply for Senior Engineer, Full-stack (US)
Apply for Senior Engineer, Full-stack (US)

Code and Theory • New York (NY)

On-site
USD 110,000 - 160,000
Senior Engineer, Cloud Infrastructure (US)
Senior Engineer, Cloud Infrastructure (US)

twentysix • Austin (TX)

On-site
USD 110,000 - 150,000
Senior Director, Principal Engineer (US)
Senior Director, Principal Engineer (US)

Code and Theory • Austin (TX)

On-site
USD 180,000 - 250,000
Senior Engineer, Cloud Infrastructure
Senior Engineer, Cloud Infrastructure

Code and Theory • Austin (TX)

On-site
USD 110,000 - 150,000