Greenboard
Senior DevSecOps Engineer
New York City · Senior
Sponsorship not specified$185k-$260kDetected 104 days ago
Code ReviewAWSCI/CDCybersecurityComplianceResearchCommunicationBurp Suite
About the role
- You'll be the first dedicated security hire on our engineering team, which means you'll have a direct hand in shaping how we think about security - from compliance frameworks and vendor diligence to infrastructure hardening and secure development practices.
- This is a high-impact, high-autonomy role.
Responsibilities
- Detect, triage, and drive remediation of vulnerabilities across the stack - infrastructure, application, and network.
- Manage third-party penetration tests and coordinate internal response to findings.
- Own credential and secrets management, including rotation policies, vault configuration, and access controls.
- Manage infrastructure patching and hardening, working with engineering to keep systems current without disrupting delivery.
- Own our SOC 2 compliance program end-to-end, including audit preparation, evidence collection, and remediation tracking.
- Maintain and mature our GDPR compliance posture, partnering with legal and product to ensure data protection requirements are met.
- Manage inbound security diligence requests that arise during client sales processes - completing questionnaires, coordinating evidence, and joining calls as needed.
- Build and maintain a vendor security review process for evaluating third-party tools and services before they're adopted.
- Maintain a library of up-to-date security documentation (policies, SOC 2 reports, architecture diagrams) to accelerate deal cycles.
- Manage endpoint security across the company - MDM, disk encryption, OS patching, and device compliance policies.
Requirements
- 3-7 years of experience in security engineering, application security, or infrastructure security roles.
- Hands-on experience with SOC 2 audits and at least one other compliance framework (GDPR, ISO 27001, PCI-DSS, or similar).
- Experience with vulnerability management tooling (e.g., Snyk, Semgrep, Qualys, Burp Suite, or equivalents).
- Familiarity with AWS Secrets Manager and IAM best practices.
- Experience managing or coordinating third-party pentests.
- Clear, low-ego communication style - you can explain a risk to an engineer and a compliance requirement to a salesperson with equal clarity.
- Comfort with ambiguity and ownership.
- Lead our ISO 42001 certification efforts, establishing and maintaining the required AI management system controls.
- Research and implement additional compliance frameworks as we expand into new markets, acting as the internal authority on what's required and when.
Nice to have
- Prior experience at a fintech or other regulated-industry startup.
- Familiarity with ISO 42001 or AI governance frameworks.
- Experience with MDM platforms
- Background supporting international expansion from a security/compliance perspective.
Skills
- Greenboard is the unified, AI-native compliance operating system for RIAs, fintechs, private funds, hedge funds, and more.
- It replaces the fragmented mix of legacy tools and automates more than previously possible.
Compensation
- 10 remote days per year plus additional around the holidays
- Bi-annual off-sites and team retreats
- $185,000-$260,000 + meaningful equity
Benefits
- Salary range: $185,000-$260,000 + meaningful equity
- Medical, dental, and vision coverage
- 15 days PTO + 11 company holidays + flexible sick time
- 2 additional PTO days for each year of service (up to 10 additional days)
Company info
- You'll work closely with engineering, product, and business teams to make sure we're building securely, meeting the compliance bar our fintech customers expect, and staying ahead of threats as we expand internationally.
Apply directly at Greenboard →Create a free account for alerts like thisView Greenboard immigration profile
This listing is sourced directly from Greenboard's careers page and normalized into a canonical job model.