Up Labs
Sr. Security Controls & Compliance Engineer (Contract)
USA · Senior
Sponsorship not specifiedDetected 15 days ago
Code ReviewGitAWSGCPAzureCI/CDCybersecuritySOC OperationsIncident ResponseComplianceJiraLogisticsLeadershipCommunicationCISSP
About the role
- This is a hands-on security execution role.
- The goal is a repeatable security baseline that each venture application can inherit, operate against, and carry forward as it matures or spins out into an independent company.
- Select, configure, and operate a compliance automation platform (evaluating options such as Vanta, Drata, or Secureframe), including evidence integrations across cloud, GitHub, identity providers, ticketing, device management, and productivity tools.
Responsibilities
- What You'll Own Given the contract timeline, you should expect to operate independently across both the technical implementation and the compliance and customer-facing sides of security.
- Specifically, you will: Build, implement, and operate security and compliance controls across multiple venture applications and supporting systems.
- Implement identity and access controls: SSO, MFA, role-based access, least privilege, access review workflows, and offboarding evidence.
- Implement operational security workflows: vendor review, risk review, change management, policy attestation, incident response evidence, exception tracking, and recurring control reviews.
- Support SOC 2 readiness end to end: control mapping, evidence requirements, gap tracking, audit prep, and control verification.
- Support customer security questionnaires, audits, evidence requests, and enterprise security reviews with accurate technical detail.
- Produce a repeatable security implementation playbook that future ventures can inherit, and support the handoff of a venture's security posture when it spins out.
Requirements
- 7+ years in security engineering, cloud security, DevSecOps, security operations, security compliance, or GRC, including hands-on control implementation in cloud/SaaS environments.
- Proven experience translating enterprise customer security requirements into practical technical controls.
- Hands-on experience with identity and access controls (SSO, MFA, RBAC, least privilege, access reviews, offboarding).
- Hands-on experience with secure SDLC controls (source control permissions, code review, branch protection, vulnerability management, dependency and secret scanning, change management evidence).
- Hands-on experience with cloud security controls (IAM, encryption, logging, monitoring, backups, network restrictions, alerting).
- Experience standing up and operating a compliance automation / GRC platform (e.g., Vanta, Drata, Secureframe) from scratch.
- Familiarity with our core stack: GitHub, Jira or Linear, Okta, Google Workspace, Slack, and a major cloud provider (AWS, Azure, or GCP).
Nice to have
- Experience in venture-backed startups, enterprise SaaS, or venture studio environments.
- Familiarity with SOC 2 Trust Services Criteria, ISO 27001, NIST CSF, or CIS Controls.
- Experience with GitHub security features, CI/CD security controls, vulnerability management tools, and cloud security monitoring.
- GitHub, Jira or Linear, Okta, Google Workspace, Slack, and a major cloud provider (AWS, Azure, or GCP).
- Strong written communication for policies, procedures, audit documentation, technical requirements, and customer-facing security responses.
Skills
- IAM policies, encryption settings, logging, monitoring, backups, network restrictions, and security alerting.
Company info
- We are not looking for someone who documents gaps, manages a compliance tool, and routes work to engineering.
- We are hiring a Senior Security Controls & Compliance Engineer on a 6+ month contract to build, implement, and operate the security control foundation across multiple venture applications.
Apply directly at Up Labs →Create a free account for alerts like thisView Up Labs immigration profile
This listing is sourced directly from Up Labs's careers page and normalized into a canonical job model.