Up Labs

Up Labs

Sr. Security Controls & Compliance Engineer (Contract)

USA · Senior

Sponsorship not specifiedDetected 15 days ago
Code ReviewGitAWSGCPAzureCI/CDCybersecuritySOC OperationsIncident ResponseComplianceJiraLogisticsLeadershipCommunicationCISSP

About the role

  • This is a hands-on security execution role.
  • The goal is a repeatable security baseline that each venture application can inherit, operate against, and carry forward as it matures or spins out into an independent company.
  • Select, configure, and operate a compliance automation platform (evaluating options such as Vanta, Drata, or Secureframe), including evidence integrations across cloud, GitHub, identity providers, ticketing, device management, and productivity tools.

Responsibilities

  • What You'll Own Given the contract timeline, you should expect to operate independently across both the technical implementation and the compliance and customer-facing sides of security.
  • Specifically, you will: Build, implement, and operate security and compliance controls across multiple venture applications and supporting systems.
  • Implement identity and access controls: SSO, MFA, role-based access, least privilege, access review workflows, and offboarding evidence.
  • Implement operational security workflows: vendor review, risk review, change management, policy attestation, incident response evidence, exception tracking, and recurring control reviews.
  • Support SOC 2 readiness end to end: control mapping, evidence requirements, gap tracking, audit prep, and control verification.
  • Support customer security questionnaires, audits, evidence requests, and enterprise security reviews with accurate technical detail.
  • Produce a repeatable security implementation playbook that future ventures can inherit, and support the handoff of a venture's security posture when it spins out.

Requirements

  • 7+ years in security engineering, cloud security, DevSecOps, security operations, security compliance, or GRC, including hands-on control implementation in cloud/SaaS environments.
  • Proven experience translating enterprise customer security requirements into practical technical controls.
  • Hands-on experience with identity and access controls (SSO, MFA, RBAC, least privilege, access reviews, offboarding).
  • Hands-on experience with secure SDLC controls (source control permissions, code review, branch protection, vulnerability management, dependency and secret scanning, change management evidence).
  • Hands-on experience with cloud security controls (IAM, encryption, logging, monitoring, backups, network restrictions, alerting).
  • Experience standing up and operating a compliance automation / GRC platform (e.g., Vanta, Drata, Secureframe) from scratch.
  • Familiarity with our core stack: GitHub, Jira or Linear, Okta, Google Workspace, Slack, and a major cloud provider (AWS, Azure, or GCP).

Nice to have

  • Experience in venture-backed startups, enterprise SaaS, or venture studio environments.
  • Familiarity with SOC 2 Trust Services Criteria, ISO 27001, NIST CSF, or CIS Controls.
  • Experience with GitHub security features, CI/CD security controls, vulnerability management tools, and cloud security monitoring.
  • GitHub, Jira or Linear, Okta, Google Workspace, Slack, and a major cloud provider (AWS, Azure, or GCP).
  • Strong written communication for policies, procedures, audit documentation, technical requirements, and customer-facing security responses.

Skills

  • IAM policies, encryption settings, logging, monitoring, backups, network restrictions, and security alerting.

Company info

  • We are not looking for someone who documents gaps, manages a compliance tool, and routes work to engineering.
  • We are hiring a Senior Security Controls & Compliance Engineer on a 6+ month contract to build, implement, and operate the security control foundation across multiple venture applications.

This listing is sourced directly from Up Labs's careers page and normalized into a canonical job model.