Security Engineer
Amazon Web Services
Application Security
Aws Iam
Cjis Compliance
Cloud
Cloud Computing
Cloud Platforms
Cloud Security
Cloud Security Assurance
Compliance Audits
Data Security
Identity and Access Management
Incident Response
Information Security
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Soc 2
Job Description
Flash AI is hiring a hands-on Security Engineer to own security and compliance across the organization, with primary accountability for CJIS and SOC 2. This role manages compliance readiness through Vanta, leads audit and evidence workflows, and partners closely with engineering to keep the application and AWS environment secure.
Responsibilities
- Own SOC 2 and CJIS compliance end to end, maintaining continuous readiness, running the annual SOC 2 audit cycle, and ensuring alignment with the CJIS Security Policy requirements for handling criminal justice information.
- Administer Vanta as the source of truth for the compliance posture by managing automated control tests, resolving failing tests, keeping integrations healthy, and serving as the primary contact for auditors and customer security reviews.
- Maintain and keep current the security documentation set, including policies, procedures, a risk register, access reviews, and incident response plans as the platform evolves.
- Drive vulnerability and supply-chain management by tracking dependency and container vulnerabilities from scanning tools, prioritizing based on real risk, pushing findings to closure within SLA, and coordinating third-party penetration tests through remediation.
- Triage application security findings and work with engineering to implement fixes by routing findings from scanners, pen tests, and external reviews to the appropriate owners and following them to closure.
- Over time, take on additional review responsibilities directly.
- Partner with engineering to harden the AWS environment by tracking IAM, networking, KMS (encryption), and logging posture, flagging misconfigurations and drift, and helping improve alerting and incident response.
Requirements
- 3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibility.
- Hands-on experience with a compliance framework such as SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS, including audit preparation and evidence management.
- Working knowledge of AWS security fundamentals: IAM, VPC networking, KMS, and CloudTrail.
- Ability to read code in Python or TypeScript/JavaScript to understand a security finding and discuss remediation with engineers.
- Familiarity with vulnerability management and dependency scanning tooling.
- Strong writing and organization skills, with documentation that can withstand audit scrutiny.
- Must reside in the United States and be able to pass state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information.
Technologies
- Vanta, SOC 2, CJIS, ISO 27001, FedRAMP, HIPAA
- AWS, IAM, VPC, KMS, CloudTrail
- Python, TypeScript, JavaScript
Nice to Have
- Direct CJIS Security Policy experience, or experience supporting government and public-sector customers.
- Experience administering Vanta, Drata, Secureframe, or a comparable GRC platform.
- Experience independently reviewing code or system designs for issues such as broken auth, injection, access control and multi-tenancy boundaries, or secrets handling.
- Security certifications including Security+, AWS Security Specialty, CCSP, CISSP, or OSCP.
- Experience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform).
- Experience securing data pipelines or ML/AI systems that handle sensitive data.
Benefits
- Paid time off
Location
Remote (remote)
Compensation
USD 120,000 per year (from $120,000.00 per year)