EngineerJobs.io
← Back to all jobs

Job Description

Flash AI is hiring a hands-on Security Engineer to own security and compliance across the organization, with primary accountability for CJIS and SOC 2. This role manages compliance readiness through Vanta, leads audit and evidence workflows, and partners closely with engineering to keep the application and AWS environment secure.

Responsibilities

  • Own SOC 2 and CJIS compliance end to end, maintaining continuous readiness, running the annual SOC 2 audit cycle, and ensuring alignment with the CJIS Security Policy requirements for handling criminal justice information.
  • Administer Vanta as the source of truth for the compliance posture by managing automated control tests, resolving failing tests, keeping integrations healthy, and serving as the primary contact for auditors and customer security reviews.
  • Maintain and keep current the security documentation set, including policies, procedures, a risk register, access reviews, and incident response plans as the platform evolves.
  • Drive vulnerability and supply-chain management by tracking dependency and container vulnerabilities from scanning tools, prioritizing based on real risk, pushing findings to closure within SLA, and coordinating third-party penetration tests through remediation.
  • Triage application security findings and work with engineering to implement fixes by routing findings from scanners, pen tests, and external reviews to the appropriate owners and following them to closure.
  • Over time, take on additional review responsibilities directly.
  • Partner with engineering to harden the AWS environment by tracking IAM, networking, KMS (encryption), and logging posture, flagging misconfigurations and drift, and helping improve alerting and incident response.

Requirements

  • 3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibility.
  • Hands-on experience with a compliance framework such as SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS, including audit preparation and evidence management.
  • Working knowledge of AWS security fundamentals: IAM, VPC networking, KMS, and CloudTrail.
  • Ability to read code in Python or TypeScript/JavaScript to understand a security finding and discuss remediation with engineers.
  • Familiarity with vulnerability management and dependency scanning tooling.
  • Strong writing and organization skills, with documentation that can withstand audit scrutiny.
  • Must reside in the United States and be able to pass state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information.

Technologies

  • Vanta, SOC 2, CJIS, ISO 27001, FedRAMP, HIPAA
  • AWS, IAM, VPC, KMS, CloudTrail
  • Python, TypeScript, JavaScript

Nice to Have

  • Direct CJIS Security Policy experience, or experience supporting government and public-sector customers.
  • Experience administering Vanta, Drata, Secureframe, or a comparable GRC platform.
  • Experience independently reviewing code or system designs for issues such as broken auth, injection, access control and multi-tenancy boundaries, or secrets handling.
  • Security certifications including Security+, AWS Security Specialty, CCSP, CISSP, or OSCP.
  • Experience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform).
  • Experience securing data pipelines or ML/AI systems that handle sensitive data.

Benefits

  • Paid time off

Location

Remote (remote)

Compensation

USD 120,000 per year (from $120,000.00 per year)

Similar Jobs