Security & Compliance Lead

Posted 5 Days Ago
Be an Early Applicant
Scottsdale, AZ, USA
Hybrid
150K-190K Annually
Senior level
Blockchain • Energy • Cryptocurrency
The Role
Own the company’s security compliance program from defining SOC 2 scope through completing the first Type II audit. Responsibilities include readiness assessments, policy creation, continuous evidence collection, engineering remediation, auditor and penetration-test vendor management, security awareness training, vendor risk reviews, and ongoing annual audit operations.
Summary Generated by Built In
## Location: Remote (Global) HQ: Bellevue, WA ## Team: Engineering ## Type: Full-Time Deferred Compensation + Bonuses ## Reports To: Chief Technology Officer We are looking for a Security & Compliance Lead to take SunCore Digital to a SOC 2 attestation and own our security compliance program end to end. SOC 2 is an audit performed by an outside licensed firm; your job is everything that makes that audit succeed. You will define the audit scope with the CTO, assess where we stand today against the Trust Services Criteria across our web platform and mobile apps, close the gaps, and manage the auditor relationship through to the final report. You will write the policies, stand up continuous evidence collection, and coordinate the technical work with our engineers, who implement the controls in code and infrastructure. This is an ownership role with checks built in: scope, spend, and major control decisions are approved by the CTO, and your program is expected to hold up under challenge from the engineers who live with it every day. This is a remote-first role with deferred compensation until 60 days post-MVP launch, plus equity, bonuses, and annual offsite perks. We value speed, ownership, and collaborative energy. ## What You'll Do - Define the SOC 2 audit scope with the CTO: which Trust Services Criteria we attest to, and whether we pursue a Type I report, a Type II report, or both in sequence - Run a readiness assessment across the web platform, the mobile apps, our infrastructure, and our vendors, and publish the gap list with owners and dates - Author and maintain the policy set: access control, change management, incident response, vendor management, business continuity, and data handling - Select and deploy a compliance automation platform so evidence is collected continuously by systems rather than assembled by hand before the audit - Coordinate remediation with engineering: you define each control and the evidence it must produce, engineers implement it, and you verify it works - Select the licensed CPA firm, negotiate the engagement, and manage the audit from kickoff through the observation window to the final report - Run security awareness training and the onboarding and offboarding controls for the whole company, not just engineering - Stand up vendor risk review for the third-party services the platform depends on - Coordinate the penetration test: vendor selection, scoping, scheduling, and tracking findings to closure - Report status, risks, and audit blockers directly to the CTO in plain language - After the first report: own the annual audit cycle and keep evidence collection continuous, so the second year is routine instead of a scramble ## What You Bring - 7+ years in information security or governance, risk, and compliance, including at least one SOC 2 program taken from no report to a completed Type II as the internal owner, not as an outside consultant who left before the audit - Working command of the Trust Services Criteria and how auditors actually test them, including mapping controls to the evidence that proves them - Hands-on experience deploying a compliance automation platform such as Vanta, Drata, or Secureframe - Enough technical depth to hold your own with engineers: you can read an architecture diagram, understand cloud access models, CI/CD pipelines, and mobile release processes, and tell a real control from a paper one - Policy writing that people actually follow: short, specific, and enforceable - Experience scoping and managing external auditors and penetration test vendors - A track record of getting compliance work done through engineers you do not manage - Clear written communication, since the audit is won or lost in documents - Bonus: experience in fintech or digital assets, or extending a program beyond SOC 2 into ISO 27001 or privacy regimes such as GDPR and CCPA ## Compensation & Benefits - Competitive pay range: - Offshore mid-senior rates: - Deferred compensation model: All development team compensation is deferred until 60 days post-MVP launch to align incentives, everyone is focused on shipping fast - Annual performance bonus (significant portion of total comp) - Milestone bonuses tied to product delivery - Health, dental, and vision plans for U.S.-based hires - Annual paid offsite (Caribbean, Hawaii, ski destinations) ## Why Join Us You will build our security compliance program from its foundation and take the company to its first SOC 2 report, with a direct line to the CTO and engineers who treat security findings as work to do rather than criticism to deflect. If owning a program end to end, from scope to signed report, is the kind of work you want, we would love to meet you. ## Apply now or reach out directly to [[email protected]](mailto:[email protected])

Skills Required

  • 7+ years of experience in information security or governance, risk, and compliance
  • Completed at least one SOC 2 Type II program from no report to final report as the internal owner
  • Working knowledge of the SOC 2 Trust Services Criteria and auditor evidence testing
  • Hands-on experience deploying a compliance automation platform such as Vanta, Drata, or Secureframe
  • Technical understanding of architecture diagrams, cloud access models, CI/CD pipelines, and mobile release processes
  • Experience writing concise, specific, and enforceable security policies
  • Experience managing external auditors and penetration testing vendors
  • Experience delivering compliance work through engineers without direct management authority
  • Clear written communication skills
  • Experience in fintech or digital assets
  • Experience extending compliance programs into ISO 27001, GDPR, or CCPA
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
Year Founded: 2025

What We Do

SunCore Digital is a blockchain services company specializing in the development of digital infrastructure for cryptocurrency mining. The company provides a dependable energy platform to power mining equipment and offers users long-term rights to mine, focusing on accelerating the build-out of digital infrastructure to support the blockchain ecosystem.

Similar Jobs

In-Office
Sedona, AZ, USA
121228 Employees
Remote or Hybrid
2 Locations
175633 Employees
167K-280K Annually
Remote or Hybrid
2 Locations
175633 Employees
150K-250K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

APD - Rideshare Commercial Claims Auto Physical Damage Adjuster

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
10 Locations
40000 Employees
46K-84K Annually

Similar Companies Hiring

Runwise Thumbnail
Greentech • Hardware • Real Estate • Software • Energy • PropTech
New York, NY
199 Employees
Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
150 Employees
Formance Thumbnail
Blockchain • Fintech • Payments • Software • Financial Services • Cryptocurrency
New York, New York
34 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account