Up Labs Inc. logo

Sr. Security Controls & Compliance Engineer

Job Overview

Location

Remote

Job Type

Full-time

Category

Engineering

Date Posted

July 10, 2026

Full Job Description

đź“‹ Description

  • • We are hiring a Sr. Security Controls & Compliance Engineer to build, implement, and operate the security control foundation across multiple applications in a venture studio environment.
  • • This is a hands-on security execution role. We are not looking for someone who only documents gaps, manages a compliance tool, or routes work to engineering.
  • • We need someone who can understand enterprise customer security requirements, identify the controls required, implement or configure those controls directly where possible, and verify that they are operating effectively.
  • • This person will help prepare our venture applications for SOC 2 readiness while supporting enterprise customer data, information security, and TPRM requirements.
  • • They will work across cloud environments, identity systems, source control, CI/CD workflows, logging, monitoring, compliance tooling, and operational security processes.
  • • The goal is to create a repeatable security baseline that each venture application can inherit, operate against, and eventually carry forward as it matures or spins out.
  • • Responsibilities include building, implementing, and operating security and compliance controls across multiple venture applications and supporting systems.
  • • Translating enterprise customer security, data handling, and TPRM requirements into practical technical controls, operational workflows, evidence requirements, and remediation plans.
  • • Creating a reusable security control baseline that can be applied across current and future venture applications.
  • • Configuring and operating compliance automation platforms such as Vanta, Drata, Secureframe, or similar tools.
  • • Configuring evidence integrations across systems such as cloud platforms, GitHub, identity providers, ticketing systems, device management tools, productivity platforms, and security tooling.
  • • Implementing identity and access controls, including SSO, MFA, role-based access, least-privilege permissions, access review workflows, and offboarding evidence.
  • • Implementing secure SDLC controls, including branch protection, required code reviews, code scanning, dependency scanning, secret scanning, vulnerability management workflows, and release/change management evidence.
  • • Implementing or configuring cloud security controls, including IAM policies, encryption settings, logging, monitoring, backup settings, network restrictions, and security alerting.
  • • Implementing operational security workflows, including vendor review, risk review, change management, policy attestation, incident response evidence, exception tracking, and recurring control reviews.
  • • Maintaining a centralized control library mapped to SOC 2 Trust Services Criteria, customer-specific requirements, and relevant frameworks such as ISO 27001, NIST CSF, or CIS Controls.
  • • Supporting SOC 2 readiness activities, including control mapping, evidence requirements, gap tracking, audit preparation, and control verification.
  • • Identifying launch-blocking security gaps and closing them directly where possible.
  • • Partnering with product engineering only where application-specific code, architecture, or deeper infrastructure changes are required.
  • • Writing clear technical requirements and acceptance criteria for any security work that must be completed by product engineering.
  • • Reviewing and verifying control implementation to ensure controls are actually operating and producing evidence.
  • • Supporting customer security questionnaires, audits, evidence requests, and enterprise security reviews with accurate technical detail.
  • • Tracking control gaps, remediation status, launch blockers, and compliance risk for leadership.
  • • Helping create a repeatable security implementation playbook that future ventures can inherit as they mature or spin out.
  • • What success looks like includes enterprise customer requirements being translated into implemented controls, not just documented gaps.
  • • Each venture application having a working security baseline across identity, cloud, source control, CI/CD, logging, monitoring, evidence, and operational processes.
  • • SOC 2 readiness being actively tracked with clear control ownership, evidence collection, and operating cadence.
  • • Compliance tooling being configured and producing useful evidence across the required systems.
  • • Engineering teams not being overloaded with generic security tasks; they are engaged only when product-specific implementation is required.
  • • Security launch blockers being identified early, prioritized clearly, and remediated quickly.
  • • Customer security reviews, audits, and questionnaires being handled with accurate technical detail and supporting evidence.
  • • Leadership having clear visibility into control maturity, launch risk, audit readiness, and open remediation items.
  • • The venture studio having a reusable security control baseline that can be applied to new applications and carried forward as ventures mature.

🎯 Requirements

  • • 5+ years of experience in security engineering, cloud security, DevSecOps, security operations, security compliance, GRC, or a related field.
  • • Hands-on experience implementing security controls in cloud/SaaS application environments.
  • • Experience supporting SOC 2 readiness, SOC 2 audits, or similar compliance programs.
  • • Strong understanding of security controls, audit evidence, policy requirements, control testing, and control operation.
  • • Experience translating customer or enterprise security requirements into practical technical controls.
  • • Ability to configure and operate security and compliance systems directly, not just document requirements.
  • • Experience with identity and access controls, including SSO, MFA, RBAC, least privilege, access reviews, and offboarding controls.
  • • Experience with secure SDLC controls, including source control permissions, code reviews, branch protection, vulnerability management, dependency scanning, secret scanning, and change management evidence.
  • • Experience with cloud security controls such as IAM, encryption, logging, monitoring, backups, network restrictions, and alerting.
  • • Experience with compliance automation or GRC tools such as Vanta, Drata, Secureframe, OneTrust, Tugboat Logic, or similar platforms.
  • • Familiarity with tools such as GitHub, Jira, Linear, Okta, Google Workspace, Slack, AWS, Azure, GCP, or similar systems.
  • • Strong written communication skills for policies, procedures, audit documentation, technical requirements, and customer-facing security responses.
  • • Ability to operate in an ambiguous, fast-moving startup or venture environment.

🏖️ Benefits

  • • Competitive salary and benefits package.
  • • Opportunity to work with a fast-growing and innovative company.
  • • Collaborative and dynamic work environment.
  • • Professional development and growth opportunities.
  • • Flexible work arrangements, including remote work options.
  • • Access to cutting-edge technology and tools.
  • • Recognition and rewards for outstanding performance.

Skills & Technologies

AWS
Azure
GCP
GitHub
Senior
Remote

Ready to Apply?

You will be redirected to an external site to apply.

AI Job Fit Analysis
Pro

See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.

Up Labs Inc. logo
Up Labs Inc.
Visit Website

About Up Labs Inc.

Up Labs is a digital product studio that specializes in building custom software solutions for businesses. They focus on creating user-centric applications, websites, and mobile apps that drive growth and innovation. Their services include product strategy, UI/UX design, front-end and back-end development, and ongoing support. Up Labs works with startups and established companies across various industries, helping them transform ideas into successful digital products. They emphasize collaboration, agile methodologies, and a commitment to delivering high-quality, scalable solutions tailored to each client's unique needs and objectives.

Get more remote jobs like this

Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.

Newsletter

Weekly remote jobs and featured talent.

No spam. Only curated remote roles and product updates. You can unsubscribe anytime.

Similar Opportunities

Dubai
Full-time
Expires Sep 14, 2026
Python
REST
Senior
+1 more

8 days ago

Remote - Munro, Argentina
Full-time
Expires Sep 2, 2026
Remote

19 days ago

Argentina
Full-time
Expires Sep 12, 2026
Python
TypeScript
AWS
+4 more

10 days ago

Expires soon
Argentina
Full-time
Expires Jul 27, 2026 (Soon)
Python
JavaScript
TypeScript
+4 more

2 months ago