
Job Overview
Location
Remote
Job Type
Full-time
Category
Cybersecurity
Date Posted
July 9, 2026
Full Job Description
đź“‹ Description
- • Build, implement, and operate security and compliance controls across multiple venture applications and supporting systems.
- • Translate enterprise customer security, data handling, and TPRM requirements into practical technical controls, operational workflows, evidence requirements, and remediation plans.
- • Create a reusable security control baseline that can be applied across current and future venture applications.
- • Select, configure, and operate a compliance automation platform (evaluating options such as Vanta, Drata, or Secureframe), including evidence integrations across cloud, GitHub, identity providers, ticketing, device management, and productivity tools.
- • Implement identity and access controls: SSO, MFA, role-based access, least privilege, access review workflows, and offboarding evidence.
- • Implement secure SDLC controls: branch protection, required code reviews, code scanning, dependency scanning, secret scanning, vulnerability management, and release/change management evidence.
- • Implement cloud security controls: IAM policies, encryption settings, logging, monitoring, backups, network restrictions, and security alerting.
- • Implement operational security workflows: vendor review, risk review, change management, policy attestation, incident response evidence, exception tracking, and recurring control reviews.
- • Maintain a centralized control library mapped to SOC 2 Trust Services Criteria, customer-specific requirements, and relevant frameworks (ISO 27001, NIST CSF, CIS Controls).
- • Support SOC 2 readiness end to end: control mapping, evidence requirements, gap tracking, audit prep, and control verification.
- • Identify launch-blocking security gaps and close them directly where possible.
- • Partner with product engineering only where application-specific code, architecture, or deeper infrastructure changes are required, writing clear technical requirements and acceptance criteria for that work.
- • Support customer security questionnaires, audits, evidence requests, and enterprise security reviews with accurate technical detail.
- • Track control gaps, remediation status, launch blockers, and compliance risk for leadership.
- • Produce a repeatable security implementation playbook that future ventures can inherit, and support the handoff of a venture's security posture when it spins out.
🎯 Requirements
- • 7+ years in security engineering, cloud security, DevSecOps, security operations, security compliance, or GRC, including hands-on control implementation in cloud/SaaS environments.
- • At least one full SOC 2 readiness-through-audit cycle owned or driven end to end.
- • Demonstrated ability to configure and operate security and compliance systems directly, not just document requirements.
- • Strong command of security controls, audit evidence, policy requirements, control testing, and control operation.
- • Proven experience translating enterprise customer security requirements into practical technical controls.
- • Hands-on experience with identity and access controls (SSO, MFA, RBAC, least privilege, access reviews, offboarding).
- • Hands-on experience with secure SDLC controls (source control permissions, code review, branch protection, vulnerability management, dependency and secret scanning, change management evidence).
- • Hands-on experience with cloud security controls (IAM, encryption, logging, monitoring, backups, network restrictions, alerting).
- • Experience standing up and operating a compliance automation / GRC platform (e.g., Vanta, Drata, Secureframe) from scratch.
- • Familiarity with our core stack: GitHub, Jira or Linear, Okta, Google Workspace, Slack, and a major cloud provider (AWS, Azure, or GCP).
- • Strong written communication for policies, procedures, audit documentation, technical requirements, and customer-facing security responses.
- • Ability to operate independently in an ambiguous, fast-moving venture environment and deliver on a compressed timeline.
🏖️ Benefits
- • Competitive hourly rate
- • Opportunity to work with a venture studio that builds and launches vertical AI enterprise SaaS companies
- • Collaborative and dynamic work environment
- • Flexible work arrangements
- • Professional development opportunities
Skills & Technologies
See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.
About Up Labs Inc.
Up Labs is a digital product studio that specializes in building custom software solutions for businesses. They focus on creating user-centric applications, websites, and mobile apps that drive growth and innovation. Their services include product strategy, UI/UX design, front-end and back-end development, and ongoing support. Up Labs works with startups and established companies across various industries, helping them transform ideas into successful digital products. They emphasize collaboration, agile methodologies, and a commitment to delivering high-quality, scalable solutions tailored to each client's unique needs and objectives.
Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.
Newsletter
Weekly remote jobs and featured talent.
No spam. Only curated remote roles and product updates. You can unsubscribe anytime.
Similar Opportunities

Arctic Wolf Networks, Inc.
3 months ago

Jasper AI, Inc.
3 months ago

Arctic Wolf Networks, Inc.
2 months ago

EverCommerce Inc.
3 months ago