Security & Compliance Engineer

1 month, 4 weeks ago
Full-time
Mid Level
DevOps and Infrastructure
Grant Street Group

Grant Street Group

Grant Street Group specializes in providing innovative cloud-based software solutions for tax collection, electronic payments, and auction services, aimed at enhancing the efficiency and effectiveness of government operations across various levels.

IT Services
251-1K
Founded 1997

Description

  • Support the day-to-day security posture of systems and services across cloud and on-prem environments.
  • Review vulnerability findings from scanners, penetration tests, and other assessments and drive remediation to closure.
  • Partner with infrastructure, platform, and engineering teams on secure configuration, access control, logging, monitoring, and incident readiness.
  • Support compliance and assessment activities related to GovRAMP/FedRAMP, PCI DSS, internal reviews, and third-party examinations.
  • Use AWS security tooling and help translate security and compliance requirements into practical operational outcomes.
  • Maintain documentation, procedures, and other operational artifacts so they remain aligned with the environment and control expectations.
  • Track remediation efforts, control monitoring, and audit-related follow-up across teams.
  • Contribute to security log management and monitoring processes.

Requirements

  • 3+ years of experience in security engineering, security operations, infrastructure security, or security compliance.
  • Hands-on experience working in Linux-based production environments and securing Linux systems.
  • Experience securing AWS environments and using services such as IAM, CloudTrail, GuardDuty, Security Hub, Config, Inspector, and KMS.
  • Working knowledge of vulnerability management, configuration management, logging, monitoring, access control, and incident response practices.
  • Scripting experience in Python, Bash, PowerShell, or similar for automation, security operations, and reporting tasks.
  • Strong written and verbal communication skills with the ability to move issues from discovery through remediation across multiple teams.
  • Experience supporting regulated or highly audited environments is a plus.
  • Familiarity with GovRAMP, FedRAMP, PCI DSS, SOC examinations, or similar frameworks is a plus.
  • Experience reviewing scanner output, penetration test findings, or security monitoring alerts and helping drive remediation is a plus.
  • Familiarity with POA&M tracking, exception handling, and remediation coordination is a plus.
  • Experience working across both cloud and legacy infrastructure is a plus.
  • Comfort using AI tools responsibly to support triage, investigation, scripting, documentation, and reporting is a plus.
  • Experience with security data lakes, OCSF schema management, or security data transformation pipelines is a plus.
  • Expected salary range of $100,000–$160,000 per year.

Benefits

  • Minimal travel, typically 2-3 weeks per year for on-site meetings.
  • Technology-rich work environment with strong collaboration tools.
  • Opportunity to work with an entrepreneurial, high-performing team.
  • Supportive culture that values teamwork, professional excellence, and individual responsibility.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Detection Engineer

DoorDash 10K-50K Air Freight & Logistics

DoorDash is hiring a Senior Detection Engineer to help build and operate detection engineering for its global cyber defense function across DoorDash, Deliveroo, and Wolt.

Go Python SIEM Snowflake SQL
1 day, 3 hours ago

Staff Security Engineer

Redox 51-250 Internet Software & Services

Redox is hiring a Staff Security Engineer to own cloud-native and application security for its remote healthcare data exchange platform, with a focus on hardening systems and driving secure-by-default engineering practices.

Argo CD AWS CI/CD CrowdStrike Docker GitHub Actions Go HashiCorp Vault Helm Kafka Kubernetes LLM Node.js PostgreSQL Python Redis Terraform TypeScript
1 day, 4 hours ago

Senior Information Security Engineer

KPA 251-1K Professional Services

KPA is hiring a Senior Information Security Engineer to own and improve its technical security platforms, cloud and identity security, and incident response efforts across a modern enterprise environment.

AWS AWS SES Azure CI/CD CrowdStrike DevSecOps Kubernetes Linux Network Security Penetration Testing PowerShell Python REST API SendGrid
1 day, 4 hours ago

IAM Architect - Saviynt

IDMWORKS 51-250 Professional Services

IDMWORKS is hiring an IAM Architect - Saviynt to design and deliver identity and access management solutions that strengthen security and support access control across enterprise environments.

Active Directory Cybersecurity OAuth SAML
1 day, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers