Overstory

Overstory

Overstory uses AI and satellite imagery to prevent wildfires and power outages by analyzing vegetation for electric utilities.

Utilities
11-50
Founded 2018
$25M raised

Description

  • Own and continuously improve Overstory’s compliance program, maintaining alignment with SOC 2, ISO 27001, and related frameworks.
  • Drive end-to-end vulnerability management, including detection, remediation prioritization, and coordination with engineering teams.
  • Design and improve security processes and controls across infrastructure, applications, and internal systems.
  • Provide security input on architecture and engineering decisions to help teams build secure-by-design systems.
  • Oversee identity and access management, endpoint security, and core IT security practices.
  • Own vendor security and third-party risk management, including assessments, risk evaluation, and mitigation planning.
  • Lead audit readiness and execution for SOC 2 and ISO 27001, including evidence collection and auditor coordination.
  • Partner with customer-facing teams to respond to security questionnaires and improve response workflows.
  • Contribute to security awareness and culture by mentoring others and raising the organization’s security standards.

Requirements

  • 5+ years of experience in security engineering, security operations, or a related field.
  • Direct experience with security and compliance frameworks such as SOC 2 and/or ISO 27001, including audit processes.
  • Deep experience with vulnerability management, including tooling, prioritization, and remediation workflows.
  • Experience working across cloud environments such as AWS, GCP, or Azure and modern SaaS ecosystems.
  • Experience with identity and access management, endpoint security, and IT/security operations.
  • Ability to translate security risks into clear, actionable guidance for both technical and non-technical stakeholders.
  • Demonstrable experience or strong interest in using AI tooling to accelerate business impact.
  • Strong written communication skills and comfort owning documentation and audit artifacts.
  • A proactive, pragmatic mindset with the ability to balance security best practices and business needs.
  • Experience influencing cross-functionally in a remote-first environment without formal authority.
  • Experience designing or improving SIEM, logging, and alerting pipelines is a plus.
  • Familiarity with compliance automation platforms such as Drata, Vanta, or Tugboat is a plus.
  • Experience leading or owning SOC 2 / ISO 27001 audits is a plus.
  • Background in application security or cloud security engineering is a plus.
  • Experience mentoring or guiding more junior team members is a plus.
  • Ability to work in Eastern North America time zones (NST, AST, EST).

Benefits

  • Competitive, location-specific compensation and benefits.
  • Flexible, autonomous, and collaborative working environment built on trust.
  • Home office stipend.
  • Coworking budget.
  • Ongoing education budget.
  • Mission-driven work focused on reducing wildfires and supporting climate resilience.
  • Remote work with the option for occasional in-person collaboration.
  • Annual in-person team gathering event.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer

Lever 251-1K Professional Services

Latitude is hiring a fully remote Senior Security Engineer to lead security architecture, authorization, and risk remediation for supply chain and logistics software supporting a federal health customer.

Agile AWS Azure HIPAA
37 minutes ago

Security Engineer

Lever 251-1K Professional Services

Latitude is hiring a fully remote Security Engineer to secure supply-chain and logistics software for a federal health customer by designing controls, integrating security into delivery processes, and validating changes for safe release.

CI/CD HIPAA
37 minutes ago

MEDR Threat Engineer US work hours

Proficio 51-250 Professional Services

Proficio is seeking a Managed EDR Threat Engineer to guide the evolution of its managed endpoint detection, response, visibility, and prevention services while collaborating with engineering, SOC, MDR, sales, and customer teams.

Carbon Black Cybersecurity Linux macOS Network Security PowerShell Python
2 days ago

DevSecOps and Security Compliance Engineer

K.L. Scott & Associates 11-50 Professional Services

K.L. Scott & Associates, LLC is hiring a DevSecOps and Security Compliance Engineer to integrate security into SAP delivery and operations for federal clients while improving deployment controls, addressing vulnerabilities, and maintaining authorization evidence.

CI/CD DevSecOps SAP Secrets Management
2 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers