Overstory

Overstory

Overstory uses AI and satellite imagery to prevent wildfires and power outages by analyzing vegetation for electric utilities.

Utilities
11-50
Founded 2018
$25M raised

Description

  • Own and continuously improve Overstory’s compliance program, maintaining alignment with SOC 2, ISO 27001, and related frameworks.
  • Drive end-to-end vulnerability management, including detection, remediation prioritization, and coordination with engineering teams.
  • Design and improve security processes and controls across infrastructure, applications, and internal systems.
  • Provide security input on architecture and engineering decisions to help teams build secure-by-design systems.
  • Oversee identity and access management, endpoint security, and core IT security practices.
  • Own vendor security and third-party risk management, including assessments, risk evaluation, and mitigation planning.
  • Lead audit readiness and execution for SOC 2 and ISO 27001, including evidence collection and auditor coordination.
  • Partner with customer-facing teams to respond to security questionnaires and improve response workflows.
  • Contribute to security awareness and culture by mentoring others and raising the organization’s security standards.

Requirements

  • 5+ years of experience in security engineering, security operations, or a related field.
  • Direct experience with security and compliance frameworks such as SOC 2 and/or ISO 27001, including audit processes.
  • Deep experience with vulnerability management, including tooling, prioritization, and remediation workflows.
  • Experience working across cloud environments such as AWS, GCP, or Azure and modern SaaS ecosystems.
  • Experience with identity and access management, endpoint security, and IT/security operations.
  • Ability to translate security risks into clear, actionable guidance for both technical and non-technical stakeholders.
  • Demonstrable experience or strong interest in using AI tooling to accelerate business impact.
  • Strong written communication skills and comfort owning documentation and audit artifacts.
  • A proactive, pragmatic mindset with the ability to balance security best practices and business needs.
  • Experience influencing cross-functionally in a remote-first environment without formal authority.
  • Experience designing or improving SIEM, logging, and alerting pipelines is a plus.
  • Familiarity with compliance automation platforms such as Drata, Vanta, or Tugboat is a plus.
  • Experience leading or owning SOC 2 / ISO 27001 audits is a plus.
  • Background in application security or cloud security engineering is a plus.
  • Experience mentoring or guiding more junior team members is a plus.
  • Ability to work in Eastern North America time zones (NST, AST, EST).

Benefits

  • Competitive, location-specific compensation and benefits.
  • Flexible, autonomous, and collaborative working environment built on trust.
  • Home office stipend.
  • Coworking budget.
  • Ongoing education budget.
  • Mission-driven work focused on reducing wildfires and supporting climate resilience.
  • Remote work with the option for occasional in-person collaboration.
  • Annual in-person team gathering event.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Technician

Unlimited Technology 51-250 Professional Services

Unlimited Technology is hiring a full-time Security Installation Technician to install, program, troubleshoot, and maintain access control and IP camera systems at client sites.

2 hours, 19 minutes ago

Senior Information Security Engineer – Data

Rubrik 1K-5K IT Services

Rubrik is hiring a Senior Security Engineer to operate its SIEM environment and help build a Security Data Lake platform that supports security monitoring, analytics, and automated SecOps across a global multi-cloud footprint.

AWS Azure CI/CD Databricks Elasticsearch GCP Kubernetes LLM Python SIEM Snowflake Splunk Terraform
2 hours, 34 minutes ago

Senior Technical Security Application Engineer, Secured Spaces

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Senior Technical Security Application Engineer to own the design, commissioning, and lifecycle sustainment of intrusion detection and access control systems for secured spaces supporting its defense technology operations.

4 hours, 2 minutes ago

Security Software Engineer II, Internal Identity & Access Management

Pinterest 5K-10K Internet Software & Services

Pinterest is hiring a software engineer for its Internal Identity & Access Management team to build production infrastructure for identity, authentication, and authorization across critical systems.

AWS C++ Envoy Go Kubernetes Microservices OAuth Puppet Python React SAML Terraform TypeScript
6 hours, 18 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers