RUNWARE

RUNWARE

RUNWARE provides an affordable API that enables AI developers to efficiently run image, video, and custom generative AI models without the need for extensive infrastructure or machine learning expertise.

Internet Software & Services
1-10
Founded 2023

Description

  • Own and drive SOC 2 and ISO 27001 compliance end-to-end, including control design, implementation, evidence collection, audits, and continuous improvement.
  • Translate compliance requirements into practical, scalable engineering and operational controls.
  • Partner with infrastructure and engineering teams to embed security into system design, delivery, and deployment pipelines.
  • Maintain and evolve security policies, standards, and the organisational risk register.
  • Lead security reviews of systems, architectures, and proposed changes with a focus on real-world risk reduction.
  • Support incident response activities including investigation, containment, and post-incident learning and remediation.
  • Improve security visibility across the platform through logging, monitoring, alerting, and audit trails.
  • Own vendor and third-party security assessments and questionnaires.
  • Establish and mature secure development practices such as access control, secrets management, least privilege, and change management.
  • Act as a security mentor and point of reference for engineers across the organisation.

Requirements

  • Strong experience in security engineering, infrastructure security, or a closely related role.
  • Proven, hands-on experience delivering SOC 2 and/or ISO 27001 in a production environment.
  • Strong understanding of cloud security fundamentals: IAM, networking, encryption, and key management.
  • Experience with modern cloud platforms, CI/CD pipelines, and containerised workloads.
  • Ability to assess risk pragmatically and prioritise controls that actually reduce risk.
  • Experience responding to and managing security incidents in real systems.
  • Comfortable working across engineering, product, and leadership stakeholders and communicating security trade-offs clearly.
  • Ability to operate independently and take ownership in a remote-first environment.
  • Nice to have: experience securing high-performance or distributed systems.
  • Nice to have: familiarity with compliance tooling and evidence automation, infrastructure-as-code (Terraform, Pulumi), vulnerability management, penetration testing or bug bounty programs, and experience at startups or scaling companies.

Benefits

  • Remote-first setup with twice-yearly in-person company retreats.
  • Generous paid time off including vacation, sick days, and public holidays.
  • Meaningful stock options to share in company upside.
  • Flexible hours with core collaboration blocks and ownership of your schedule.
  • Paid family leave (maternity, paternity, and caregiver time).
  • Company culture that encourages unplugging and recharge after major release pushes.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Head of Corporate Engineering

Databricks 1K-5K IT Services

Databricks is hiring a Head of Corporate Engineering to lead global enterprise engineering and operations, building and scaling secure cloud infrastructure, identity and access, endpoints, collaboration and engineering tools to enable developer velocity and enterprise compliance.

Agile AWS Azure Confluence GCP GitHub JIRA macOS
1 month ago

Incident Response Security Engineer

ClickHouse 51-250 IT Services

Security practitioner role at ClickHouse focused on scaling incident detection and response capabilities, driving adoption of security processes and tooling, and protecting the company’s cloud and product infrastructure for customer-facing services.

AWS Azure ClickHouse GCP Penetration Testing Python SIEM
1 month ago

Senior Security Engineer - Vulnerability Management

Samsara 1K-5K IT Services

Senior Security Engineer at Samsara responsible for deploying, operating, and improving the company’s Vulnerability Management program to reduce software vulnerabilities and protect customer-facing infrastructure.

AWS CI/CD DevSecOps Go Python Serverless Terraform
1 month ago

Junior DevSecOps Engineer - Contingent

ARETUM Construction & Engineering

Junior DevSecOps Engineer at Aretum supporting a federal client to operate, automate, and secure cloud-based systems and CI/CD pipelines to enable reliable, compliant deployments.

Agile Ansible AWS AWS CDK Azure Chef CI/CD Docker Encryption Git GitLab CI Grafana JIRA Kubernetes Linux LXC Prometheus Puppet SaltStack Scrum Serverless Terraform
1 month ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers