Security & Compliance Engineer
Aurelian · Seattle, WA · 1 mo ago
On-siteManagement$150k–$215k/yrFull-time
About the role
Aurelian builds AI tools that help 911 centers handle more with less, so telecommunicators can stay focused on what matters most and communities get the response they need. We are looking for a dedicated security and compliance owner to join our growing team.
Responsibilities
- Own our security posture end-to-end: Be the single source of truth for how Aurelian handles sensitive data. Keep our security claims accurate, consistent, and defensible across every document, questionnaire, and contract.
- Run the compliance program: Own SOC 2 and our alignment to the CJIS Security Policy (and FedRAMP/GovCloud as our gov pipeline grows).
- Own the artifacts that don't fully exist yet - subprocessor lists, data management and retention policies, incident response plans - and keep them current.
- Turn security reviews from a bottleneck into a process: Own the customer security-questionnaire pipeline so deals don't wait on engineering.
- Work directly with our implementation and sales teams to get agencies the answers they need, quickly and accurately.
- Do the engineering, not just the paperwork: Harden our cloud infrastructure (Azure), tighten IAM and tenant isolation, improve logging/audit and detection, and shore up our secure development practices.
- Automate the compliance grind: Wire up and operate compliance-automation tooling so evidence collection, continuous controls monitoring, and questionnaire responses run as close to hands-off as possible.
- Treat compliance as code.
- Operationalize personnel security: Run the processes CJIS requires across engineering - background checks / fingerprinting, security-awareness training, and access controls for anyone who touches criminal justice information.
Requirements
- ~5–8 years across security engineering and GRC is a good marker, but we care about the blend more than the number.
- Fluent in the frameworks that matter to us: Direct experience with SOC 2 and hands-on familiarity with the CJIS Security Policy, NIST 800-53/800-171, or FedRAMP.
- Comfortable in the cloud and in code: You can harden a cloud environment (Azure ideally), reason about IAM, encryption, network isolation, and logging, and automate controls and evidence with scripting and GRC tooling.
- Credible in the room: You can face an auditor, a state CJIS Systems Officer, or a county CISO team and answer hard questions clearly — and translate the same material for our sales and implementation teams and our engineers.
- High ownership, low ceremony: You see the gap, define the right thing to build, and drive it to done. You'd rather build a durable system than win an argument, and you're energized by being the person the whole company relies on for this.
Qualifications
- You must be authorized to work in the US without visa sponsorship, and — because of the data we handle — able to pass a state and national fingerprint-based background check for CJIS clearance.
Skills
- Security Engineering
- Compliance Program Ownership
- Cloud Infrastructure Hardening
- Automation of Compliance Processes
- Personnel Security Operations
Benefits
- Comprehensive Medical, Dental, Vision & Life insurance
- 401(k)
- Unlimited PTO
- Company-wide offsites
- Equipment stipend
- Relocation assistance
- Daily delivered lunches (on us)
- Office in Seattle
Pay
- Range: $150K - $215K
Schedule
- Full-time