Job Closed
This listing is no longer active.
ComplyAuto is a RegTech company offering cloud-based software that helps companies enhance their compliance and security capabilities while becoming more efficient and cost-effective. ComplyAuto manages and automates compliance decisions, performing tasks that would normally require manually-intensive processes and human intelligence. ComplyAuto began as a privacy compliance company for automotive dealers, but has quickly expanded into other verticals and compliance areas including cybersecurity, EHS (environmental, health, and safety), and legal compliance.
Software Security Engineer
Location
United States
Posted
27 days ago
Salary
$145K - $160K / year
Seniority
Mid Level
Job Description
Software Security Engineer
ComplyAuto
Role Description ComplyAuto is looking for a hands-on Software Security Engineer to help shape and scale our application security program. In this high-impact individual contributor role, you'll work closely with the Director of Information Security and our Development team to identify risk, strengthen our codebase, and embed security into the way we build software. This is an ideal opportunity for someone who enjoys going deeper than automated tooling, conducting manual code reviews, testing real-world application risk, and partnering directly with engineers to design secure, practical solutions. You'll play a key role in securing modern JavaScript and TypeScript applications, improving our CI/CD security practices, and driving application security initiatives across a fast-moving, high-growth SaaS environment. What You'll Do - Lead day-to-day application security efforts across ComplyAuto's software environment, including secure code reviews, threat modeling, manual security assessments, penetration testing, and vulnerability remediation. - Work directly with developers to identify risks in JavaScript, TypeScript, React, Node.js, APIs, databases, and cloud-based SaaS applications, then provide clear, actionable guidance to fix issues at the source. - Help mature and design our application security program by developing security policies, documenting controls, implementing security testing tools, and automating SAST and DAST capabilities within CI/CD pipelines. - Deliver secure coding training and support incident response for application-related events. Qualifications - 5–7+ years of experience in application security, software development, or a related security engineering role. - Strong hands-on experience reviewing code and identifying vulnerabilities that automated tools may miss. - Comfortable working in TypeScript, JavaScript, or Python. - Familiar with modern development environments such as React and Node.js. - Experience securing APIs, relational databases, SaaS applications, and cloud infrastructure across AWS, Azure, or GCP. - Experience configuring and managing SAST and DAST tools such as Snyk, Checkmarx, Veracode, Synopsys, StackHawk, Qualys, or Burp Suite. - Strong communication skills to translate complex technical risks into practical recommendations for both technical and non-technical stakeholders. - Familiarity with secure coding standards, web application architecture, security and compliance frameworks such as NIST CSF, CIS, SOC 2, and PCI-DSS, and regulatory requirements such as CCPA and GLBA. Benefits - 401(k) 5% match (1:1) - Medical, dental, and vision insurance; premiums we pay 100% for employee and family - HSA contribution for qualifying plans - Unlimited Paid time off and 11 observed holidays - Laptop and related hardware required provided Requirements - Applicants must be authorized to work in the United States and provide proof of work authorization within three days of hire. - ComplyAuto is unable to sponsor or transfer employment visas for this role at this time. - This is a fully remote opportunity for candidates residing in the Continental United States. - Please note we are not accepting applications from candidates residing in California, Hawaii, or Alaska for this position. - ComplyAuto is an equal opportunity employer and participates in E-Verify. - Background check required.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cyber Security Specialist
RadixA Radix está sempre no topo das Melhores Empresas para se trabalhar porque: Temos profissionais comprometidos, dedicados, curiosos e inovadores. O espírito de equipe é a nossa maior força. Trabalhamos de forma cooperativa e sabemos que estamos juntos, remando na mesma direção. Temos um ambiente diverso, que valoriza equidade e inclusão. Nossa jornada de trabalho é flexível e em quase todos os projetos é possível trabalhar de qualquer lugar do Brasil. Valorizamos o bem-estar e o cuidado com as nossas pessoas, com programas de apoio à saúde mental, psiquiatra e médico consultor disponíveis.
Role Description A primeira coisa que você precisa saber é que aqui você não vai cair na rotina. A Radix desenvolve soluções para empresas de diferentes setores e indústrias. Cada projeto tem suas tecnologias, soluções e prazos e você terá oportunidade de atuar e experimentar diferentes desafios. OT Cybersecurity Specialist: - Perform targeted OT cybersecurity maturity reviews focused on asset visibility, network exposure, and uncontrolled access paths. - Identify and document gaps that contribute to unknown or unquantified cyber risk in critical production environments. - Validate that critical assets are properly inventoried, reachable across networks, and assigned to a responsible owner. - Validate actual network reachability and communication paths between IT, OT, and vendor access points. - Assess vendor and remote access mechanisms, identifying persistent, shared, or unmonitored connections. - Evaluate incident containment readiness, including the ability to isolate assets and identify response constraints. - Produce concise, site-level exposure summaries, including prioritized risks and key findings for Security and Operations teams. Benefits - Assistência Médica Nacional (para o titular e dependentes, com quarto privativo). - Assistência odontológica nacional (para o titular e dependentes). - Vale refeição / alimentação flexível. - Auxílio home office. - Day off (no mês do aniversário). - Wellhub (antigo Gympass). - Licença Maternidade (6 meses) e Paternidade (20 dias) estendidas. - Auxílio creche para filhos de até 3 anos (por filho). - Apoio em saúde mental com a Wellz. - Clube de Vantagens com descontos em diversos parceiros. - Convênio com instituições de ensino e cursos de idioma. - Desenvolvimento Profissional (Universidade Corporativa). - Parceria com empresa de coworkings no Brasil. - Programa de Qualidade de Vida e Bem-Estar. - Médico consultor para acompanhamento de radixers. - Planos de incentivos.
• Design, implement, and maintain security controls, processes, and architectures across major cloud environments. • Conduct risk assessments, penetration tests, vulnerability management, and system hardening for cloud services and workloads. • Collaborate closely with engineering, DevOps, compliance, and business stakeholders to enable secure solution delivery and effective risk management. • Build and maintain Infrastructure as Code (IaC) security practices (Terraform, CloudFormation) and work within CI/CD pipelines to embed security in the software development lifecycle. • Partner with the GRC team to ensure compliance automation tooling is implemented effectively across required scope. • Serve as subject matter expert on cloud security technologies, best practices, and emerging threats while providing mentorship to other engineers. • Lead incident investigations, performing root cause analysis and driving remediation actions. • Participate in weekly on-call rotation with the security engineering team. • Operate and mature our CSPM/CNAPP program, driving posture management, misconfiguration remediation, and continuous control monitoring.
Cybersecurity Network Engineer
Accenture Federal ServicesWe believe in the power of change, harnessed in ways that matter for our country and communities.
• The Cybersecurity Engineer will be responsible for ensuring that all information systems' Ports, Protocols, and Services (PPS) accessible to managed networks are registered in the PPSM central registry. • They must protect and use PPS according to the latest vulnerability assessment reports and implement them as per the current DoD STIGs on network infrastructure and application security. • The engineer will review software, hardware, and PPS against approved lists, perform access blocking as per policies. • They will manage PPSM in support of network changes, such as cloud migrations.
• Own and manage the IT general controls (ITGCs) component of the ICFR compliance program while supporting the build out of the ITGCs & IT Application controls (ITAC) for the SOX program from the ground up, leveraging existing frameworks and controls where applicable • Partner with Finance, IT, and business stakeholders to identify and document key controls over financial reporting, ensuring controls are designed and in place ahead of audit cycles • Ensure ITGCs and ITACs supporting financial systems are properly documented and operating as intended • Serve as the primary point of contact for external auditors, coordinating evidence requests, walkthroughs, and finding remediation • Build and maintain a controls inventory with clear ownership, documentation standards, and readiness status • Work cross-functionally with control owners to ensure gaps are identified early and remediation plans are in place before audit periods • Develop and report on compliance readiness and control health to senior leadership • Drive continuous improvement in the efficiency and effectiveness of the SOX Compliance system (AuditBoard) and related technologies • Maintain current knowledge of emerging risks, industry trends, and regulatory changes relevant to the business and the audit profession • Expand ownership to include SOC 1&2, PCI DSS, and NIST compliance programs, building a unified compliance function • Lead a small team of compliance specialists, providing mentorship, prioritization, and ensuring alignment across the aforementioned compliance initiatives


