Grant Street Group logo
Grant Street Group

Grant Street Group specializes in cloud-based government solutions for tax collection, e-payments, and auctions.

Security & Compliance Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

$100K - $160K / year

Seniority

Senior

Bachelor Degree3 yrs expEnglishAWSCloudLinuxPython

Job Description

Security & Compliance Engineer

Grant Street Group

• Support the day-to-day security posture of systems and services across cloud and on-prem environments. • Review vulnerability findings from scanners, penetration tests, and other assessments, and help drive remediation to closure. • Partner with infrastructure, platform, and engineering teams on secure configuration, access control, logging, monitoring, and incident readiness. • Support compliance and assessment activities related to GovRAMP/FedRAMP, PCI DSS, internal reviews, and third-party examinations. • Use AWS security tooling effectively, support day-to-day security processes, and help translate security and compliance requirements into practical, durable operational outcomes. • Maintain documentation, procedures, and other operational artifacts so they stay aligned with the environment and current control expectations.

Job Requirements

  • 3+ years of experience in security engineering, security operations, infrastructure security, or security compliance.
  • Hands-on experience working in Linux-based production environments and securing Linux systems.
  • Experience securing AWS environments and using services such as IAM, CloudTrail, GuardDuty, Security Hub, Config, Inspector, and KMS.
  • Working knowledge of vulnerability management, configuration management, logging, monitoring, access control, and incident response practices.
  • Scripting experience in Python, Bash, PowerShell, or similar for automation, security operations, and reporting tasks.
  • Strong written and verbal communication skills, with the ability to move issues from discovery through remediation across multiple teams.
  • Experience supporting regulated or highly audited environments is a plus.
  • Familiarity with GovRAMP, FedRAMP, PCI DSS, SOC examinations, or similar frameworks is a plus.
  • Experience reviewing scanner output, penetration test findings, or security monitoring alerts and helping drive remediation is a plus.
  • Familiarity with POA&M tracking, exception handling, and remediation coordination is a plus.
  • Experience working across both cloud and legacy infrastructure is a plus.

Benefits

  • minimal travel: typically 2-3 weeks per year for on-site meetings
  • technology-rich work environment

Related Categories

Related Job Pages

More Security Engineer Jobs

Planet Technologies logo

Security and Compliance Consultant

Planet Technologies

For 24 years, we have built our reputation on establishing trust. Trust with our clients and among our team.

Full TimeRemoteTeam 201-500Since 1999H1B No Sponsor

• Serve as a primary technical lead on client engagements involving Microsoft security, compliance, and data protection solutions • Design and implement data security, governance, and compliance strategies aligned with Microsoft 365 and Azure capabilities • Advise clients on secure adoption of Microsoft Copilot, including data exposure risks, governance controls, and compliance considerations • Architect and deploy solutions leveraging tools such as: Microsoft Purview, Microsoft Defender suite and Microsoft Sentinel • Translate regulatory and compliance requirements into actionable technical solutions (e.g., ISO frameworks, government regulations, internal controls) • Conduct data discovery, classification, and protection strategy design • Collaborate with project managers and stakeholders to deliver high-quality outcomes • Contribute to pre-sales efforts, including solution design, scoping, and level-of-effort estimates • Create technical documentation, implementation guides, and client training materials • Act as a subject matter expert (SME) and mentor to other engineers • Develop and refine repeatable offerings around data security, compliance, and Copilot readiness • Stay current on evolving Microsoft security, compliance, and AI governance capabilities

United States
$120K - $210K / year
Full TimeRemoteTeam 10,001+Since 1993H1B Sponsor

• Define, analyze, and review secure software architectures for centralized automotive computing platforms • Perform threat modeling and security architecture analysis for mixed-criticality, multi-tenant automotive software systems • Partner with safety architects to reason about the interaction between security controls, safety mechanisms, failure modes, and recovery behavior • Define OS security policy, access control, isolation, and privilege models across Android, Linux, QNX, and virtualized environments • Build security systems that maintain integrity and availability for safety-critical vehicle software • Analyze security trade-offs involving performance, latency, memory footprint, boot time, diagnosability, and functional safety requirements • Guide engineering teams on secure build, secure coding, threat mitigation, and security review practices • Collaborate across software, hardware, safety, security, and systems teams to meet NVIDIA and automotive industry standards

California + 4 moreAll locations: California | New York | Michigan | Texas | Washington
$224K - $356.5K / year
Full TimeRemoteTeam 11-50

Role Description 10a Labs' Investigations Team is looking for a Senior Cyber Investigator to support critical safety incidents and conduct investigations across a range of cyber abuse areas. This role requires deep cybersecurity subject-matter expertise to detect and respond to malicious activity, assess threat actor behavior at the organizational level, and handle escalated cases requiring senior technical judgment. Investigations may involve exposure to harmful or disturbing content, including malicious code, exploit development, and content designed to facilitate cyberattacks. - Detect and investigate malicious uses and cyber abuse, including cases involving scaled data extraction, ransomware, and local and remote exploits. - Conduct org-level analysis of threat actor behavior, identifying patterns across cases to inform detection and mitigation strategies. - Handle escalated and technically complex cases, applying senior cybersecurity expertise to assess real-world harm potential. - Query internal data sources using SQL and Python and cross-reference open-source information (OSINT) to support investigations. - Document and share investigative findings and recommendations with internal stakeholders and client teams. - Support quality and consistency across the investigations team, providing guidance to junior investigators on ambiguous cases. - Respond to reactive escalations and on-call leads, including those not caught by existing safety systems. Qualifications - At least 5+ years of experience in cybersecurity, threat intelligence, Trust & Safety, national security, defense, intelligence, or law enforcement domains. - Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. - Familiarity with LLM systems and how AI technology can be misused for cyber operations. - Deep subject-matter expertise in one or more of the following: scaled data extraction, ransomware, local and remote exploits, or offensive security operations. - Strong ability to assess the real-world harm potential of technical content, distinguishing genuine offensive uplift from benign or educational security research. - Strong SQL and Python proficiency for querying data and supporting detection workflows. - Proven experience conducting org-level threat actor analysis across large datasets. - Ability to rapidly context-switch across domains, modalities, and abuse areas in a fast-paced, ambiguous environment. - Ability to clear an insider-threat background check. Preferred Qualifications - Experience with threat intelligence frameworks such as MITRE ATT&CK. - Background in dark web monitoring, OSINT, or cross-platform threat analysis. - Experience scaling and automating detection and mitigation processes. - Full professional proficiency in Arabic, Chinese, Farsi, Portuguese, Russian, or Spanish. - Relevant certifications such as OSCP, GREM, or GCTI. Benefits - Salary Range: $115K–$140K, depending on experience and location. - Work Environment: Fully remote, U.S.-based. - Health Benefits: Comprehensive health, dental, and vision coverage. - Time Off: Generous PTO and paid holiday schedule. - Retirement: 401(k) plan.

United States
$115K - $140K / year
Full TimeRemoteTeam 11-50

Role Description 10a Labs' Investigations Team is looking for a Cyber Investigator to support high-volume exchange labeling and investigations across a range of cyber abuse areas. This role requires a solid foundation in cybersecurity and a keen ability to assess whether technical content poses real-world harm. Investigations may involve exposure to harmful or disturbing content, including malicious code, exploit development, and content designed to facilitate cyberattacks. In this role, you will: - Review and label AI-generated exchanges to assess whether content provides meaningful offensive cyber uplift, distinguishing it from legitimate security research. - Investigate potentially policy-violating activity by querying internal data sources using SQL and Python and cross-referencing open-source information (OSINT). - Document and share investigative findings with internal stakeholders. - Respond to reactive escalations and on-call leads, including those not caught by existing safety systems. Qualifications - At least 1–3 years of experience in cybersecurity, Trust & Safety, national security, defense, intelligence, or law enforcement domains. - Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. - Foundational knowledge of cyber threat concepts, including one or more of the following: scaled data extraction, ransomware, local and remote exploits, or offensive security operations. - Familiarity with LLM systems and how AI technology can be misused for cyber operations. - Ability to assess the real-world harm potential of technical content, distinguishing offensive uplift from benign or educational security research. - Strong SQL and Python proficiency for querying data and supporting investigations. - Ability to rapidly context-switch across domains, modalities, and abuse areas in a fast-paced, ambiguous environment. - Ability to clear an insider-threat background check. Requirements - Experience with threat intelligence frameworks such as MITRE ATT&CK. - Background in dark web monitoring, OSINT, or cross-platform threat analysis. - Full professional proficiency in Arabic, Chinese, Farsi, Portuguese, Russian, or Spanish. - Relevant certifications such as CompTIA Security+, CEH, or OSCP. Benefits - Salary Range: $80K–$105K, depending on experience and location. - Work Environment: Fully remote, U.S.-based. - Health Benefits: Comprehensive health, dental, and vision coverage. - Time Off: Generous PTO and paid holiday schedule. - Retirement: 401(k) plan.

United States
$80K - $105K / year