Senior Compliance Engineer

Estuary
Estuary

Legal

United States · Remote

Posted on Aug 28, 2026
The Role: Join security and compliance to drive GDPR depth and lead PCI DSS while sustaining mature SOC 2 and HIPAA programs. Governance-first role: design control sets, automate evidence, run audits, keep policy current, handle customer security calls. Own corporate IT areas where many controls live (identity/endpoint/SaaS). Success blends framework expertise with practical systems judgment. What You'll Do — Governance & Compliance: - Deepen GDPR across records of processing, lawful basis, DPAs/sub-processors, cross-border transfers, residency, retention, DSARs. - Lead PCI DSS to attestation as a service provider (scope, gaps, remediation, attestation). - Sustain SOC 2/HIPAA (evidence collection, access reviews, control testing, audits, BAAs/PHI). - Maintain risk register; vendor/sub-processor assessments; coordinate pen tests; security awareness. - Keep compliance scope current with platform evolution; support enterprise diligence (questionnaires, audits, trust center). - Maintain/exercise incident response/BCP/DR. The Systems Underneath: - Run identity & access (SSO/IdP, provisioning, MFA, least privilege, automated access reviews). - Run endpoints & SaaS estate (MDM, endpoint security, onboarding/offboarding, procurement/review, license hygiene, visibility). - Automate evidence collection to keep controls continuously satisfied. What We're Looking For: 8+ years in compliance/GRC/security governance with program ownership; SOC 2 depth; GDPR fluency; strong policy/judgment; hands-on identity/device/SaaS ownership; systems thinking; engineering empathy; clear communication. Bonus: PCI DSS, ISO 27001, data infra context, Vanta/Drata/Secureframe, public sector (FedRAMP/StateRAMP/NIST), startup grit. Why Estuary: VC-backed, diverse low-ego team, competitive comp/equity/benefits, flexible remote work, high autonomy, quarterly offsites.