freehire launches on Product Hunt on 26 August.

Follow →

Security & Compliance Engineer

Open 55d

Are you the kind of security professional who likes turning findings into fixes? Do you enjoy working across AWS, Linux, and compliance-driven environments to keep systems secure and practical? If so, you may be the perfect fit for Grant Street Group!

Grant Street Group is a growing company providing SaaS products in areas such as electronic payments, auctions, and tax collection. We’re looking for a hands-on Security & Compliance Engineer to help maintain and improve the operational security of our linux based systems and services across hybrid AWS and on-prem environments. This role focuses on vulnerability management, security log management, control monitoring, remediation tracking, audit support, and cross-team coordination.

What you’ll do

  • Support the day-to-day security posture of systems and services across cloud and on-prem environments.

  • Review vulnerability findings from scanners, penetration tests, and other assessments, and help drive remediation to closure.

  • Partner with infrastructure, platform, and engineering teams on secure configuration, access control, logging, monitoring, and incident readiness.

  • Support compliance and assessment activities related to GovRAMP/FedRAMP, PCI DSS, internal reviews, and third-party examinations.

  • Use AWS security tooling effectively, support day-to-day security processes, and help translate security and compliance requirements into practical, durable operational outcomes

  • Maintain documentation, procedures, and other operational artifacts so they stay aligned with the environment and current control expectations.

What makes you a great fit?

  • 3+ years of experience in security engineering, security operations, infrastructure security, or security compliance.

  • Hands-on experience working in Linux-based production environments and securing Linux systems.

  • Experience securing AWS environments and using services such as IAM, CloudTrail, GuardDuty, Security Hub, Config, Inspector, and KMS.

  • Working knowledge of vulnerability management, configuration management, logging, monitoring, access control, and incident response practices.

  • Scripting experience in Python, Bash, PowerShell, or similar for automation, security operations, and reporting tasks.

  • Strong written and verbal communication skills, with the ability to move issues from discovery through remediation across multiple teams.

Experience with any of the following is a plus

  • Experience supporting regulated or highly audited environments.

  • Familiarity with GovRAMP, FedRAMP, PCI DSS, SOC examinations, or similar frameworks.

  • Experience reviewing scanner output, penetration test findings, or security monitoring alerts and helping drive remediation.

  • Familiarity with POA&M tracking, exception handling, and remediation coordination.

  • Experience working across both cloud and legacy infrastructure.

  • Comfort using AI tools responsibly to support workflows such as triage, investigation, scripting, documentation, and reporting.

  • Experience with security data lakes, OCSF schema management, or security data transformation pipelines.

There is minimal travel: typically 2-3 weeks per year for on-site meetings.

We reward teamwork, professional excellence, and individual responsibility. Using the best collaboration tools available, we offer a technology-rich work environment that makes it possible for us to support the needs of our employees. If you are passionate about your work, have an entrepreneurial spirit, and want to be on a team of exceptional professionals, this could be the opportunity you are looking for.

Expected Salary Range: $100,000 – $160,000/year

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, Other (website, portfolio, GitHub, etc.) URL

  • Will you, now or in the future, require visa sponsorship to work in the United States? choose one · optional
  • Please choose from the following: choose one · optional
  • Why do you want to work with us? Tell us what interests you about this opportunity. written answer
  • Describe a security problem you personally owned in AWS. What was the issue, what actions did you take, and what was the outcome? written answer
  • Tell us about a time you had to manage or improve a high-volume logging, monitoring, or security data environment. What tools did you use, and how did you keep it practical and scalable? written answer
  • Describe how you have handled vulnerability findings or security alerts from discovery through remediation. How did you prioritize, coordinate with other teams, and make sure work actually got done? written answer
  • Give an example of a time you improved a security process without being asked step-by-step. What did you notice, what did you change, and what happened afterward? written answer
  • Tell us about a time you had to work closely with engineers, infrastructure, or operations teams to solve a security issue. How did you build alignment and move the work forward? written answer
  • If you joined a team with growing AWS log volume, limited security staff, and too many findings to review manually, how would you approach the first 60–90 days? written answer

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available