FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in implementing and maintaining SOC 2 and ISO 27001 controls, with hands-on experience in cloud security, particularly AWS. Proficient in managing access control, incident response, and conducting security training while ensuring compliance with security policies.
Highest-signal resume keywords
SOC 2 ImplementationISO 27001 ControlsAWS Cloud SecurityVulnerability ScanningAccess Control Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security EngineeringCloud SecurityIncident ResponseData ClassificationContinuous Control MonitoringAccess ReviewsRemediation TrackingEncryptionIAM ManagementLog Monitoring
Soft Skills
Clear Written CommunicationAsynchronous Collaboration
Tools & Technologies
GRC Automation PlatformsVantaDrata
Certifications & Qualifications
Security+CySA+ISO 27001 Lead ImplementerCISACISSP
Industry Keywords
Risk RegisterThird-Party Risk AssessmentPhishing SimulationsSecurity PoliciesAudit Evidence Collection
Tech Stack
Tools & technologiesAWSCloud
About the role
Key responsibilities & impact- Implement and maintain SOC 2 and ISO 27001 controls across infrastructure, applications and internal systems
- Close control gaps as they are identified
- Enforce information security policies across engineering and business teams
- Manage access control, data classification, incident response, vendor risk and change management practices
- Perform continuous control monitoring, including recurring access reviews, log reviews, vulnerability scans and patch cadence checks
- Organize evidence ahead of audits
- Triage vulnerability scanner findings, coordinate remediation with engineering and verify closure
- Manage onboarding/offboarding, least-privilege access, MFA enforcement and periodic access recertification
- Monitor security alerts and logs, triage and escalate incidents according to the incident response plan
- Maintain the risk register and third-party risk assessments and track remediation to closure
- Prepare evidence for annual assessments and respond to customer security questionnaires
- Run employee security training and phishing simulations
- Partner with engineering on AWS secure cloud configuration, least-privilege IAM, encryption and secrets management
- Report into the Security & Compliance team
- Spend approximately 90% of time on hands-on execution and 10% on cross-functional work
Requirements
What you’ll need- 2–5 years in security engineering, cloud security or infrastructure security
- Ideally direct SOC 2 or ISO 27001 exposure
- Working knowledge of the SOC 2 Trust Services Criteria and mapping technical controls to them
- Hands-on cloud security fundamentals, preferably AWS
- Experience with IAM, logging/monitoring and vulnerability scanning
- Comfortable executing security policy day to day, including access reviews, evidence collection and remediation tracking
- Clear written communication
- Comfortable working asynchronously across time zones with a distributed team
- Familiarity with GRC automation platforms such as Vanta or Drata is highly valued
- Relevant certification such as Security+, CySA+, ISO 27001 Lead Implementer, or progress toward CISA/CISSP is highly valued
Benefits
Comp & perks- Competitive compensation
- Flexible hours
- Fully remote work
- Global, distributed team environment
- Real ownership over security controls
- Multi-framework exposure to SOC 2 and ISO 27001 programs
- Professional exposure to a fast-moving, AI-native product team
