FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cloud and application security, with a strong focus on SOC 2 Type II and ISO 27001 audits. Proficient in automating security processes and maintaining compliance in regulated environments.
Highest-signal resume keywords
SOC 2 Type II Audit LeadershipISO 27001 Compliance ExpertiseCloud Security OperationsJava and Gradle ProficiencyVulnerability Scanning Tools Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security OperationsSecurity EngineeringDevSecOpsCloud SecurityControl DesignPolicy WritingShell ScriptingUnix/LinuxNode.jsPython
Soft Skills
Self-DirectedProactiveJudgmentClear Communication
Tools & Technologies
GCP Security Command CenterSonarQubeGitHub DependabotAmazon InspectorJenkinsGCP Cloud BuildGitHub ActionsCompliance Automation Platforms
Certifications & Qualifications
CISSPCISAISO 27001 Lead AuditorISO 27001 Lead ImplementerGoogle Professional Cloud Security Engineer
Industry Keywords
PaymentsBankingFintechRegulated Financial Environment
Tech Stack
Tools & technologiesCloudGoogle Cloud PlatformGradleJavaJavaScriptJenkinsLinuxNode.jsPythonShell ScriptingUnix
About the role
Key responsibilities & impact- Assess, triage, and resolve Security Command Center findings across GCP environments
- Harden cloud infrastructure and configuration
- Review CVEs and drive remediation across application dependencies, container images, and infrastructure
- Convert automated scanner findings into precise code, library, and configuration change requirements
- Automate tools, services, and code build and inspection steps from finding identification through resolution
- Strengthen CI/CD pipeline security and embed scanning and checks into software delivery
- Identify emerging risks early and raise them before incidents occur
- Guide and evolve security practices, standards, and tooling
- Lead SOC 2 Type II and ISO 27001 audits end to end, including scoping, readiness, evidence collection, auditor walkthroughs, and exception remediation
- Manage audit firm relationships and coordinate internal audit resources
- Plan and run internal audits and control testing against SOC 2, ISO 27001, and company policies
- Serve as primary point of contact for auditors
- Support security reviews, questionnaires, and due diligence from banking partners and enterprise customers
- Own the security control framework, policies, and risk register
- Automate evidence collection to maintain continuous audit readiness
- Collaborate with Engineering, DevOps, Compliance, and leadership across time zones
Requirements
What you’ll need- 5+ years in security operations, security engineering, or DevSecOps
- Hands-on ownership of cloud and application security in a production environment
- Proven experience leading SOC 2 Type II and/or ISO 27001 audits
- Experience acting as primary point of contact for external auditors
- Experience planning and running internal audits
- Strong knowledge of SOC 2 Trust Services Criteria and ISO 27001 Annex A
- Experience designing controls, writing policies, and preparing audit evidence
- Hands-on experience with Java and Gradle
- Experience with vulnerability and code scanning tools such as SonarQube, GitHub Dependabot, or Amazon Inspector
- Ability to write and maintain security tooling and automation in Node.js or Python
- Strong knowledge of shell scripting, Unix/Linux, and networking
- Fluent use of modern AI assistants such as Claude Code or similar
- Self-directed and proactive, with judgment to prioritize risk and drive remediation to completion
- Ability to explain security findings, control gaps, and impact clearly to engineers, leadership, auditors, and external partners
- Preferred: Experience with GCP Security Command Center
- Preferred: Experience with Jenkins, GCP Cloud Build, GitHub Actions, or similar build pipelines
- Preferred: Experience in payments, banking, fintech, or another regulated financial environment
- Preferred: Experience with compliance automation platforms such as Vanta or Drata
- Preferred: Relevant certifications such as CISSP, CISA, ISO 27001 Lead Auditor/Lead Implementer, or Google Professional Cloud Security Engineer
- Preferred: Experience working with global development and operations teams
- Must be legally authorized to work in the U.S. without sponsorship
Benefits
Comp & perks- Equity
- Bonus
- Opportunity to own the platform and operations function end-to-end
- Scope expansion across new products, rails, partners, and markets
- Collaborative team culture valuing curiosity, inclusion, and sustainable work
- Equal opportunity, diversity, and inclusion commitment
