Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Stealth

Security Operations Engineer

Stealth

. Assess, triage, and resolve Security Command Center findings across GCP environments .

Posted 10/6/2026full-timeSan Francisco • California • United StatesMid-LevelSenior💰 $140,000 - $170,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cloud and application security, with a strong focus on SOC 2 Type II and ISO 27001 audits. Proficient in automating security processes and maintaining compliance in regulated environments.

Highest-signal resume keywords
SOC 2 Type II Audit LeadershipISO 27001 Compliance ExpertiseCloud Security OperationsJava and Gradle ProficiencyVulnerability Scanning Tools Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security OperationsSecurity EngineeringDevSecOpsCloud SecurityControl DesignPolicy WritingShell ScriptingUnix/LinuxNode.jsPython
Soft Skills
Self-DirectedProactiveJudgmentClear Communication
Tools & Technologies
GCP Security Command CenterSonarQubeGitHub DependabotAmazon InspectorJenkinsGCP Cloud BuildGitHub ActionsCompliance Automation Platforms
Certifications & Qualifications
CISSPCISAISO 27001 Lead AuditorISO 27001 Lead ImplementerGoogle Professional Cloud Security Engineer
Industry Keywords
PaymentsBankingFintechRegulated Financial Environment

Tech Stack

Tools & technologies
CloudGoogle Cloud PlatformGradleJavaJavaScriptJenkinsLinuxNode.jsPythonShell ScriptingUnix

About the role

Key responsibilities & impact
  • Assess, triage, and resolve Security Command Center findings across GCP environments
  • Harden cloud infrastructure and configuration
  • Review CVEs and drive remediation across application dependencies, container images, and infrastructure
  • Convert automated scanner findings into precise code, library, and configuration change requirements
  • Automate tools, services, and code build and inspection steps from finding identification through resolution
  • Strengthen CI/CD pipeline security and embed scanning and checks into software delivery
  • Identify emerging risks early and raise them before incidents occur
  • Guide and evolve security practices, standards, and tooling
  • Lead SOC 2 Type II and ISO 27001 audits end to end, including scoping, readiness, evidence collection, auditor walkthroughs, and exception remediation
  • Manage audit firm relationships and coordinate internal audit resources
  • Plan and run internal audits and control testing against SOC 2, ISO 27001, and company policies
  • Serve as primary point of contact for auditors
  • Support security reviews, questionnaires, and due diligence from banking partners and enterprise customers
  • Own the security control framework, policies, and risk register
  • Automate evidence collection to maintain continuous audit readiness
  • Collaborate with Engineering, DevOps, Compliance, and leadership across time zones

Requirements

What you’ll need
  • 5+ years in security operations, security engineering, or DevSecOps
  • Hands-on ownership of cloud and application security in a production environment
  • Proven experience leading SOC 2 Type II and/or ISO 27001 audits
  • Experience acting as primary point of contact for external auditors
  • Experience planning and running internal audits
  • Strong knowledge of SOC 2 Trust Services Criteria and ISO 27001 Annex A
  • Experience designing controls, writing policies, and preparing audit evidence
  • Hands-on experience with Java and Gradle
  • Experience with vulnerability and code scanning tools such as SonarQube, GitHub Dependabot, or Amazon Inspector
  • Ability to write and maintain security tooling and automation in Node.js or Python
  • Strong knowledge of shell scripting, Unix/Linux, and networking
  • Fluent use of modern AI assistants such as Claude Code or similar
  • Self-directed and proactive, with judgment to prioritize risk and drive remediation to completion
  • Ability to explain security findings, control gaps, and impact clearly to engineers, leadership, auditors, and external partners
  • Preferred: Experience with GCP Security Command Center
  • Preferred: Experience with Jenkins, GCP Cloud Build, GitHub Actions, or similar build pipelines
  • Preferred: Experience in payments, banking, fintech, or another regulated financial environment
  • Preferred: Experience with compliance automation platforms such as Vanta or Drata
  • Preferred: Relevant certifications such as CISSP, CISA, ISO 27001 Lead Auditor/Lead Implementer, or Google Professional Cloud Security Engineer
  • Preferred: Experience working with global development and operations teams
  • Must be legally authorized to work in the U.S. without sponsorship

Benefits

Comp & perks
  • Equity
  • Bonus
  • Opportunity to own the platform and operations function end-to-end
  • Scope expansion across new products, rails, partners, and markets
  • Collaborative team culture valuing curiosity, inclusion, and sustainable work
  • Equal opportunity, diversity, and inclusion commitment