Socket•25 days ago
Compliance Engineering Lead
Recruiter Fit Breakdown & Candid Summary
1
Socket is hiring a Compliance Engineering Lead to own SOC 2, ISO 27001, and automated evidence pipelines reporting directly to the CISO.
2
This is a hands-on technical engineering role ideal for compliance professionals who prefer writing automation and code over chasing stakeholders for screenshots.
3
The ideal candidate has personally owned SOC 2 Type II cycles and ISO 27001 implementations, while candidates relying solely on traditional GRC checklists should not apply.
Role Responsibilities
- 1Own SOC 2 Type II end to end, managing the observation window, auditor relationships, and evidence pipeline.
- 2Take Socket through ISO 27001 certification, defining scope and maintaining the ISMS.
- 3Build continuous and automated evidence collection by writing automation pulling from GCP, GitHub, IDPs, MDM, and ticketing systems.
- 4Maintain risk management and third-party vendor risk programs in partnership with external security partners.
- 5Own the customer-facing assurance surface, trust portal, and artifact library to reduce enterprise questionnaire friction.
- 6Scope and advise on AI assurance postures such as ISO/IEC 42001, AIUC-1, and NIST AI RMF.
Skills Matrix
Must-Have Skills
SOC 2 Type II(SOC 2)
ISO 27001(ISO27001)
Automation(scripting)
Risk Management(risk register)
Nice-to-Have Skills
ISO/IEC 42001
AI Risk Management Framework(NIST AI RMF)
Free Instant Match Check
Will an ATS filter reject your resume for this role?
Check your keyword match score, missing must-have skills, and formatting flags — before you apply.
Checking saved resume…
No signups. Free check in 3 seconds.
Ready to submit your application?
Apply directly on Socket's official job portal.