Compliance Engineer

DiscoNew York City, NY
Remote

About The Position

DISCO is a legal tech software company aiming to lead the legal tech market. Our mission is to provide a unified technology platform for the practice of law, using technology to automate tasks and allow lawyers to focus on judgment. As a Compliance Engineer on the DevOps team, you will drive the implementation of compliance requirements, enhancing system reliability, scalability, and security. Your work will automate the 'audit burden' for engineers, shaping our cloud strategy and assuring partners.

Requirements

  • A minimum of 5 years in a technical compliance, security, or DevOps-adjacent role, preferably within a SaaS environment.
  • Strong understanding of key compliance frameworks, including SOX 404, ISO-27001, SOC2, and IT general controls (ITGC).
  • 2-4 years of hands-on experience in DevOps or Platform Engineering, specifically working with AWS, cloud-native applications, and automating deployment/scaling of containerized applications using Infrastructure as Code.
  • A desire and/or experience in leveraging compliance automation platforms (e.g., Anecdotes) to build and maintain automated evidence-gathering tools.
  • An engineering background with a preference for collaborative work, including mentoring others and partnering with cross-functional engineering teams to build and maintain highly performant systems.
  • Authorization to Work in the U.S. without sponsorship.

Nice To Haves

  • Exposure to and understanding of security and compliance frameworks such as FedRAMP, NIST 800-53, or CSRF.
  • Experience building and managing PaaS (Platform as a Service) for internal development teams.
  • Experience with Cloud Networking (VLAN, routing).
  • Experience with other cloud platforms, specifically Azure and GCP.
  • Familiarity with Windows Server and Administration (Active Directory, Group Policy Objects).
  • Experience with ASP.NET Deployments (WebDeploy).
  • General experience with Software Development and any tech stack.

Responsibilities

  • Serve as the Engineering technical contact for annual SOX, SOC2 Type II, and ISO-27001 audits while automating evidence collection into "Continuous Compliance" workflows.
  • Work with DevOps Engineers to implement "Compliance as Code," establishing automated guardrails and performing internal reviews of infrastructure configurations.
  • Manage the technical lifecycle of user access, enforce Segregation of Duties (SoD), and review deprovisioning workflows.
  • Support GRC teams by providing technical expertise during sales cycles, responding to RFPs, and maintaining the Security Trust Center and compliance documentation.

Benefits

  • medical, dental and vision insurance
  • 401(k)
  • Flexible PTO
  • Growth opportunities throughout the company
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service