Compliance Engineering Lead

Socket,
Remote

About The Position

Socket is seeking a Compliance Engineering Lead to establish compliance as an engineered system, moving beyond simple reminders. This role is crucial as Socket serves security-focused customers who demand rigorous compliance standards. The ideal candidate will engineer solutions for SOC 2 Type II, ISO 27001, risk management, and vendor programs, ensuring these are robust and credible. This is a foundational, engineering-centric role where the focus is on building automated systems for evidence collection and control testing, rather than manual processes. The Compliance Engineering Lead will report to the CISO, own the end-to-end compliance program, and build and lead a team, starting with a customer trust hire. This role will significantly shape the future of GRC at Socket.

Requirements

  • Personal ownership of at least two full SOC 2 Type II cycles, including auditor relationships, scoping, evidence, and findings.
  • Ability to describe a failed control, its cause, and the implemented solution.
  • Experience with ISO 27001, including taking an organization through certification or running an ISMS through surveillance audits.
  • Demonstrated ability to build and maintain automations against services (e.g., GCP, GitHub).
  • Comfort operating with scheduled jobs and APIs before resorting to manual reminders.
  • Clear opinions and hands-on experience with compliance platforms like Drata or Vanta, understanding their leverage points and limitations.
  • Judgment to prioritize compliance efforts based on real risk rather than auditor preferences.
  • Strong writing skills capable of communicating with auditors, enterprise security reviewers, engineers, and executives.
  • Instinct to address unowned problems, particularly in the seams between Security, Engineering, Legal, and Go-to-Market.
  • Experience in a remote, fast-moving environment with shifting priorities and undefined programs.

Nice To Haves

  • Exposure to AI governance frameworks (ISO/IEC 42001, NIST AI RMF, EU AI Act).
  • Experience at a security vendor or a company with high customer-imposed security standards.
  • Experience with contract security review alongside Legal.
  • Experience building compliance automation in-house.

Responsibilities

  • Own SOC 2 Type II end to end, including the observation window, auditor relationship, and evidence pipeline.
  • Ensure described controls accurately reflect actual running controls and own the final report for customers.
  • Lead Socket through ISO 27001 certification by defining scope, ISMS, running gap assessments and internal audits, and preparing the organization.
  • Maintain the ISMS as a functional tool for the company, not just for auditors.
  • Automate evidence collection from systems like GCP, GitHub, identity providers, MDM, and ticketing systems.
  • Build control monitoring to detect drift immediately.
  • Develop and maintain a risk register that reflects actual risks and informs leadership decisions.
  • Manage third-party risk in partnership with an external security partner, including tiering, reviews, and renewal cadences.
  • Own and maintain the customer-facing assurance surface, including a trust portal and artifact library.
  • Reduce the load of security questionnaires and RFPs.
  • Evaluate and define Socket's AI assurance posture, considering frameworks like ISO/IEC 42001, NIST AI RMF, and the EU AI Act.
  • Determine which AI assurance standards to commit to and the necessary steps for implementation.

Benefits

  • Market competitive salary bands
  • Meaningful equity program
  • Comprehensive health benefits for you and your family (99% coverage)
  • Flexible time-off, holidays, and winter shutdown
  • Paid parental leave
  • Remote-first work environment
  • Quarterly team off-sites
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service