- Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
- Automate compliance workflows, evidence collection, access reviews, security checks, and other repetitive processes.
- Partner with Engineering and Security to implement and monitor controls around access management, infrastructure, data protection, logging, and vulnerability management.
- Support audits by owning technical evidence collection and working with auditors to address compliance requirements.
- Work with customers and internal teams to respond to security questionnaires, compliance requirements, and technical due diligence.
- Identify gaps in our compliance and security programs and build scalable systems to address them.