Senior Compliance Engineer
Legal
United States · Remote
Posted on Aug 28, 2026
The Role: Senior Compliance Engineer for security/compliance. SOC 2 and HIPAA programs are mature; lead GDPR depth and PCI DSS attestation while sustaining existing programs. Governance-first role: design control set, automate evidence, run audits, keep policy current, answer customer security calls. Covers corporate IT (identity and endpoint). Success blends framework expertise and practical systems judgment; translate controls into automation and defaults engineers can use. Compliance at Estuary carries commercial weight and is customer-visible. What You'll Do – Governance and Compliance: Deepen GDPR (records of processing, lawful basis, DPAs/sub-processors, transfers, residency, retention, DSARs). Lead PCI DSS as a service provider from scoping to attestation. Sustain SOC 2 and HIPAA (evidence, access reviews, control testing, auditors, BAAs/PHI). Maintain risk register and system of record; vendor/sub-processor assessments; pen tests; training. Keep compliance scope current with product/architecture/vendor changes. Support enterprise diligence (questionnaires, risk reviews, audits, trust center, documentation). Keep incident readiness (IR, BCP/DR) with engineering. The Systems Underneath: Run identity and access (SSO/IdP, provisioning, MFA, least privilege, access review automation). Run endpoints and SaaS estate (MDM, endpoint security, onboarding/offboarding, vendor procurement/security review, license hygiene, SaaS visibility). Automate evidence collection. What We're Looking For: 8+ years in compliance/GRC/security governance with program ownership; built programs from near-zero; SOC 2 Type II depth; GDPR fluency; policy/judgment; hands-on identity/device/SaaS admin; systems thinking; engineering empathy; clear communication to technical and non-technical audiences; practical experience (certs welcome but track record weighted). Bonus: PCI DSS service provider experience; ISO 27001; data infrastructure context; Vanta/Drata/Secureframe; public sector frameworks (FedRAMP/StateRAMP/NIST 800-53); startup grit. Why Estuary: VC-backed, low-ego team; competitive compensation/equity/benefits; flexible remote culture; high autonomy; quarterly offsites in cities like Miami.
