xelys jobs xelys jobs

Security & Compliance Engineer

Grant Street Group

nullmidpermanentsecuritybackend United States 32 days ago via LinkedIn
100,000 - 160,000 USD/annual

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

AWSLinuxSecurity EngineeringVulnerability ManagementFedRAMPPCI DSSIAMCloudTrailGuardDutyPython

About the role

Role Overview

Hands-on Security & Compliance Engineer to improve and maintain the operational security of Linux-based systems and services across hybrid AWS and on-prem environments. You’ll help turn security findings into durable fixes while supporting security operations, vulnerability management, and compliance obligations.

Responsibilities

  • Support the day-to-day security posture across cloud and on-prem systems/services
  • Review findings from scanners, penetration tests, and other assessments, and drive remediation to closure
  • Partner with infrastructure/platform/engineering teams on:
    • Secure configuration and access control
    • Logging and monitoring
    • Incident readiness
  • Support compliance and assessments including GovRAMP/FedRAMP, PCI DSS, internal reviews, and third-party examinations
  • Use AWS security tooling to support operational security processes
  • Maintain documentation/procedures and operational artifacts aligned to current environments and control expectations
  • Coordinate remediation tracking and audit support, including cross-team communication
  • Maintain and support vulnerability management, control monitoring, and security log management

Requirements

  • 3+ years in security engineering, security operations, infrastructure security, or security compliance
  • Hands-on experience securing Linux-based production environments
  • Experience securing AWS, including using:
    • IAM, CloudTrail, GuardDuty, Security Hub, Config, Inspector, KMS
  • Working knowledge of:
    • vulnerability management
    • configuration management
    • logging/monitoring
    • access control
    • incident response
  • Scripting experience in Python, Bash, PowerShell, or similar for automation and reporting
  • Strong written/verbal communication; able to drive issues from discovery through remediation across teams

Nice to Have

  • Experience in regulated/highly audited environments
  • Familiarity with GovRAMP, FedRAMP, PCI DSS, SOC examinations
  • Experience with POA&M tracking, exception handling, and remediation coordination
  • Experience across cloud and legacy infrastructure
  • Responsible use of AI tools for triage/investigation/scripting/documentation/reporting
  • Familiarity with security data lakes, OCSF schema management, or security data transformation pipelines

Travel

  • Minimal travel: typically 2–3 weeks per year for on-site meetings

About Grant Street Group

Grant Street Group is a growing SaaS company providing solutions in electronic payments, auctions, and tax collection. The company operates SaaS products across hybrid cloud and on-prem environments and emphasizes operational security and compliance-ready systems.

Scraped 6/28/2026