Security Engineer
Amazon Web Services
Application Security
Aws Iam
Cjis Compliance
Cloud
Cloud Computing
Cloud Platforms
Cloud Security
Cloud Security Assurance
Compliance Audits
Data Security
Engineer
Identity and Access Management
Incident Response
Information Security
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Soc 2
Job Description
Flash AI is seeking a hands-on Security Engineer to help own security and compliance across the organization. This remote role focuses on maintaining continuous compliance readiness for CJIS and SOC 2, operating Vanta as the compliance source of truth, and partnering with engineering to keep both the application and AWS environment secure. The compensation starts at $120,000 USD per year, with paid time off included.
What you’ll own
- SOC 2 and CJIS compliance end to end, including ongoing readiness, running the annual SOC 2 audit cycle, and meeting CJIS Security Policy requirements for handling criminal justice information.
- Vanta administration as the primary source of truth for compliance posture: manage automated control tests, investigate and resolve failing tests, keep integrations healthy, and serve as the key point of contact for auditors and customer security reviews.
- Maintain a living security documentation set, including policies, procedures, the risk register, access reviews, and incident response plans, updated as the platform evolves.
- Vulnerability and supply-chain management by tracking dependency and container vulnerabilities from security scanning tools, prioritizing issues based on real risk, driving remediation to closure within SLA, and coordinating third-party penetration tests through the fix process.
- Application security findings triage: route findings from scanners, penetration tests, and external reviews to the right owners and follow them through to closure in coordination with engineering.
- Over time, take on more of the security review work directly.
- Partner with engineering on AWS hardening by monitoring IAM, VPC/networking, KMS encryption, and logging (CloudTrail), flagging misconfigurations and configuration drift, and helping strengthen alerting and incident response.
What you bring
- 3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibilities.
- Hands-on experience with a compliance framework such as SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS, including audit preparation and evidence management.
- Working knowledge of AWS security fundamentals: IAM, VPC, KMS, and CloudTrail.
- Comfort reading code in Python or TypeScript/JavaScript to understand findings and discuss fixes with engineers.
- Familiarity with vulnerability management and dependency scanning tooling.
- Strong writing and organization, with documentation that can stand up under audit.
- Must reside in the United States and be able to pass the state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information.
Technologies you may work with
Vanta, SOC 2, CJIS, ISO 27001, FedRAMP, HIPAA, AWS, IAM, VPC, KMS, CloudTrail, Python, TypeScript, JavaScript
Nice to have
- Direct CJIS Security Policy experience, or experience supporting government and public-sector customers.
- Experience administering Vanta, Drata, Secureframe, or a comparable GRC platform.
- Experience independently reviewing code or system designs for issues such as broken auth, injection, access control and multi-tenancy boundaries, or secrets handling.
- Relevant security certifications such as Security+, AWS Security Specialty, CCSP, CISSP, or OSCP.
- Experience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform).
- Experience securing data pipelines or ML/AI systems that handle sensitive data.
Role details
Location: Remote (remote)
Pay: From $120,000 USD per year
Benefits: Paid time off