Security Engineer

Flash, Inc
United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$120,000.0
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Amazon Web Services Software System Penetration Testing Cloud Engineering Identity and Access Management Python (Programming Language) TypeScript Software Vulnerability Management Data Logging Software Security Amazon Virtual Private Cloud (VPC) Containerization
+3 more
Tenable Nessus Terraform Data Pipelines

Job description

This is a hands-on role that owns security and compliance at Flash. Your primary mandate is our compliance programs: CJIS and SOC 2. You will own our Vanta instance and the documentation behind our audits, serve as the front line for auditor and customer security reviews, and work alongside our engineering team to keep our application and AWS environment secure.

What you’ll do

  • Own SOC 2 and CJIS compliance end to end. Maintain continuous readiness, run the annual SOC 2 audit cycle, and ensure we meet CJIS Security Policy requirements for handling criminal justice information.
  • Administer Vanta as the source of truth for our compliance posture. Manage automated control tests, resolve failing tests, keep integrations healthy, and serve as the primary contact for auditors and customer security reviews.
  • Maintain the security documentation set. Policies, procedures, the risk register, access reviews, and incident response plans, kept accurate as the platform evolves.
  • Run vulnerability and supply-chain management. Track dependency and container vulnerabilities from our scanning tools, prioritize by real risk, drive them to closure within SLA, and coordinate our third-party penetration tests through remediation.
  • Triage application security findings and partner with engineering on fixes. Route findings from scanners, pen tests, and external reviews to the right owners, and follow them to closure. Over time, take on more of the review work yourself.
  • Partner with engineering to harden our AWS environment. Track IAM, networking, encryption (KMS), and logging posture; flag misconfigurations and drift; help improve alerting and incident response

Requirements

  • 3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibility.
  • Hands-on experience with a compliance framework (SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS), including audit preparation and evidence management.
  • Working knowledge of AWS security fundamentals: IAM, VPC/networking, KMS, and CloudTrail.
  • Comfortable reading code in Python or TypeScript/JavaScript, well enough to understand a security finding and discuss the fix with an engineer.
  • Familiarity with vulnerability management and dependency scanning tooling.
  • Strong writing and organization. A large part of this job is documentation that has to hold up under audit.
  • Must reside in the United States and be able to pass the state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information.

Nice to have

  • Direct CJIS Security Policy experience, or experience supporting government and public-sector customers.
  • Experience administering Vanta, Drata, Secureframe, or a comparable GRC platform.
  • Experience independently reviewing code or system designs for issues like broken auth, injection, access control and multi-tenancy boundaries, or secrets handling.
  • Security certifications such as Security+, AWS Security Specialty, CCSP, CISSP, or OSCP.
  • Experience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform).
  • Experience securing data pipelines or ML/AI systems that handle sensitive data.

Benefits & conditions

Pulled from the full job description Paid time off, * Paid time off

About the company

Flash AI is a software company serving law enforcement and corrections agencies. We build AI tools that help agencies work through large volumes of investigative and communications data, cutting down the manual review that consumes so much of their staff’s time.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:00 min

Misconceptions about TypeScript safety capabilities

Simone Sanfratello · JS Congress

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all