Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
This is a hands-on role that owns security and compliance at Flash. Your primary mandate is our compliance programs: CJIS and SOC 2. You will own our Vanta instance and the documentation behind our audits, serve as the front line for auditor and customer security reviews, and work alongside our engineering team to keep our application and AWS environment secure.
What you’ll do
- Own SOC 2 and CJIS compliance end to end. Maintain continuous readiness, run the annual SOC 2 audit cycle, and ensure we meet CJIS Security Policy requirements for handling criminal justice information.
- Administer Vanta as the source of truth for our compliance posture. Manage automated control tests, resolve failing tests, keep integrations healthy, and serve as the primary contact for auditors and customer security reviews.
- Maintain the security documentation set. Policies, procedures, the risk register, access reviews, and incident response plans, kept accurate as the platform evolves.
- Run vulnerability and supply-chain management. Track dependency and container vulnerabilities from our scanning tools, prioritize by real risk, drive them to closure within SLA, and coordinate our third-party penetration tests through remediation.
- Triage application security findings and partner with engineering on fixes. Route findings from scanners, pen tests, and external reviews to the right owners, and follow them to closure. Over time, take on more of the review work yourself.
- Partner with engineering to harden our AWS environment. Track IAM, networking, encryption (KMS), and logging posture; flag misconfigurations and drift; help improve alerting and incident response
Requirements
- 3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibility.
- Hands-on experience with a compliance framework (SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS), including audit preparation and evidence management.
- Working knowledge of AWS security fundamentals: IAM, VPC/networking, KMS, and CloudTrail.
- Comfortable reading code in Python or TypeScript/JavaScript, well enough to understand a security finding and discuss the fix with an engineer.
- Familiarity with vulnerability management and dependency scanning tooling.
- Strong writing and organization. A large part of this job is documentation that has to hold up under audit.
- Must reside in the United States and be able to pass the state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information.
Nice to have
- Direct CJIS Security Policy experience, or experience supporting government and public-sector customers.
- Experience administering Vanta, Drata, Secureframe, or a comparable GRC platform.
- Experience independently reviewing code or system designs for issues like broken auth, injection, access control and multi-tenancy boundaries, or secrets handling.
- Security certifications such as Security+, AWS Security Specialty, CCSP, CISSP, or OSCP.
- Experience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform).
- Experience securing data pipelines or ML/AI systems that handle sensitive data.
Benefits & conditions
Pulled from the full job description Paid time off, * Paid time off
About the company
Flash AI is a software company serving law enforcement and corrections agencies. We build AI tools that help agencies work through large volumes of investigative and communications data, cutting down the manual review that consumes so much of their staff’s time.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 138 - Are you secure about this?
Understanding and Mitigating Common Web Vulnerabilities
The Overflow: Security and Privacy