> Markdown version of [/jobs/ext/1911821-security-engineer](https://www.wearedevelopers.com/jobs/ext/1911821-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Flash, Inc - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $120,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Amazon Web Services, Software System Penetration Testing, Cloud Engineering, Identity and Access Management, Python (Programming Language), TypeScript, Software Vulnerability Management, Data Logging, Software Security, Amazon Virtual Private Cloud (VPC), Containerization, Tenable Nessus, Terraform, Data Pipelines - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e3a23ea707a93262 ## About the Role * 3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibility. * Hands-on experience with a compliance framework (SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS), including audit preparation and evidence management. * Working knowledge of AWS security fundamentals: IAM, VPC/networking, KMS, and CloudTrail. * Comfortable reading code in Python or TypeScript/JavaScript, well enough to understand a security finding and discuss the fix with an engineer. * Familiarity with vulnerability management and dependency scanning tooling. * Strong writing and organization. A large part of this job is documentation that has to hold up under audit. * Must reside in the United States and be able to pass the state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information. Nice to have * Direct CJIS Security Policy experience, or experience supporting government and public-sector customers. * Experience administering Vanta, Drata, Secureframe, or a comparable GRC platform. * Experience independently reviewing code or system designs for issues like broken auth, injection, access control and multi-tenancy boundaries, or secrets handling. * Security certifications such as Security+, AWS Security Specialty, CCSP, CISSP, or OSCP. * Experience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform). * Experience securing data pipelines or ML/AI systems that handle sensitive data. ## Description This is a hands-on role that owns security and compliance at Flash. Your primary mandate is our compliance programs: CJIS and SOC 2. You will own our Vanta instance and the documentation behind our audits, serve as the front line for auditor and customer security reviews, and work alongside our engineering team to keep our application and AWS environment secure. What you'll do * Own SOC 2 and CJIS compliance end to end. Maintain continuous readiness, run the annual SOC 2 audit cycle, and ensure we meet CJIS Security Policy requirements for handling criminal justice information. * Administer Vanta as the source of truth for our compliance posture. Manage automated control tests, resolve failing tests, keep integrations healthy, and serve as the primary contact for auditors and customer security reviews. * Maintain the security documentation set. Policies, procedures, the risk register, access reviews, and incident response plans, kept accurate as the platform evolves. * Run vulnerability and supply-chain management. Track dependency and container vulnerabilities from our scanning tools, prioritize by real risk, drive them to closure within SLA, and coordinate our third-party penetration tests through remediation. * Triage application security findings and partner with engineering on fixes. Route findings from scanners, pen tests, and external reviews to the right owners, and follow them to closure. Over time, take on more of the review work yourself. * Partner with engineering to harden our AWS environment. Track IAM, networking, encryption (KMS), and logging posture; flag misconfigurations and drift; help improve alerting and incident response ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)