Security & Compliance Lead
- Salary
- $150K–$190KUSD per year
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Sep 29, 2026
## Location: Remote (Global) HQ: Bellevue, WA ## Team: Engineering ## Type: Full-Time Deferred Compensation + Bonuses ## Reports To: Chief Technology Officer We are looking for a Security & Compliance Lead to take SunCore Digital to a SOC 2 attestation and own our security compliance program end to end. SOC 2 is an audit performed by an outside licensed firm; your job is everything that makes that audit succeed. You will define the audit scope with the CTO, assess where we stand today against the Trust Services Criteria across our web platform and mobile apps, close the gaps, and manage the auditor relationship through to the final report. You will write the policies, stand up continuous evidence collection, and coordinate the technical work with our engineers, who implement the controls in code and infrastructure. This is an ownership role with checks built in: scope, spend, and major control decisions are approved by the CTO, and your program is expected to hold up under challenge from the engineers who live with it every day. This is a remote-first role with deferred compensation until 60 days post-MVP launch, plus equity, bonuses, and annual offsite perks. We value speed, ownership, and collaborative energy. ## What You'll Do - Define the SOC 2 audit scope with the CTO: which Trust Services Criteria we attest to, and whether we pursue a Type I report, a Type II report, or both in sequence - Run a readiness assessment across the web platform, the mobile apps, our infrastructure, and our vendors, and publish the gap list with owners and dates - Author and maintain the policy set: access control, change management, incident response, vendor management, business continuity, and data handling - Select and deploy a compliance automation platform so evidence is collected continuously by systems rather than assembled by hand before the audit - Coordinate remediation with engineering: you define each control and the evidence it must produce, engineers implement it, and you verify it works - Select the licensed CPA firm, negotiate the engagement, and manage the audit from kickoff through the observation window to the final report - Run security awareness training and the onboarding and offboarding controls for the whole company, not just engineering - Stand up vendor risk review for the third-party services the platform depends on - Coordinate the penetration test: vendor selection, scoping, scheduling, and tracking findings to closure - Report status, risks, and audit blockers directly to the CTO in plain language - After the first report: own the annual audit cycle and keep evidence collection continuous, so the second year is routine instead of a scramble ## What You Bring - 7+ years in information security or governance, risk, and compliance, including at least one SOC 2 program taken from no report to a completed Type II as the internal owner, not as an outside consultant who left before the audit - Working command of the Trust Services Criteria and how auditors actually test them, including mapping controls to the evidence that proves them - Hands-on experience deploying a compliance automation platform such as Vanta, Drata, or Secureframe - Enough technical depth to hold your own with engineers: you can read an architecture diagram, understand cloud access models, CI/CD pipelines, and mobile release processes, and tell a real control from a paper one - Policy writing that people actually follow: short, specific, and enforceable - Experience scoping and managing external auditors and penetration test vendors - A track record of getting compliance work done through engineers you do not manage - Clear written communication, since the audit is won or lost in documents - Bonus: experience in fintech or digital assets, or extending a program beyond SOC 2 into ISO 27001 or privacy regimes such as GDPR and CCPA ## Compensation & Benefits - Competitive pay range: - Offshore mid-senior rates: - Deferred compensation model: All development team compensation is deferred until 60 days post-MVP launch to align incentives, everyone is focused on shipping fast - Annual performance bonus (significant portion of total comp) - Milestone bonuses tied to product delivery - Health, dental, and vision plans for U.S.-based hires - Annual paid offsite (Caribbean, Hawaii, ski destinations) ## Why Join Us You will build our security compliance program from its foundation and take the company to its first SOC 2 report, with a direct line to the CTO and engineers who treat security findings as work to do rather than criticism to deflect. If owning a program end to end, from scope to signed report, is the kind of work you want, we would love to meet you. ## Apply now or reach out directly to [sphillips@suncoredigital.com](mailto:sphillips@suncoredigital.com)