Security Engineer
Firmable's product depends on customer trust in how we handle their data. This role is the operational backbone of that trust: the controls you run are what let 1,000+ customers rely on Firmable with their data.
The Role
As our Security Engineer, you'll own the day-to-day execution of the security controls and policies that keep Firmable compliant against SOC 2 (all five TSC) and ISO 27001:2022. You'll report into the Security & Compliance team, fully remote and open globally. This is a hands-on operational role, not a paper-compliance one: you implement, monitor and continuously tighten the controls auditors and customers actually test against.
~90% hands-on execution: control implementation, continuous monitoring, evidence collection, vulnerability and access management.
~10% cross-functional: partnering with engineering on secure cloud config and shaping the program as it scales across frameworks.
What You'll Own
SOC 2 & ISO 27001 execution: implement and maintain controls across infrastructure, applications and internal systems; close gaps as they're identified
Security policy enforcement: put information security policy into daily practice across engineering and business teams, covering access control, data classification, incident response, vendor risk and change management
Continuous control monitoring: recurring access reviews, log reviews, vulnerability scans and patch cadence checks; organise evidence ahead of audits
Vulnerability management: triage scanner findings, coordinate remediation with engineering, verify closure
Identity & access management: onboarding/offboarding, least-privilege and MFA enforcement, periodic access recertification
Monitoring & incident response: watch security alerts and logs, triage and escalate per the incident response plan
Risk & vendor management: maintain the risk register and third-party risk assessments, track remediation to closure
Audit readiness: prepare evidence for annual assessments and respond to customer security questionnaires
Security awareness: run employee training and phishing simulations
Secure cloud configuration: partner with engineering on least-privilege IAM, encryption at rest and in transit, and secrets management (AWS)
What We're Looking For
Must haves
2–5 years in security engineering, cloud security or infrastructure security, ideally with direct SOC 2 or ISO 27001 exposure
Working knowledge of the SOC 2 Trust Services Criteria and how technical controls map to them
Hands-on cloud security fundamentals (AWS preferred): IAM, logging/monitoring, vulnerability scanning
Comfortable executing policy day to day (access reviews, evidence collection, remediation tracking), not just writing it
Clear written communication and comfortable working async across time zones with a distributed team
Highly valued
Familiarity with GRC automation platforms (Vanta, Drata or similar)
Relevant certification (Security+, CySA+, ISO 27001 Lead Implementer, or progress toward CISA/CISSP)
The Environment
Fully remote, open globally, working closely with a distributed Security and Engineering team across time zones. Real ownership over controls that directly protect customer trust, not a box-ticking exercise. Fast-moving, AI-native product team.
Why This Role
Real ownership: the controls you run directly protect the trust 1,000+ customers place in Firmable's data
Multi-framework exposure from day one: a live SOC 2 and ISO 27001 program, not a single-framework box-tick
Competitive compensation and flexible hours in a fast-moving, AI-native product team
- Department
- R&D - Security, Infra & IT
- Role
- Systems & Security Engineer
- Location
- India (remote)
- Remote status
- Fully Remote