UP.Labs logo

Senior Security Controls and Compliance Engineer

UP.Labs

Remote
Contract
Senior
7+ yrs
Salary not listedPosted 4w ago

Real job — pulled straight from UP.Labs’s careers page · Verified July 15, 2026 · No reposts.

Job description

UP.Labs is hiring a Senior Security Controls and Compliance Engineer — a contract, remote role. Apply directly on UP.Labs's careers page below.

Sr. Security Controls & Compliance Engineer (Contract)

Location: Remote

Department: Engineering

Location Type: REMOTE

Employment Type: CONTRACT

About the Role


UP.Labs is a venture studio that builds and launches vertical AI enterprise SaaS companies with corporate partners in transportation, mobility, logistics, and industrial markets. We are hiring a Senior Security Controls & Compliance Engineer on a 6+ month contract to build, implement, and operate the security control foundation across multiple venture applications.


This is a hands-on security execution role. We are not looking for someone who documents gaps, manages a compliance tool, and routes work to engineering. We need an operator who can understand enterprise customer security requirements, identify the controls required, implement or configure those controls directly, and verify they are operating effectively.
You will prepare our venture applications for SOC 2 readiness while supporting enterprise customer data, information security, and TPRM requirements. Because our ventures are built alongside large corporate partners, the security bar is set by real enterprise buyers from day one, not by an internal checklist.
The goal is a repeatable security baseline that each venture application can inherit, operate against, and carry forward as it matures or spins out into an independent company.


What You'll Own


Given the contract timeline, you should expect to operate independently across both the technical implementation and the compliance and customer-facing sides of security. Specifically, you will:
  • Build, implement, and operate security and compliance controls across multiple venture applications and supporting systems.
  • Translate enterprise customer security, data handling, and TPRM requirements into practical technical controls, operational workflows, evidence requirements, and remediation plans.
  • Create a reusable security control baseline that can be applied across current and future venture applications.
  • Select, configure, and operate a compliance automation platform (evaluating options such as Vanta, Drata, or Secureframe), including evidence integrations across cloud, GitHub, identity providers, ticketing, device management, and productivity tools.
  • Implement identity and access controls: SSO, MFA, role-based access, least privilege, access review workflows, and offboarding evidence.
  • Implement secure SDLC controls: branch protection, required code reviews, code scanning, dependency scanning, secret scanning, vulnerability management, and release/change management evidence.
  • Implement cloud security controls: IAM policies, encryption settings, logging, monitoring, backups, network restrictions, and security alerting.
  • Implement operational security workflows: vendor review, risk review, change management, policy attestation, incident response evidence, exception tracking, and recurring control reviews.
  • Maintain a centralized control library mapped to SOC 2 Trust Services Criteria, customer-specific requirements, and relevant frameworks (ISO 27001, NIST CSF, CIS Controls).
  • Support SOC 2 readiness end to end: control mapping, evidence requirements, gap tracking, audit prep, and control verification.
  • Identify launch-blocking security gaps and close them directly where possible.
  • Partner with product engineering only where application-specific code, architecture, or deeper infrastructure changes are required, writing clear technical requirements and acceptance criteria for that work.
  • Support customer security questionnaires, audits, evidence requests, and enterprise security reviews with accurate technical detail.
  • Track control gaps, remediation status, launch blockers, and compliance risk for leadership.
  • Produce a repeatable security implementation playbook that future ventures can inherit, and support the handoff of a venture's security posture when it spins out.


What Success Looks Like


  • Enterprise customer requirements are translated into implemented controls, not just documented gaps.
  • Each venture application has a working security baseline across identity, cloud, source control, CI/CD, logging, monitoring, evidence, and operational processes.
  • SOC 2 readiness is actively tracked with clear control ownership, evidence collection, and operating cadence.
  • Compliance tooling is selected, configured, and producing useful evidence across the required systems.
  • Engineering teams are engaged only when product-specific implementation is required, not overloaded with generic security tasks.
  • Security launch blockers are identified early, prioritized clearly, and remediated quickly.
  • Customer security reviews, audits, and questionnaires are handled with accurate technical detail and supporting evidence.
  • Leadership has clear visibility into control maturity, launch risk, audit readiness, and open remediation items.
  • A reusable security control baseline and playbook exists that can be applied to new ventures and carried forward as they spin out.


Required Qualifications


  • 7+ years in security engineering, cloud security, DevSecOps, security operations, security compliance, or GRC, including hands-on control implementation in cloud/SaaS environments.
  • At least one full SOC 2 readiness-through-audit cycle owned or driven end to end.
  • Demonstrated ability to configure and operate security and compliance systems directly, not just document requirements.
  • Strong command of security controls, audit evidence, policy requirements, control testing, and control operation.
  • Proven experience translating enterprise customer security requirements into practical technical controls.
  • Hands-on experience with identity and access controls (SSO, MFA, RBAC, least privilege, access reviews, offboarding).
  • Hands-on experience with secure SDLC controls (source control permissions, code review, branch protection, vulnerability management, dependency and secret scanning, change management evidence).
  • Hands-on experience with cloud security controls (IAM, encryption, logging, monitoring, backups, network restrictions, alerting).
  • Experience standing up and operating a compliance automation / GRC platform (e.g., Vanta, Drata, Secureframe) from scratch.
  • Familiarity with our core stack: GitHub, Jira or Linear, Okta, Google Workspace, Slack, and a major cloud provider (AWS, Azure, or GCP).
  • Strong written communication for policies, procedures, audit documentation, technical requirements, and customer-facing security responses.
  • Ability to operate independently in an ambiguous, fast-moving venture environment and deliver on a compressed timeline.


Preferred Qualifications


  • Experience supporting enterprise customers with strict security, data handling, or TPRM requirements.
  • Experience in venture-backed startups, enterprise SaaS, or venture studio environments.
  • Experience carving a company's security posture out of a parent or shared-services environment during a spin-out or standalone build.
  • Familiarity with SOC 2 Trust Services Criteria, ISO 27001, NIST CSF, or CIS Controls.
  • Experience with GitHub security features, CI/CD security controls, vulnerability management tools, and cloud security monitoring.
  • Relevant certifications: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, AWS Security Specialty, or Security+.


Get Security Engineer jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Northmark logo

Security Operations Centre Supervisor

Spartanburg, SC
✓ From careers page· 25m ago
Bankjoy logo

Vice President of Systems Engineering (Remote)

Remote · US-eligible
✓ From careers page· 40m ago
Bankjoy logo

VP of Systems Engineering

Toronto, ON
✓ From careers page· 40m ago
Alpaca logo

Lead, Data Governance (Remote)

Remote · US +3
✓ From careers page· 2h ago

Frequently asked questions

Is Senior Security Controls and Compliance Engineer at UP.Labs a remote job?

Yes, Senior Security Controls and Compliance Engineer at UP.Labs is a remote position. This role is open to remote candidates.

What skills are required for Senior Security Controls and Compliance Engineer at UP.Labs?

The required skills for Senior Security Controls and Compliance Engineer at UP.Labs include: SOC 2, IAM, ISO 27001, AWS, Azure, GCP, GitHub, JIRA, Google Workspace, Slack, CISSP, CISM, CISA, CompTIA Security+.

What is the seniority level for Senior Security Controls and Compliance Engineer at UP.Labs?

Senior Security Controls and Compliance Engineer at UP.Labs is a Senior level position.

How do I apply for Senior Security Controls and Compliance Engineer at UP.Labs?

You can view the full description and apply for Senior Security Controls and Compliance Engineer at UP.Labs on EchoJobs: https://echojobs.io/job/up-labs-sr-security-controls-compliance-engineer-contract-qniq8.