Compliance Engineering Lead
Socket
- Location
- United States
- Employment
- Full Time
- Work model
- Remote
- Level
- Senior
- Posted
- 1h ago
Skills
About this role
About Us
Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our customers - from Anthropic to xAI, and Figma to Vercel - love Socket (just check out their tweets to see for yourself!) Founded by Feross Aboukhadijeh , a long-time open source maintainer with software downloaded over a billion times a month, Socket has raised $ 125M in funding from top angels, operators, and security leaders.
About the Role
We are hiring a Compliance Engineering Lead to own compliance as an engineered system rather than a calendar of reminders. Socket sells to security teams. Our customers ask harder questions than most buyers ask, and they are right to. That means our SOC 2 Type II, our path to ISO 27001, our risk and vendor programs, and the assurance artifacts we put in front of enterprise buyers all have to be genuinely well run, not merely present. The credibility of what we sell depends on it. This is a foundational role, and it is deliberately an engineering role. The person we want does not manage compliance by chasing people for screenshots. They write code against APIs, build control tests that run on a schedule and fail loudly, and treat evidence collection as a pipeline with an owner and an SLA. You will own the compliance platform decision, including whether the platform we use today is the right one. If your answer is that we should build more of it ourselves, make that case. You will report directly to the CISO, own the compliance program end to end, and hire and lead your first teammate, a customer trust hire focused on security questionnaires, RFPs, and contract security review with Legal. You will shape what GRC at Socket becomes.
What You'll Do
Own SOC 2 Type II end to end. Run the observation window, the auditor relationship, and the evidence pipeline behind both. Scope the audit and make sure the controls we describe are the controls that actually run. You own the report our customers read. Take Socket through ISO 27001 certification. Define the scope and the ISMS, run the gap assessment and internal audit, prepare the organization and get us certified. Enterprise customers are asking for this now. Then keep the ISMS alive as something the company uses rather than something the auditor visits. Make evidence collection continuous, automated, and boring. Write and maintain automation that pulls evidence directly from the systems of record: GCP, GitHub, our identity provider, MDM, ticketing. Build control monitoring that alerts on drift the day it happens instead of surfacing it the week before an audit. Every recurring manual task you inherit is a candidate for deletion. Turn risk management and vendor risk into working programs. Maintain a risk register that reflects the risks we actually carry and that leadership uses when making decisions. In partnership with our external security partner, run third party risk with real tiering, real reviews, and a renewal cadence that holds. Own the customer-facing assurance surface. Launch and maintain our trust portal, and build the library of artifacts that answers enterprise buyers before they send a spreadsheet. Measure your success by how much questionnaire load disappears, not by how quickly it gets processed. Scope our AI assurance posture. Our customers are shipping AI systems and so are we. Evaluate what matters: ISO/IEC 42001, emerging AI agent assurance standards such as AIUC-1, the EU AI Act, and the NIST AI Risk Management Framework. Inform which of these to commit to, in what order, and what it would take. This is open ground and you will help decide what Socket does here.
What You'll Bring
You have personally owned at least two full SOC 2 Type II cycles as the accountable person. Not contributed to them. Owned them, including the auditor relationship, the scoping arguments, the evidence, and the findings. You can describe a control that failed, why, and what you