UserGems logo
UserGems·

Senior Security Engineer - UserGems

Fully remoteFull-timeSenior€86K - €108KUTC+0–+3AsyncEurope#security#compliance#awsHealth

UserGems is the AI Command Center for outbound and ABM, capturing account and buying signals to help companies target, engage, and convert at scale. We are looking for a Senior Security Engineer to operate our security and compliance program day-to-day, partnering with the Sr. Director on direction and strategy.

As UserGems' single dedicated security person, you will take over the operational majority of compliance and security work, focusing heavily on SOC 2, ISO standards, customer security reviews, and Drata-driven remediation in AWS.

What You'll Do

  • Own SOC 2: Keep Drata green and audits clean.
  • Lead Compliance: Drive ISO 27001 implementation, followed by ISO 42001.
  • Manage Customer Security Reviews: Run the questionnaire process via SafeBase and Trust Center to unblock revenue.
  • Drata-Driven AWS Remediation: Action simple Drata findings directly in AWS (IAM, S3, KMS, audit trails).
  • Vulnerability Management: Oversee and extend existing scanner-findings automation in Linear and hit SLAs.
  • Secure Code Review: Spot-check high-risk features and new repositories (especially AI/LLM systems) before production.
  • Threat Detection & Response: Tune GuardDuty findings, evaluate central logging/SIEM, run tabletop exercises, and mature the IRP.
  • Offensive Security: Run annual external pen tests, perform internal pen tests, and handle bug bounty reports.
  • Access Management: Own onboarding and offboarding access provisioning and revocation.

AI Security & Governance

  • ISO 42001 Readiness: Build AI governance from scratch.
  • Model & Data Governance: Secure Gem-E and self-hosted LLMs on Azure (data residency, prompt-injection threat modeling, access controls).
  • Internal AI Tooling: Shape guardrails, access boundaries, and monitoring for internal AI tools built by non-engineering teams.

Tech Stack

  • Cloud: AWS (primary), Azure (self-hosted LLMs)
  • Compliance / GRC: Drata, SafeBase, Linear
  • Detection / Endpoint: AWS GuardDuty, CrowdStrike Complete
  • Scanners: GitHub, AWS Inspector, ZAP

What We're Looking For

  • Non-negotiable: Personally owned a SOC 2 or ISO audit end-to-end as the operational owner, delivering a zero-exception report.
  • Working AWS knowledge (IAM, S3, KMS, CloudTrail).
  • Ability to understand and work with Terraform using AI assistance.
  • High ownership, excellent written English, and comfort with async collaboration.
  • Experience in a startup environment where you ship and move on.

Timezone overlap

UTC+0–+3

Culture

Async-friendly

Benefits

Health

Open to

Europe

Sign in to track applications and earn points.

More roles at UserGems

Similar remote roles