Senior Security & Compliance Engineer

ZooLATECH
ZooLATECH
Central EuropePresencialCompetitivoPublicado hace 8 días
🇬🇧Inglés requerido
ZooLATECH

Senior Security & Compliance Engineer

Anuncio original

Our client is a purpose-driven software company focused on the social impact sector, building innovative SaaS solutions that empower nonprofits, donors, and communities to operate more efficiently and maximize their impact.

We're hiring an experienced Senior Security & Compliance Engineer who drives security hardening and compliance certification readiness for a CSR platform. The work spans SOC certification preparation, GDPR compliance implementation, data residency architecture, and Auth0-based authentication and authorization patterns. This is hands-on engineering, not advisory - you write code, configure infrastructure, and build security controls.

What You Will Build

  • SOC 1 Type II and SOC 2 Type II certification readiness (controls implementation, evidence collection automation)

  • GDPR cross-border data transfer safeguards and data subject rights APIs

  • Data residency controls for multi-region expansion

  • Auth0 tenant federation and SSO configuration (SAML 2.0, OIDC)

  • SCIM-based user lifecycle provisioning

  • Role-based and attribute-based access control enforcement in API middleware

  • Audit logging with tamper protection and 7-year retention compliance

  • PCI DSS compliance validation (SAQ-A level, Stripe integration)

  • Security monitoring: CloudWatch-based alerting, log export for customer-facing compliance

Required Skills

  • Expert use of AI-assisted development tools (Copilot, Claude, Cursor, or equivalent)

  • Auth0 administration and integration (tenant configuration, federation, token validation)

  • OAuth2 / OIDC / SAML 2.0 implementation

  • RBAC and ABAC modeling for multi-tenant SaaS

  • SOC 2 Type II controls - practical implementation, not just audit familiarity

  • GDPR technical compliance (deletion APIs, consent tracking, cross-border safeguards)

  • AWS security services: IAM, KMS, Secrets Manager, CloudWatch, VPC security groups

  • TypeScript / Node.js (for security middleware and API enforcement)

  • Aurora PostgreSQL (field-level encryption, row-level security)

Nice to Have

  • SOC 1 Type II experience

  • PCI DSS (SAQ-A or higher)

  • Data residency architecture for multi-region SaaS

  • ISO 27001 familiarity

Candidatura gestionada por ZooLATECH