Driving ISO 27001 certification and SOC 2 attestation initiatives, the full-time Senior IT Security Engineer will manage compliance efforts, implement security standards, and collaborate cross-functionally to ensure audit readiness for a SaaS product launch in a remote work environment. Key responsibilities Lead end-to-end ISO 27001 and SOC 2 certification processes, including gap analysis, control design, and audit coordination Develop and manage the GRC program, conducting risk assessments and producing compliance reporting for leadership Define and enforce IAM standards and implement SIEM platforms for security monitoring and threat visibility Required qualifications 8+ years of experience in information security, cybersecurity engineering, or a GRC-focused role Hands-on experience with ISO 27001 and SOC 2 audit and certification processes Prior experience in a B2B SaaS company with responsibilities in product and corporate IT security Strong knowledge of compliance frameworks including ISO 27001, SOC 2, and NIST CSF Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience)