Epsilon ASI
Security & Compliance Engineer
United States · Posted 19h ago
Job Description
About the Role
We are seeking a Security & Compliance Engineer to support the development and maintenance of secure, compliant technology environments. This role is ideal for an early-career security professional who has hands-on experience with security testing, cloud environments, and compliance frameworks and is looking to grow within a highly technical environment.
The ideal candidate will bring a strong understanding of security and compliance standards, with particular value placed on FedRAMP experience and experience working with government or highly regulated environments.
What You'll Do
Support security and compliance initiatives across cloud-based environments.
Conduct and support web application penetration testing and vulnerability assessments.
Help implement and maintain security controls aligned with applicable compliance frameworks.
Work with cloud environments such as AWS GovCloud, with equivalent experience in GCP or Azure also considered.
Assist with security documentation, assessments, remediation efforts, and audit readiness.
Collaborate with engineering and technical teams to identify and address security risks.
Translate compliance requirements into practical technical controls and processes.
Support continuous improvement of security posture and compliance programs.
What We're Looking For
1+ year of professional experience in security engineering, cybersecurity, compliance engineering, or a related field.
Hands-on experience with web penetration testing or application security.
Experience working with AWS GovCloud or comparable environments in GCP or Azure.
Working knowledge of security and compliance frameworks, including:
NIST
CMMC
SOC 2
FedRAMP
Ability to speak confidently and accurately about security controls, compliance requirements, and applicable frameworks.
Strong analytical and problem-solving skills.
Ability to work independently in a remote environment and collaborate effectively with engineering teams.
Preferred Qualifications
FedRAMP experience — highly valued.
Experience supporting government, federal, or regulated customers.
Active or previously held security clearance.
Experience with cloud security, vulnerability management, or security automation.
Familiarity with security documentation and audit/compliance processes.
What Will Set You Apart
We're particularly interested in candidates who can go beyond simply listing compliance frameworks on a resume. The strongest candidates will be able to fluently discuss NIST, CMMC, SOC 2, and FedRAMP, explain how the frameworks differ, and connect compliance