Summary
Epsilon ASI is seeking a Security & Compliance Engineer to help develop and maintain secure, compliant cloud-based technology environments. The role focuses on security testing, vulnerability assessments, compliance controls, documentation, audit readiness, and collaboration with engineering teams to address security risks.
Responsibilities
- Support security and compliance initiatives across cloud-based environments
- Conduct and support web application penetration testing and vulnerability assessments
- Help implement and maintain security controls aligned with applicable compliance frameworks
- Work with cloud environments such as AWS GovCloud, with equivalent experience in GCP or Azure also considered
- Assist with security documentation, assessments, remediation efforts, and audit readiness
- Collaborate with engineering and technical teams to identify and address security risks
- Translate compliance requirements into practical technical controls and processes
- Support continuous improvement of security posture and compliance programs
Skills
- • 1+ year of professional experience in security engineering, cybersecurity, compliance engineering, or a related field
- • Hands-on experience with web penetration testing or application security
- • Experience working with AWS GovCloud or comparable environments in GCP or Azure
- • Working knowledge of security and compliance frameworks, including:
- + NIST
- + CMMC
- + SOC 2
- + FedRAMP
- • Ability to speak confidently and accurately about security controls, compliance requirements, and applicable frameworks
- • Strong analytical and problem-solving skills
- • Ability to work independently in a remote environment and collaborate effectively with engineering teams
- • FedRAMP experience — highly valued
- • Experience supporting government, federal, or regulated customers
- • Active or previously held security clearance
- • Experience with cloud security, vulnerability management, or security automation
- • Familiarity with security documentation and audit/compliance processes
Qualifications
Must Haves
- • 1+ year of professional experience in security engineering, cybersecurity, compliance engineering, or a related field
- • Hands-on experience with web penetration testing or application security
- • Experience working with AWS GovCloud or comparable environments in GCP or Azure
- • Working knowledge of security and compliance frameworks, including:
- + NIST
- + CMMC
- + SOC 2
- + FedRAMP
- • Ability to speak confidently and accurately about security controls, compliance requirements, and applicable frameworks
- • Strong analytical and problem-solving skills
- • Ability to work independently in a remote environment and collaborate effectively with engineering teams
Nice to Haves
- • FedRAMP experience — highly valued
- • Experience supporting government, federal, or regulated customers
- • Active or previously held security clearance
- • Experience with cloud security, vulnerability management, or security automation
- • Familiarity with security documentation and audit/compliance processes
Benefits