Enter a job title or keyword

Security & Compliance Lead

SunCore Digital


Job Location:

Scottsdale, AZ - USA

Yearly Salary: USD 150000 - 190000
Posted: 1 October 2026 (Yesterday)
Application Deadline: 29 December 2026
Vacancies: 1 Vacancy

Job Summary

## Location: Remote (Global) HQ: Bellevue WA## Team: Engineering## Type: Full-Time Deferred Compensation Bonuses## Reports To: Chief Technology OfficerWe are looking for a Security & Compliance Lead to take SunCore Digital to a SOC 2 attestation and own our security compliance program end to end. SOC 2 is an audit performed by an outside licensed firm; your job is everything that makes that audit succeed. You will define the audit scope with the CTO assess where we stand today against the Trust Services Criteria across our web platform and mobile apps close the gaps and manage the auditor relationship through to the final report. You will write the policies stand up continuous evidence collection and coordinate the technical work with our engineers who implement the controls in code and infrastructure. This is an ownership role with checks built in: scope spend and major control decisions are approved by the CTO and your program is expected to hold up under challenge from the engineers who live with it every day. This is a remote-first role with deferred compensation until 60 days post-MVP launch plus equity bonuses and annual offsite perks. We value speed ownership and collaborative energy.## What Youll Do- Define the SOC 2 audit scope with the CTO: which Trust Services Criteria we attest to and whether we pursue a Type I report a Type II report or both in sequence- Run a readiness assessment across the web platform the mobile apps our infrastructure and our vendors and publish the gap list with owners and dates- Author and maintain the policy set: access control change management incident response vendor management business continuity and data handling- Select and deploy a compliance automation platform so evidence is collected continuously by systems rather than assembled by hand before the audit- Coordinate remediation with engineering: you define each control and the evidence it must produce engineers implement it and you verify it works- Select the licensed CPA firm negotiate the engagement and manage the audit from kickoff through the observation window to the final report- Run security awareness training and the onboarding and offboarding controls for the whole company not just engineering- Stand up vendor risk review for the third-party services the platform depends on- Coordinate the penetration test: vendor selection scoping scheduling and tracking findings to closure- Report status risks and audit blockers directly to the CTO in plain language- After the first report: own the annual audit cycle and keep evidence collection continuous so the second year is routine instead of a scramble## What You Bring- 7 years in information security or governance risk and compliance including at least one SOC 2 program taken from no report to a completed Type II as the internal owner not as an outside consultant who left before the audit- Working command of the Trust Services Criteria and how auditors actually test them including mapping controls to the evidence that proves them- Hands-on experience deploying a compliance automation platform such as Vanta Drata or Secureframe- Enough technical depth to hold your own with engineers: you can read an architecture diagram understand cloud access models CI/CD pipelines and mobile release processes and tell a real control from a paper one- Policy writing that people actually follow: short specific and enforceable- Experience scoping and managing external auditors and penetration test vendors- A track record of getting compliance work done through engineers you do not manage- Clear written communication since the audit is won or lost in documents- Bonus: experience in fintech or digital assets or extending a program beyond SOC 2 into ISO 27001 or privacy regimes such as GDPR and CCPA## Compensation & Benefits- Competitive pay range:- Offshore mid-senior rates:- Deferred compensation model: All development team compensation is deferred until 60 days post-MVP launch to align incentives everyone is focused on shipping fast- Annual performance bonus (significant portion of total comp)- Milestone bonuses tied to product delivery- Health dental and vision plans for U.S.-based hires- Annual paid offsite (Caribbean Hawaii ski destinations)## Why Join UsYou will build our security compliance program from its foundation and take the company to its first SOC 2 report with a direct line to the CTO and engineers who treat security findings as work to do rather than criticism to deflect. If owning a program end to end from scope to signed report is the kind of work you want we would love to meet you.## Apply now or reach out directly (mailto:)