{"schemaVersion":"jobsearcher.job.v1","id":"0914633d39d66e15365d4497","url":"https://jobsearcher.com/jobs/0914633d39d66e15365d4497","canonicalUrl":"https://jobsearcher.com/jobs/0914633d39d66e15365d4497","title":"Security Engineer","description":"About Flash\nFlash AI is a software company serving law enforcement and corrections agencies. We build AI tools that help agencies work through large volumes of investigative and communications data, cutting down the manual review that consumes so much of their staff's time.\nOur customers are state and local government agencies. Work of this kind falls under the FBI's CJIS Security Policy, which sets the requirements for how criminal justice information is stored, accessed, and protected. Meeting those requirements is a standing part of how we operate.\nThe role\nThis is a hands-on role that owns security and compliance at Flash. Your primary mandate is our compliance programs: CJIS and SOC 2. You will own our Vanta instance and the documentation behind our audits, serve as the front line for auditor and customer security reviews, and work alongside our engineering team to keep our application and AWS environment secure.\nWhat you'll do\nOwn SOC 2 and CJIS compliance end to end. Maintain continuous readiness, run the annual SOC 2 audit cycle, and ensure we meet CJIS Security Policy requirements for handling criminal justice information.\nAdminister Vanta as the source of truth for our compliance posture. Manage automated control tests, resolve failing tests, keep integrations healthy, and serve as the primary contact for auditors and customer security reviews.\nMaintain the security documentation set. Policies, procedures, the risk register, access reviews, and incident response plans, kept accurate as the platform evolves.\nRun vulnerability and supply-chain management. Track dependency and container vulnerabilities from our scanning tools, prioritize by real risk, drive them to closure within SLA, and coordinate our third-party penetration tests through remediation.\nTriage application security findings and partner with engineering on fixes. Route findings from scanners, pen tests, and external reviews to the right owners, and follow them to closure. Over time, take on more of the review work yourself.\nPartner with engineering to harden our AWS environment. Track IAM, networking, encryption (KMS), and logging posture; flag misconfigurations and drift; help improve alerting and incident response\nWhat we're looking for\n3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibility.\nHands-on experience with a compliance framework (SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS), including audit preparation and evidence management.\nWorking knowledge of AWS security fundamentals: IAM, VPC/networking, KMS, and CloudTrail.\nComfortable reading code in Python or TypeScript/JavaScript, well enough to understand a security finding and discuss the fix with an engineer.\nFamiliarity with vulnerability management and dependency scanning tooling.\nStrong writing and organization. A large part of this job is documentation that has to hold up under audit.\nMust reside in the United States and be able to pass the state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information.\nNice to have\nDirect CJIS Security Policy experience, or experience supporting government and public-sector customers.\nExperience administering Vanta, Drata, Secureframe, or a comparable GRC platform.\nExperience independently reviewing code or system designs for issues like broken auth, injection, access control and multi-tenancy boundaries, or secrets handling.\nSecurity certifications such as Security+, AWS Security Specialty, CCSP, CISSP, or OSCP.\nExperience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform).\nExperience securing data pipelines or ML/AI systems that handle sensitive data.\nPay: From $120,000.00 per year\nBenefits:\nPaid time off\nWork Location: Remote","company":"Flash Ai","rawCompany":"flash ai","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-07T10:39:55.037Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Engineer","description":"About Flash\nFlash AI is a software company serving law enforcement and corrections agencies. We build AI tools that help agencies work through large volumes of investigative and communications data, cutting down the manual review that consumes so much of their staff's time.\nOur customers are state and local government agencies. Work of this kind falls under the FBI's CJIS Security Policy, which sets the requirements for how criminal justice information is stored, accessed, and protected. Meeting those requirements is a standing part of how we operate.\nThe role\nThis is a hands-on role that owns security and compliance at Flash. Your primary mandate is our compliance programs: CJIS and SOC 2. You will own our Vanta instance and the documentation behind our audits, serve as the front line for auditor and customer security reviews, and work alongside our engineering team to keep our application and AWS environment secure.\nWhat you'll do\nOwn SOC 2 and CJIS compliance end to end. Maintain continuous readiness, run the annual SOC 2 audit cycle, and ensure we meet CJIS Security Policy requirements for handling criminal justice information.\nAdminister Vanta as the source of truth for our compliance posture. Manage automated control tests, resolve failing tests, keep integrations healthy, and serve as the primary contact for auditors and customer security reviews.\nMaintain the security documentation set. Policies, procedures, the risk register, access reviews, and incident response plans, kept accurate as the platform evolves.\nRun vulnerability and supply-chain management. Track dependency and container vulnerabilities from our scanning tools, prioritize by real risk, drive them to closure within SLA, and coordinate our third-party penetration tests through remediation.\nTriage application security findings and partner with engineering on fixes. Route findings from scanners, pen tests, and external reviews to the right owners, and follow them to closure. Over time, take on more of the review work yourself.\nPartner with engineering to harden our AWS environment. Track IAM, networking, encryption (KMS), and logging posture; flag misconfigurations and drift; help improve alerting and incident response\nWhat we're looking for\n3+ years in security, compliance, or IT/cloud engineering with meaningful security responsibility.\nHands-on experience with a compliance framework (SOC 2, ISO 27001, FedRAMP, HIPAA, or CJIS), including audit preparation and evidence management.\nWorking knowledge of AWS security fundamentals: IAM, VPC/networking, KMS, and CloudTrail.\nComfortable reading code in Python or TypeScript/JavaScript, well enough to understand a security finding and discuss the fix with an engineer.\nFamiliarity with vulnerability management and dependency scanning tooling.\nStrong writing and organization. A large part of this job is documentation that has to hold up under audit.\nMust reside in the United States and be able to pass the state and federal fingerprint-based background checks required for CJIS-authorized access to criminal justice information.\nNice to have\nDirect CJIS Security Policy experience, or experience supporting government and public-sector customers.\nExperience administering Vanta, Drata, Secureframe, or a comparable GRC platform.\nExperience independently reviewing code or system designs for issues like broken auth, injection, access control and multi-tenancy boundaries, or secrets handling.\nSecurity certifications such as Security+, AWS Security Specialty, CCSP, CISSP, or OSCP.\nExperience securing containerized workloads, CI/CD pipelines, and infrastructure as code (Terraform).\nExperience securing data pipelines or ML/AI systems that handle sensitive data.\nPay: From $120,000.00 per year\nBenefits:\nPaid time off\nWork Location: Remote","datePosted":"2026-08-07T10:39:55.037Z","dateModified":"2026-08-07T10:39:55.037Z","hiringOrganization":{"@type":"Organization","name":"Flash Ai","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"0914633d39d66e15365d4497"},"url":"https://jobsearcher.com/jobs/0914633d39d66e15365d4497"}}