{"schemaVersion":"jobsearcher.job.v1","id":"92cc1dd3ce41ded3d68ca120","url":"https://jobsearcher.com/jobs/92cc1dd3ce41ded3d68ca120","canonicalUrl":"https://jobsearcher.com/jobs/92cc1dd3ce41ded3d68ca120","title":"Security Engineer (Compliance)","description":"We do Consulting Differently\nSecond Sight Solutions, a subsidiary of Berkeley Research Group (BRG), is a health technology company, and our innovative technology reimagines how drug discount data is exchanged, establishing new connections and improving transparency for drug manufacturers and their customers. Our customers and partners trust us to deliver reliable, first-to-market solutions and safeguard the data we receive. We trust our employees, and our culture gives them the freedom to create, collaborate, and grow. Our leaders are industry experts, creative, unafraid to challenge the status quo, and the pioneers of market-changing solutions.\nWe are seeking a motivated Security Engineer (Compliance) to be an integral part of our Security team! The ideal candidate will be passionate about cyber security and possess both deep and wide expertise in the security space, with specific experience in the application and implementation of Governance, Risk, and Compliance (GRC) programs.\nResponsibilities:\nOwn, manage, and support the application of key compliance frameworks (SOC 1 and 2, ISO 27001, CSA STAR, NIST CSF, etc).\nDevelop, control, and maintain applicable organizational policies, procedures, best practices, and guides associated with key compliance requirements and in support of annual audits.\nAssist in the development and implementation of an internal audit program designed to:\nmeasure the effectiveness of organizational processes and procedures;\nassess organizational adherence to those processes and procedures;\nidentify opportunities for organizational and systemic process improvement; and\nalert the organization about emerging risks to the comprehensive compliance program.\nSupport the Risk Management Program with a goal of making risk-based decisions an integrated part of the cultural landscape, including:\nrisk identification;\nrisk mitigation;\nrisk monitoring;\nrisk reporting; and\ndocumentation of risk realization and/or retirement.\nWork closely with the Security Operations (SecOps) team to ensure security functions meet operational compliance requirements and will meet/exceed independent annual audit standards.\nEnsure technical, operational, and administrative controls are fully operable and meet standards necessary for SOC 1 and 2 audits.\nSupport Quarterly Access Reviews (QARs) as part of the larger User Access Request process.\nQualifications:\n5+ years of proven work experience as a System or Information Security Engineer, Compliance Engineer, or Risk Engineer.\nDetailed technical knowledge of compliance frameworks and their application across systems and organizations.\nThorough understanding of the latest security principles, techniques, and protocols.\nProblem solving skills and ability to work under pressure.\nExperience with compliance frameworks (e.g., SOC 1 and 2, ISO 27001, CSA STAR, NIST CSF).\nFamiliarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and network/web related protocols.\nExperience with cloud services (Microsoft 365, SharePoint Online, Microsoft Azure, and Amazon Web Services).\nOperational understanding of security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, and content.\nIdeal candidates will have a strong risk background that includes:\nrisk identification, adjudication, and mitigation development experience;\nexperience working with engineering teams to document, plan, and address identified risk items;\ndocumentation and communication of identified risks to organizational leadership (up to and include the Executive Leadership Team or ELT);\nregular review and maintenance of residual risk items; and\nownership of risks and the applicable risk lifecycle through risk identification, adjudication, mitigation/reduction, avoidance, transference, realization, and retirement.\n\nCandidate must be able to submit verification of his/her legal right to work in the U.S., without company sponsorship.\nThis position is primarily remote; however, on‑site travel will be required for onboarding, team events, or other business‑driven needs.\nSalary Range: $125,000-$170,000 per year.\n#LI-JQ1\n#LI-Remote\nAbout BRG\n\nBRG combines world-leading academic credentials with world-tested business expertise purpose-built for agility and connectivity, which sets us apart—and gets you ahead.\nAt BRG, our top-tier professionals include specialist consultants, industry experts, renowned academics, and leading-edge data scientists. Together, they bring a diversity of proven real-world experience to economics, disputes, and investigations; corporate finance; and performance improvement services that address the most complex challenges for organizations across the globe.\nOur unique structure nurtures the interdisciplinary relationships that give us the edge, laying the groundwork for more informed insights and more original, incisive thinking from diverse perspectives that, when paired with our global reach and resources, make us uniquely capable to address our clients’ challenges. We get results because we know how to apply our thinking to your world.\nAt BRG, we don’t just show you what’s possible. We’re built to help you make it happen.\nBRG is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, religion, color, sex, gender, national origin, age, United States military veteran status, ancestry, sexual orientation, marital status, family structure, medical condition including genetic characteristics or information, veteran status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law.","company":"Berkeley Research Group","rawCompany":"berkeley research group","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-05T15:43:56.695Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Engineer (Compliance)","description":"We do Consulting Differently\nSecond Sight Solutions, a subsidiary of Berkeley Research Group (BRG), is a health technology company, and our innovative technology reimagines how drug discount data is exchanged, establishing new connections and improving transparency for drug manufacturers and their customers. Our customers and partners trust us to deliver reliable, first-to-market solutions and safeguard the data we receive. We trust our employees, and our culture gives them the freedom to create, collaborate, and grow. Our leaders are industry experts, creative, unafraid to challenge the status quo, and the pioneers of market-changing solutions.\nWe are seeking a motivated Security Engineer (Compliance) to be an integral part of our Security team! The ideal candidate will be passionate about cyber security and possess both deep and wide expertise in the security space, with specific experience in the application and implementation of Governance, Risk, and Compliance (GRC) programs.\nResponsibilities:\nOwn, manage, and support the application of key compliance frameworks (SOC 1 and 2, ISO 27001, CSA STAR, NIST CSF, etc).\nDevelop, control, and maintain applicable organizational policies, procedures, best practices, and guides associated with key compliance requirements and in support of annual audits.\nAssist in the development and implementation of an internal audit program designed to:\nmeasure the effectiveness of organizational processes and procedures;\nassess organizational adherence to those processes and procedures;\nidentify opportunities for organizational and systemic process improvement; and\nalert the organization about emerging risks to the comprehensive compliance program.\nSupport the Risk Management Program with a goal of making risk-based decisions an integrated part of the cultural landscape, including:\nrisk identification;\nrisk mitigation;\nrisk monitoring;\nrisk reporting; and\ndocumentation of risk realization and/or retirement.\nWork closely with the Security Operations (SecOps) team to ensure security functions meet operational compliance requirements and will meet/exceed independent annual audit standards.\nEnsure technical, operational, and administrative controls are fully operable and meet standards necessary for SOC 1 and 2 audits.\nSupport Quarterly Access Reviews (QARs) as part of the larger User Access Request process.\nQualifications:\n5+ years of proven work experience as a System or Information Security Engineer, Compliance Engineer, or Risk Engineer.\nDetailed technical knowledge of compliance frameworks and their application across systems and organizations.\nThorough understanding of the latest security principles, techniques, and protocols.\nProblem solving skills and ability to work under pressure.\nExperience with compliance frameworks (e.g., SOC 1 and 2, ISO 27001, CSA STAR, NIST CSF).\nFamiliarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and network/web related protocols.\nExperience with cloud services (Microsoft 365, SharePoint Online, Microsoft Azure, and Amazon Web Services).\nOperational understanding of security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, and content.\nIdeal candidates will have a strong risk background that includes:\nrisk identification, adjudication, and mitigation development experience;\nexperience working with engineering teams to document, plan, and address identified risk items;\ndocumentation and communication of identified risks to organizational leadership (up to and include the Executive Leadership Team or ELT);\nregular review and maintenance of residual risk items; and\nownership of risks and the applicable risk lifecycle through risk identification, adjudication, mitigation/reduction, avoidance, transference, realization, and retirement.\n\nCandidate must be able to submit verification of his/her legal right to work in the U.S., without company sponsorship.\nThis position is primarily remote; however, on‑site travel will be required for onboarding, team events, or other business‑driven needs.\nSalary Range: $125,000-$170,000 per year.\n#LI-JQ1\n#LI-Remote\nAbout BRG\n\nBRG combines world-leading academic credentials with world-tested business expertise purpose-built for agility and connectivity, which sets us apart—and gets you ahead.\nAt BRG, our top-tier professionals include specialist consultants, industry experts, renowned academics, and leading-edge data scientists. Together, they bring a diversity of proven real-world experience to economics, disputes, and investigations; corporate finance; and performance improvement services that address the most complex challenges for organizations across the globe.\nOur unique structure nurtures the interdisciplinary relationships that give us the edge, laying the groundwork for more informed insights and more original, incisive thinking from diverse perspectives that, when paired with our global reach and resources, make us uniquely capable to address our clients’ challenges. We get results because we know how to apply our thinking to your world.\nAt BRG, we don’t just show you what’s possible. We’re built to help you make it happen.\nBRG is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, religion, color, sex, gender, national origin, age, United States military veteran status, ancestry, sexual orientation, marital status, family structure, medical condition including genetic characteristics or information, veteran status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law.","datePosted":"2026-08-05T15:43:56.695Z","dateModified":"2026-08-05T15:43:56.695Z","hiringOrganization":{"@type":"Organization","name":"Berkeley Research Group","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"92cc1dd3ce41ded3d68ca120"},"url":"https://jobsearcher.com/jobs/92cc1dd3ce41ded3d68ca120"}}