1

Security Compliance Engineer Jobs (NOW HIRING)

Compliance Engineer

San Francisco, CA · On-site

$120K - $145K/yr

Role Description We are building our information security compliance program and this role sits at the center of that effort. As our Compliance Engineer, you will work directly with the Head of ...

We are seeking a motivated Security Engineer (Compliance) to be an integral part of our Security team! The ideal candidate will be passionate about cyber security and possess both deep and wide ...

As a Compliance Engineer on our growing DevOps team, you will be driving the implementation of our ... Your expertise will deliver enhancements to our system's reliability, scalability, security, and ...

Compliance Engineer

Livermore, CA · On-site

$102K - $116K/yr

The Compliance Engineer works closely with notified bodies, engineering, security, legal, and operations teams to design, implement, and maintain product compliance while supporting audits and ...

As a Compliance Engineer on the DevOps team, you will implement compliance requirements and enhance system reliability, security, and scalability while automating compliance processes.

As a Compliance Engineer on our growing DevOps team, you will be driving the implementation of our ... Your expertise will deliver enhancements to our system's reliability, scalability, security, and ...

Compliance Engineer

New York, NY · On-site

$155K - $190K/yr

As a Compliance Engineer on our growing DevOps team, you will be driving the implementation of our ... Your expertise will deliver enhancements to our system's reliability, scalability, security, and ...

next page

Showing results 1-20

Security Compliance Engineer information

See salary details

$90K

$117.7K

$164K

How much do security compliance engineer jobs pay per year?

As of Jun 11, 2026, the average yearly pay for security compliance engineer in the United States is $117,706.00, according to ZipRecruiter salary data. Most workers in this role earn between $106,000.00 and $121,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Compliance Engineer, and why are they important?

To thrive as a Security Compliance Engineer, you need in-depth knowledge of information security frameworks (such as ISO 27001, NIST, SOC 2), risk assessment methodologies, and a relevant bachelor’s degree or certification (e.g., CISSP, CISA). Familiarity with GRC (Governance, Risk, and Compliance) tools, vulnerability management systems, and audit management platforms is typically required. Strong analytical thinking, attention to detail, and effective communication skills help in interpreting regulations and collaborating with cross-functional teams. These skills ensure organizations remain compliant with industry regulations, minimize security risks, and maintain customer trust.

What engineers make $300,000 a year?

Senior security compliance engineers, cybersecurity engineers, and security architects with extensive experience, advanced certifications, and specialized skills can earn $300,000 or more annually. These roles often require expertise in compliance standards, risk management, and security tools, and may involve leadership responsibilities or working in high-demand industries.

What are some common challenges Security Compliance Engineers face when working with cross-functional teams?

Security Compliance Engineers often collaborate with IT, development, and business teams to ensure that security policies and compliance requirements are integrated into daily operations. A common challenge is bridging the gap between technical security standards and practical business processes, as different teams may have varying priorities and levels of understanding regarding compliance. Effectively communicating complex regulations, coordinating audits, and advocating for necessary changes without disrupting workflow are essential skills for success. Building strong relationships and fostering a culture of security awareness can help overcome these challenges.

What is the difference between Security Compliance Engineer vs Security Analyst?

AspectSecurity Compliance EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, GIAC Security Essentials
Work EnvironmentFocus on compliance policies, audits, and regulatory standardsMonitor security systems, analyze threats, respond to incidents
Employer & Industry UsageUsed in organizations with strict regulatory requirements, such as finance and healthcareCommon across various industries for threat detection and incident response

While both roles involve security, Security Compliance Engineers primarily focus on ensuring organizations meet regulatory standards and maintain compliance. Security Analysts concentrate on monitoring security threats, analyzing vulnerabilities, and responding to incidents. Understanding these differences helps in choosing the right career path or job focus within cybersecurity.

What engineers make $500,000?

Senior security compliance engineers with extensive experience, specialized certifications (such as CISSP or CISA), and expertise in regulatory standards can reach or exceed $500,000 annually, especially in high-demand industries or senior leadership roles. Achieving this level often requires advanced skills, leadership responsibilities, and a strong track record in security governance and risk management.

What are Security Compliance Engineers?

Security Compliance Engineers are professionals who ensure that an organization’s information systems and processes comply with relevant laws, regulations, and internal policies. They assess security controls, identify risks, and implement measures to meet compliance standards such as GDPR, HIPAA, or ISO 27001. Their role often involves conducting audits, preparing documentation, and working with IT and security teams to mitigate vulnerabilities and maintain regulatory compliance.

Can you make $500,000 a year in cyber security?

Security Compliance Engineers with extensive experience, advanced certifications, and specialized skills in compliance frameworks can potentially earn salaries approaching or exceeding $500,000 annually, especially in senior or leadership roles. Achieving this level often requires a combination of technical expertise, strategic responsibilities, and working in high-demand industries or organizations with large security budgets.

Can you make 300k in cyber security?

Security Compliance Engineers with extensive experience, specialized skills, and relevant certifications such as CISSP or CISA can potentially earn salaries around or above $300,000, especially in high-cost-of-living areas or senior roles. Achieving this level often requires a combination of technical expertise, leadership responsibilities, and industry demand.
More about Security Compliance Engineer jobs
What cities are hiring for Security Compliance Engineer jobs? Cities with the most Security Compliance Engineer job openings:
Who are the top companies hiring for Security Compliance Engineer jobs? The top employers for Security Compliance Engineer jobs are:
What states have the most Security Compliance Engineer jobs? States with the most job openings for Security Compliance Engineer jobs include:
What job categories do people searching Security Compliance Engineer jobs look for? The top searched job categories for Security Compliance Engineer jobs are:
Infographic showing various Security Compliance Engineer job openings in the United States as of June 2026, with employment types broken down into 100% Full Time. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $117,706 per year, or $56.6 per hour.
Compliance Engineer

Compliance Engineer

Gridware

San Francisco, CA • On-site

$120K - $145K/yr

Full-time

Medical, Dental, Vision

Posted 19 days ago


Job description

About Gridware
Gridware is a San Francisco-based technology company dedicated to protecting and enhancing the electrical grid. We pioneered a groundbreaking new class of grid management called active grid response (AGR), focused on monitoring the electrical, physical, and environmental aspects of the grid that affect reliability and safety. Gridware's advanced Active Grid Response platform uses high-precision sensors to detect potential issues early, enabling proactive maintenance and fault mitigation. This comprehensive approach helps improve safety, reduce outages, and ensure the grid operates efficiently. The company is backed by climate-tech and Silicon Valley investors. For more information, please visit www.Gridware.io.
Role Description
We are building our information security compliance program and this role sits at the center of that effort. As our Compliance Engineer, you will work directly with the Head of Information Security to design, implement, and operationalize controls across multiple frameworks (SOC 2, ISO 27001, NIS 2, CIS IG3, NERC CIP, and NIST). You will also own customer-facing security assurance, including security questionnaires and audit evidence requests.
This is a high-visibility role for someone energized by building structure in ambiguous environments and who understands that good compliance is good engineering.
Responsibilities
Framework Implementation & Control Management
  • Design a unified control framework mapped across SOC 2, ISO 27001, CIS IG3, NERC CIP, and NIST (CSF/800-53), eliminating duplication and creating a single source of truth for compliance posture.
  • Develop and maintain a control library, policy inventory, and risk register.
  • Translate technical control requirements into actionable guidance for engineering, IT, and operations teams.
Audit Readiness & Evidence Collection
  • Build a structured, repeatable evidence collection process supporting concurrent audits across all frameworks.
  • Maintain a continuously updated evidence repository and coordinate with Engineering, DevOps, HR, and Legal to gather and validate artifacts.
  • Serve as primary liaison with external auditors; manage schedules, fieldwork, and findings remediation through to closure.
Customer Security Assurance
  • Own intake, triage, and completion of customer security questionnaires (SIG Lite, CAIQ, custom assessments).
  • Maintain a living questionnaire knowledge base and develop customer-facing security documentation, including trust portal content.
Program Development
  • Define compliance workflows, SOPs, tooling requirements, and automation opportunities as the program matures.
  • Monitor regulatory changes across NERC CIP, NIS 2, and NIST; proactively communicate impacts to the team.

Required Skills
  • 2-4 years in information security compliance, GRC, or a related discipline.
  • Working knowledge of two or more: SOC 2, ISO 27001, NIST CSF/800-53, CIS Controls, NERC CIP.
  • Experience supporting or leading external audits, including evidence collection and auditor coordination.
  • Ability to perform cross-framework control mapping and identify gaps or conflicts.
  • Strong written communication skills across technical and non-technical audiences.

Bonus Skills
  • Hands-on experience with NERC CIP (CIP-002 through CIP-014) in an OT or critical infrastructure environment.
  • Familiarity with GRC platforms such as Vanta, Drata, OneTrust, or Archer.
  • Certifications: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or NERC CIP.

$120,000 - $145,000 a year
**At this time, Gridware is unable to provide visa sponsorship or immigration support for this role. We're only able to consider candidates who are currently authorized to work in the country of employment without visa sponsorship now or in the future.**
This describes the ideal candidate; many of us have picked up this expertise along the way. Even if you meet only part of this list, we encourage you to apply!
Benefits
Health, Dental & Vision (Gold and Platinum with some providers plans fully covered)
Paid parental leave
Alternating day off (every other Monday)
"Off the Grid", a two week per year paid break for all employees.
Commuter allowance
Company-paid training