Skip to main content
Zobhira
Home
Jobs
Certifications
Zobhira
JobsCertificationsTodayAbout
Log inSign up
Zobhira

New job and contest openings, updated every morning on one searchable board.

Find work

  • All jobs
  • Fresher roles
  • Remote roles
  • Certifications

Compete

  • Added today

Popular cities

  • India
  • Bangalore, Karnataka, India
  • Hyderabad, Telangana, India
  • Pune, Maharashtra, India
  • Chennai, Tamil Nadu, India
  • Mumbai, Maharashtra, India

Company

  • About
  • Contact
  • Privacy
  • Terms

Stay updated

One email a week with new roles.

Secure infrastructure
Free to use, no account needed to search

Board updated daily ยท ยฉ 2026 Zobhira. All rights reserved.

Privacy PolicyTerms of Service
Home / Jobs / UserGems ๐Ÿ’Ž

Senior Security Engineer

UserGems ๐Ÿ’Ž

WorldwideremotePosted 1 month ago
UserGems ๐Ÿ’Ž logo

Skill Required

Security-EngineeringGRC-SecurityCloud-Security-EngineeringCompliance-EngineeringAI-SecuritySenior-Security-EngineerSenior-Engineer---SecuritySenior-Information-Security-EngineerSenior-Cybersecurity-EngineerSenior-Principal-Security-EngineerSenior-Security-Engineering-ManagerSenior-Security-Operations-EngineerSenior-Application-Security-EngineerLead-Security-EngineerSecurity EngineersecuritySOCEngineeringKubernetesISO 27001ObservabilityTerraformbuildingwrittenDockerGitAzureCloudSIEMGenerative AIAWSIAMSAPGoAIFulltime

Key highlights

  • Salary: โ‚ฌ80k โ€“ โ‚ฌ100k
  • Experience: Must have personally led a SOC 2 or ISO audit end-to-end
  • Requirement: Hands-on AWS console and remediation knowledge
  • Benefit: No on-call rotation
  • Work Model: Remote-first (Americas & Europe)
  • Requirement: Excellent written English for customer-facing security work

Role overview

UserGems is an AI platform that helps sales and marketing teams double their pipeline impact by identifying high-value targets. Its AI agent, Gem-E, captures buying signals and CRM data to identify who to target, when, and why, drafting personalized outreach that has generated $4 billion in pipeline and over $950 million in revenue for customers like CrowdStrike, UserTesting, and SAP LeanIX (often seeing 15X+ ROI). The company is a remote-first startup of approximately 70 people, including 25 engineers in Europe and 45 sales and marketing team members in the U.S. This role is for the company's first dedicated security professional, responsible for taking over the operational majority of the security and compliance program, which is currently in excellent shape with SOC 2 Type II already in place and compliance monitoring centralized in Drata.

Responsibilities

  • Operate UserGems' security and compliance program day-to-day, partnered with the Sr. Director on direction and strategy.
  • Take over the operational majority of the security work the Sr. Director currently owns, proposing, shaping, and executing the program.
  • Own SOC 2 - keep Drata green and audits clean.
  • Lead ISO 27001 implementation, then ISO 42001.
  • Run the customer security questionnaire process (SafeBase + Trust Center) to unblock revenue.
  • Perform Drata-driven AWS remediation, actioning simple findings directly in AWS (IAM tweaks, S3 settings, secrets hygiene, audit-trail follow-ups).
  • Oversee and extend the existing scanner-findings automation in Linear and hit SLAs for vulnerability management.
  • Conduct light secure code review, spot-checking high-risk features and new repositories (especially AI/LLM systems) before production.
  • Escalate deeper AppSec questions to engineering and external pen testers.
  • Tune GuardDuty findings, evaluate central logging / SIEM options, run tabletop exercises, and mature the Incident Response Plan (IRP) from written to rehearsed.
  • Run the annual external pen test, perform regular internal pen tests, and handle external researcher reports and bug bounty payouts.
  • Own access provisioning and revocation for onboarding and offboarding.
  • Act as the face of security at UserGems, handling questions, escalations, customer security reviews, and audit conversations.
  • Shape how the company secures both its product and internal AI usage.
  • Own ISO 42001 readiness from scratch.
  • Manage model and data governance for Gem-E and self-hosted LLMs on Azure, including data residency posture, prompt-injection threat modeling, and access controls on training/inference data.
  • Shape the safe scaling of internal AI tooling built by non-engineering teams through guardrails, access boundaries, monitoring, and review.
  • Extend AI in the security stack, including scanner automations, AI-assisted questionnaire workflows, and security review of AI-generated code.
  • Shape the customer-facing AI security narrative, including Trust Center statements and policies.

Requirements

  • Non-negotiable: Personally owned a SOC 2 or ISO audit end-to-end as the operational owner accountable to the auditor and delivered a zero-exception report.
  • Non-negotiable: Working AWS knowledge, including navigating the console, actioning Drata-flagged remediations (IAM, S3, KMS, audit trails), and reading CloudTrail.
  • Non-negotiable: Ability to understand Terraform with AI help to explain diffs and catch errors (fluency not required).
  • Non-negotiable: High ownership and accountability to ship audits, questionnaires, and policy work without a project manager.
  • Non-negotiable: Excellent written English for customer-facing questionnaires, Trust Center, and policies.
  • Non-negotiable: Comfortable with async collaboration across Europe and the U.S., including some late-afternoon CET availability roughly once a week.

Nice to have

  • Solid grasp of attacker techniques and modern application security (web/API, cloud, supply chain).
  • Hands-on secure code review experience, including AI/LLM systems.
  • Comfort tuning detection (GuardDuty / SIEM) and running incident response.
  • ISO 27001 Lead Implementer or Lead Auditor experience.
  • ISO 42001 / AI governance familiarity.
  • Hands-on Kubernetes / container security.
  • Light coding ability (Java preferred) to extend security automation code.
  • Experience with auditing LLM security.

Benefits

  • Remote-first company with employees across the Americas and Europe.
  • Weekly standups, virtual happy hours, and in-person off-sites around the world.
  • No on-call rotation; incident response is a whole-team effort.
  • Sr. Director continues to cover security during your time off.
  • Trust to manage your own time.
  • Competitive salary and benefits.
  • Opportunity to be part of a fast-growing startup as it scales from 70 to 100+ employees.

Additional details

  • UserGems has generated $4 Billion in pipeline and over $950 Million in revenue for hundreds of start-ups and public companies.
  • Companies like Mimecast, UserTesting, SAP LeanIX see more than 15X ROI in closed won revenue.
  • This is a compliance-led role with hands-on operational components - heavy on SOC 2 / ISO ownership, customer security reviews, and Drata-driven remediation.
  • Compliance is the primary focus; the role will eventually own full technical scope.
  • Cadence includes a bi-weekly 1:1 with the Sr. Director and a weekly work discussion.
  • Security program status: No fires; SOC 2 Type II in place for years; monitoring centralized in Drata; scanner findings auto-flow into Linear; CrowdStrike Complete (managed MDR) for runtime protection.
  • The Sr. Director currently runs the program in ~25% of their time; the new owner will have significant headroom for new initiatives.
  • Time split: 2โ€“3 days per week on baseline operations, remainder on new initiatives (ISO 27001 and ISO 42001).
  • You'll thrive if you lean into compliance/GRC operations, want to own operations end-to-end, and like a startup environment with clear priorities and real ownership.
  • UserGems is already EU AI Act compliant.
  • Cloud Tech: AWS (primary), some Azure (self-hosted LLMs).
  • Compliance/GRC Tech: Drata, SafeBase, Linear.
  • Detection/Endpoint Tech: AWS GuardDuty, CrowdStrike Complete.
  • Scanners: GitHub, AWS Inspector, ZAP.
  • Infra (Engineering-owned): Terraform, Kubernetes, Docker, GitHub.
  • Target annual compensation range: โ‚ฌ80k โ€“ โ‚ฌ100k.
  • Final seniority leveling and compensation determined based on experience and qualifications.
  • Expectations: Flag blockers early, surface progress, and avoid 'going dark'.
  • High-commitment role, not a standard 9-to-5.
  • Strong Glassdoor, RepVue, and G2 reviews.
  • Value individual differences regardless of skin color, gender, or sexual orientation.
  • Originally posted on Himalayas.

Similar jobs open now

ABB logo
Senior Project Engineer -SIS
ABB
Bangalore, Karnataka, India
View details
Cognyte logo
Product Manager
Cognyte
Pune, Maharashtra, India
View details
IBM logo
Data Engineer-Data Platforms-AWS
IBM
Pune, Maharashtra, India
View details
IBM logo
Technical Consultant-AI Integration
IBM
Pune, Maharashtra, India
View details
Apply now
LocationWorldwide
TypeFulltime
SalaryEUR 80000 - 100000
Posted8/3/2026
Apply by10/2/2026

Links are checked every day. If this one stops working, tell us and we'll pull it.

More like this

View all
ABB logo
Senior Project Engineer -SIS
ABB
Cognyte logo
Product Manager
Cognyte
IBM logo
Data Engineer-Data Platforms-AWS
IBM
Apply now