SecOps Engineer

$$$$

Company overview:
 

Graphio connects to your existing systems through APIs to analyze events, activities, fields, and metadata. No content across documents or communication is analyzed.

 

Zero Integration: Works with your existing systems via APIs.

Zero Disruption: No changes to your current team workflows.

Privacy by Design: We analyze only fields, events, activities and metadata and don't analyze sensitive content across files and communication.

Rapid Deployment: Fully operational in under 48 hours.

SOC 2 Type 2, HIPAA compliant, and ISO 27001 (pending).

 

We’ve built and scaled before: the team behind Graphio.ai previously built upSWOT, a B2B platform adopted by hundreds of financial institutions, which was later acquired by Uptiq.  We’re applying those lessons in execution, delivery, and scale to Graphio.ai.

 

Supported by senior leaders from Experian, Mastercard, Lattice, BambooHR, Altrata, SAP, JackHenry, FIS, Pfizer, Workday, and more (graphio.ai/investors).

 


Position Overview:
 

We are looking for a Strong SecOps Engineer to own security operations and compliance for Graphio.ai β€” our compliance programs (SOC 2 Type 2, HIPAA, ISO 27001), the security architecture of a multi-tenant, AI-driven platform, and the audits, penetration tests, and customer security reviews that keep enterprise customers confident in how we handle their data.

 

This is a hands-on role for someone who treats security and compliance as an engineering discipline β€” rigorous and evidence-based β€” rather than a documentation exercise. You will build and run the processes that keep our security posture accurate, defensible, and consistent across every system, contract, and customer conversation.

 

You will work closely with Engineering on platform and infrastructure security, with Customer Success and Sales on enterprise security reviews, and with Legal on the security and data-handling terms of our contracts.

 

You will report directly to the CTO.

 


Key Responsibilities:
 

  • Own and continuously operate our compliance programs (SOC 2 Type 2, HIPAA, ISO 27001): design controls correctly, keep evidence current, and make sure they hold up to independent scrutiny across the full period, not only at the point of testing.
  • Design and run our penetration testing and vulnerability management program: define scope, prioritize findings by risk, and track remediation through to closure.
  • Own the security architecture of a multi-tenant, AI-driven platform: data isolation between tenants and at the inference/model layer, including third-party infrastructure and GPU providers.
  • Harden authentication, authorization, and network-layer defenses across our APIs and integrations, and keep that posture current as the product evolves.
  • Keep our security and compliance documentation internally consistent β€” audits, contracts, architecture records, and public-facing claims should tell the same accurate story and stand up to scrutiny from customers and auditors.
  • Lead technical engagement with enterprise customers during security reviews and due-diligence processes, acting as the internal authority on what we can credibly claim about our security posture.
  • Manage risk from infrastructure and sub-processor vendors, including reviewing their security posture and attestations before we rely on them.
  • Partner with Legal on the security and data-handling terms of customer and vendor contracts (including data processing agreements), so operational practice and written commitments stay aligned.

 


Preferred Qualifications:

 

  • Substantial experience in security engineering, SecOps, or compliance engineering, including real ownership of at least one SOC 2, HIPAA, or ISO 27001 program from the inside.
  • Practical experience running or managing a penetration testing and vulnerability management program, including remediation tracking and reporting.
  • Solid understanding of multi-tenant SaaS security models and the tradeoffs between shared and dedicated infrastructure.
  • Practical knowledge of cloud infrastructure security (Azure preferred; AWS or GCP acceptable), API security (authentication, authorization, rate limiting, WAF), and secrets and token lifecycle management.
  • Familiarity with data processing agreements and similar compliance-related contract language, and comfort partnering with Legal on it.
  • Experience handling enterprise customer security questionnaires and vendor due-diligence processes.
  • A rigorous, evidence-first approach: comfortable being the internal authority on whether a security or compliance claim is actually accurate.
  • Excellent written English: able to produce documentation clear and precise enough to satisfy external auditors and enterprise customers.


    Nice to have:

  • Experience with AI/LLM inference security β€” isolating tenant context at the model layer, GPU-provider risk.
  • Exposure to AI-specific attestation frameworks (e.g., ISO/IEC 42001) or willingness to build toward one.
  • Experience building or scaling a compliance program in a startup environment.
  • Experience with compliance automation tooling (e.g., Vanta, Drata, Secureframe, or similar).


 

What we offer:

 

  • Full ownership of the security and compliance function β€” you build and run the program, not just execute someone else's checklist.
  • Direct access to the CTO and engineering leadership, with a clear mandate to shape how security and compliance work at Graphio.ai.
  • A product built for compliance-conscious enterprise customers, so this work has direct, visible business impact.
  • Direct collaboration with Product, Machine Learning and AI specialists, and Software Engineers in a low-bureaucracy startup environment.
  • Clear success metrics tied to audit outcomes, customer trust, and reduced security risk.
  • Competitive compensation and room to grow into a company-wide security leadership role as we scale.



Company Operating Requirements:

 

At Graphio.ai we run a high-ownership, mission-driven team with clear operating rules. Please read these carefully before applying:

  • LinkedIn profile is required (company policy). Employees are required to keep a current LinkedIn profile that shows their Graphio.ai position and is linked to the official Graphio.ai company page (company logo visible on the profile). Profile standards are provided during onboarding.
  • Synchronized team vacations. The team takes coordinated time off four times per year to keep planning aligned and reduce context switching. Dates are announced in advance.
  • Startup constraints. Vacation timing may be restricted during critical company periods. We plan time off as a team and communicate constraints early.
  • Non-standard schedule. The role requires flexibility to collaborate across time zones. This may occasionally include early/late meetings depending on customer and team needs.
  • US Eastern Time (ET) collaboration. This role requires regular overlap with US East Coast (ET) working hours. You must be comfortable running meetings, follow-ups, and execution in that time zone.
  • Zero slow offboarding. We run lean and fast. When the fit isn’t there, we act quickly: employment may be ended within a day and access is removed immediately.

 

 

Final note:
 

Graphio.ai is not a 9-to-5 corporate environment. We move fast, operate with high ownership, and expect proactive execution without micromanagement. Graphio.ai is a strong fit for people who actively seek challenges for personal growth - especially those who want to build their own company one day and see this as a place to learn how high-performing startups execute.


Because we work with US-based stakeholders, you should be comfortable aligning part of your schedule with US Eastern Time (ET).

 

English: B2

Required domain experience

SaaS 2 years

Required languages

English B2 - Upper Intermediate
Published 13 August
3 views
Β·
2 applications
Response activity: Medium
To apply for this and other jobs on Djinni login or signup.
Loading...