Security & Compliance Engineer
Listed on 2026-08-12
-
IT/Tech
Information Security & Data Protection, Cybersecurity
About Varick. Varick builds AI agents that take over real operational workflows inside the world's largest enterprises. Our forward-deployed engineers and strategists embed with client teams, map how work actually runs, then our engineers build the agents into production. We're venture-backed, revenue-generating from day one, and already in production inside several of these companies. You'll join an elite team from Meta, AWS Bedrock, Citadel Securities, McKinsey, BCG, Stanford, and more.
The Role. We run AI agents inside regulated enterprises that hold real money and sensitive data, so security and compliance are what make the deals possible in the first place. You own our security posture and the compliance work (SOC 2 and beyond) that lets a bank or a Fortune 500 trust us inside their environment.
What You'll Do.
- Own and run our SOC 2 program, and the frameworks clients ask for next, from evidence collection through audit
- Harden the platform: access controls, secrets management, encryption, and the security review of how agents touch client systems
- Build the security tooling and monitoring that catches problems early across our deployments
- Be the technical point person on client security reviews and vendor questionnaires, translating what we do into what their security team needs to hear
- Set the security standards the engineering team builds against, and make the secure path the easy path
What We're Looking For.
- 3+ years in security engineering, compliance engineering, or a blend, with real ownership of a program
- Hands-on with SOC 2 (and ideally more: ISO 27001, HIPAA, FedRAMP, or similar), not just policy but the technical evidence behind it
- Solid grasp of cloud security (AWS, GCP, Azure), IAM, secrets, and encryption
- Comfort talking to enterprise security teams and holding your own in a review
- A builder's instinct: you automate compliance instead of running it on spreadsheets
Nice to Have.
- Experience securing multi-tenant SaaS or single-tenant enterprise deployments
- Familiarity with LLM and agent-specific security concerns (prompt injection, data exfiltration, tool-use guardrails)
- Enterprise environments with strict reliability and audit requirements
What We Offer.
- Meaningful equity
- real ownership
- direct access to how the world's largest enterprises actually run
- flexible PTO
- free lunch and dinner in the office
- Ubers home if you're staying late
- monthly team dinners
Logistics. On-site in our San Francisco Financial District office, 5-6 days a week. Comfortable with startup hours, for startup upside.
Equal opportunity employer. Employment is subject to a standard confidentiality and non-disclosure agreement.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).